Update password hashing for improved security and consistency

Replace dynamic environment-based password hashing with a simplified, robust crypto-based approach to ensure consistent security practices across all environments, including production.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: a8a78c07-e900-425c-a577-5b4c5894379d
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a8a78c07-e900-425c-a577-5b4c5894379d/oleRdyv
This commit is contained in:
michaelschal committed 2025-08-11 19:42:12 +00:00
1 parent d84d3e656e
commit 469880b6fe
1 file changed
+11 -19
+11 -19
View File
@@ -6,21 +6,15 @@ import { requireModulePermission, requireAdmin } from "./permissions";
console.log('🔍 Using development storage and authentication');
// Function to get the correct hashPassword function based on environment
async function getHashPassword() {
if (process.env.NODE_ENV === 'production') {
try {
const prodAuth = await import("./localAuth.production.js");
return prodAuth.hashPassword;
} catch (error) {
console.error('❌ Failed to import production auth, falling back to dev auth:', error);
const devAuth = await import("./localAuth");
return devAuth.hashPassword;
}
} else {
const devAuth = await import("./localAuth");
return devAuth.hashPassword;
}
// Simple hash password function using crypto
async function hashPasswordSimple(password: string) {
const crypto = await import('crypto');
const { promisify } = await import('util');
const scryptAsync = promisify(crypto.scrypt);
const salt = crypto.randomBytes(16).toString("hex");
const buf = (await scryptAsync(password, salt, 64)) as Buffer;
return `${buf.toString("hex")}.${salt}`;
}
@@ -904,8 +898,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
// Hash password if provided (for local auth)
if (userData.password) {
const hashPassword = await getHashPassword();
userData.password = await hashPassword(userData.password);
userData.password = await hashPasswordSimple(userData.password);
}
const newUser = await storage.createUser({
@@ -960,8 +953,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
// Hash password if provided
if (userData.password) {
const hashPassword = await getHashPassword();
userData.password = await hashPassword(userData.password);
userData.password = await hashPasswordSimple(userData.password);
// Mark password as changed
(userData as any).passwordChanged = true;
}