From 469880b6fefe47e6cdcdbe30bfc7ebbb1593450d Mon Sep 17 00:00:00 2001 From: michaelschal <35957947-michaelschal@users.noreply.replit.com> Date: Mon, 11 Aug 2025 19:42:12 +0000 Subject: [PATCH] Update password hashing for improved security and consistency Replace dynamic environment-based password hashing with a simplified, robust crypto-based approach to ensure consistent security practices across all environments, including production. Replit-Commit-Author: Agent Replit-Commit-Session-Id: a8a78c07-e900-425c-a577-5b4c5894379d Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a8a78c07-e900-425c-a577-5b4c5894379d/oleRdyv --- server/routes.ts | 30 +++++++++++------------------- 1 file changed, 11 insertions(+), 19 deletions(-) diff --git a/server/routes.ts b/server/routes.ts index b0025c2..d877332 100644 --- a/server/routes.ts +++ b/server/routes.ts @@ -6,21 +6,15 @@ import { requireModulePermission, requireAdmin } from "./permissions"; console.log('🔍 Using development storage and authentication'); -// Function to get the correct hashPassword function based on environment -async function getHashPassword() { - if (process.env.NODE_ENV === 'production') { - try { - const prodAuth = await import("./localAuth.production.js"); - return prodAuth.hashPassword; - } catch (error) { - console.error('❌ Failed to import production auth, falling back to dev auth:', error); - const devAuth = await import("./localAuth"); - return devAuth.hashPassword; - } - } else { - const devAuth = await import("./localAuth"); - return devAuth.hashPassword; - } +// Simple hash password function using crypto +async function hashPasswordSimple(password: string) { + const crypto = await import('crypto'); + const { promisify } = await import('util'); + const scryptAsync = promisify(crypto.scrypt); + + const salt = crypto.randomBytes(16).toString("hex"); + const buf = (await scryptAsync(password, salt, 64)) as Buffer; + return `${buf.toString("hex")}.${salt}`; } @@ -904,8 +898,7 @@ export async function registerRoutes(app: Express): Promise { // Hash password if provided (for local auth) if (userData.password) { - const hashPassword = await getHashPassword(); - userData.password = await hashPassword(userData.password); + userData.password = await hashPasswordSimple(userData.password); } const newUser = await storage.createUser({ @@ -960,8 +953,7 @@ export async function registerRoutes(app: Express): Promise { // Hash password if provided if (userData.password) { - const hashPassword = await getHashPassword(); - userData.password = await hashPassword(userData.password); + userData.password = await hashPasswordSimple(userData.password); // Mark password as changed (userData as any).passwordChanged = true; }