Update password hashing for improved security and consistency

Replace dynamic environment-based password hashing with a simplified, robust crypto-based approach to ensure consistent security practices across all environments, including production.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: a8a78c07-e900-425c-a577-5b4c5894379d
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a8a78c07-e900-425c-a577-5b4c5894379d/oleRdyv
This commit is contained in:
michaelschal committed 2025-08-11 19:42:12 +00:00
1 parent d84d3e656e
commit 469880b6fe
1 file changed
+11 -19
+11 -19
View File
@@ -6,21 +6,15 @@ import { requireModulePermission, requireAdmin } from "./permissions";
console.log('🔍 Using development storage and authentication'); console.log('🔍 Using development storage and authentication');
// Function to get the correct hashPassword function based on environment // Simple hash password function using crypto
async function getHashPassword() { async function hashPasswordSimple(password: string) {
if (process.env.NODE_ENV === 'production') { const crypto = await import('crypto');
try { const { promisify } = await import('util');
const prodAuth = await import("./localAuth.production.js"); const scryptAsync = promisify(crypto.scrypt);
return prodAuth.hashPassword;
} catch (error) { const salt = crypto.randomBytes(16).toString("hex");
console.error('❌ Failed to import production auth, falling back to dev auth:', error); const buf = (await scryptAsync(password, salt, 64)) as Buffer;
const devAuth = await import("./localAuth"); return `${buf.toString("hex")}.${salt}`;
return devAuth.hashPassword;
}
} else {
const devAuth = await import("./localAuth");
return devAuth.hashPassword;
}
} }
@@ -904,8 +898,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
// Hash password if provided (for local auth) // Hash password if provided (for local auth)
if (userData.password) { if (userData.password) {
const hashPassword = await getHashPassword(); userData.password = await hashPasswordSimple(userData.password);
userData.password = await hashPassword(userData.password);
} }
const newUser = await storage.createUser({ const newUser = await storage.createUser({
@@ -960,8 +953,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
// Hash password if provided // Hash password if provided
if (userData.password) { if (userData.password) {
const hashPassword = await getHashPassword(); userData.password = await hashPasswordSimple(userData.password);
userData.password = await hashPassword(userData.password);
// Mark password as changed // Mark password as changed
(userData as any).passwordChanged = true; (userData as any).passwordChanged = true;
} }