Skip to content

Modernize phpass and add portable password verification - #4

Merged
jhurliman merged 1 commit into
masterfrom
modernization/phpass
Sep 10, 2026
Merged

Modernize phpass and add portable password verification#4
jhurliman merged 1 commit into
masterfrom
modernization/phpass

Conversation

@jhurliman

Copy link
Copy Markdown
Owner

Adds verification for the portable $P$ and $H$ hashes requested in #2 and modernizes the normal bcrypt path. The old code generated salts with Math.random, used the constructor's cost instead of the stored hash's cost during verification, and encoded non-ASCII passwords as UTF-16 low bytes. Standard bcrypt now uses bcrypt.js with cryptographic salts, UTF-8, and stored-cost verification.

This prepares 1.0.0 because new hashes use $2b$, the default generation cost changes from 8 to 10, Node.js 22+ is required, inputs/costs are validated, and new passwords beyond bcrypt's 72-byte limit are rejected. Existing non-ASCII node-phpass records have an explicit checkPasswordLegacy() migration path; normal checks never silently fall back to the old encoding. Portable generation remains unsupported.

Adds Promise methods (portable verification runs in a worker), verification cost ceilings, declarations, a lockfile, explicit package contents, GitHub Actions, and a rewritten README covering supported formats, concurrency, limits, and migration. Existing license/third-party attribution is retained.

Validation: 12 passing tests, including independent native-bcrypt interoperability; 12 portable vectors generated by Openwall's C reference at a recorded commit; old-release ASCII/Unicode fixtures; malformed inputs and excessive-cost rejection; cryptographic randomness without Math.random; async verification and worker timer responsiveness. Strict TypeScript CJS/ESM consumers compile. Installed the packed archive and ran CommonJS, ESM, portable-worker, and README examples. Native bcrypt is development-only.

Fixes #2. Publication remains a separate step.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-10T19:50:30.646745Z 2dedf67 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@jhurliman
jhurliman merged commit ffb41a1 into master Sep 10, 2026
6 checks passed
@jhurliman
jhurliman deleted the modernization/phpass branch September 10, 2026 23:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Portable Password Checking

1 participant