CodeSampleX

Beispiel

bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding

Verifiziertes Beispiel für npm bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character…

sha256:728973545e45ca5700dadbdcde59e4ceb0c9e7cf083c2ca5d448fde147d2bfd9

Dieses Netzwerk bietet eine Sache: ein Sample, das baut. Es hat es in einer Sandbox ausgeführt und die signierte Quittung behalten. Es bewertet nichts und garantiert nichts — ob derselbe Code bei Ihnen baut, hat es nicht gemessen. Wie viele verschiedene Signaturschlüssel eine bestandene Vertragsquittung eingereicht haben. Einer ist der Autor allein; mehr als einer heißt, jemand anderes hat es auch gebaut. Ein Schlüssel wird selbst erzeugt und hat keine registrierte Identität dahinter — gezählt werden Schlüssel, nicht Personen. MIT-0

Ausführungsbelege

Die deklarierte Umgebung und die signierten Läufe stehen getrennt, damit Sie genau sehen, was dieses Sample ausgeführt hat und wo.

Beleggrundlage
Signierter Vertrag bestanden
Verifizierungsbelege
2
Signaturschlüssel, die es gebaut haben
2
Deklarierte Umgebung node linux x64 node node npm

Umgebungen der Verifizierungsläufe

Umgebung Contract Stufen Lauf
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Fall

HOW
Ziel
Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding
Pakete
Symbole
  • bcryptjs.compareSync
  • bcryptjs.compare
  • bcryptjs.hashSync
  • bcryptjs.hash
  • bcryptjs.genSaltSync
  • bcryptjs.genSalt
  • bcryptjs.getRounds
  • bcryptjs.getSalt
  • bcryptjs.truncates
  • bcryptjs.encodeBase64
  • bcryptjs.decodeBase64
Umgebung
node
Erstellt
2026-08-16T06:23:33Z

Contract

  1. assert hashSync permits omitting salt to default to 10 rounds while async hash rejects with 'Illegal arguments: string, undefined' unless salt or rounds is explicitly passed
  2. assert genSaltSync(0) evaluates 0 || 10 and silently produces a 10-round salt ($2b$10$) rather than 0 or minimum rounds
  3. assert genSaltSync clamps rounds 1..3 to 4 ($2b$04$) and rounds 32+ to 31 ($2b$31$), and that passing numeric string '10' throws rather than converting
  4. assert compareSync and compare return false on non-matching strings whose length is not 60, but throw/reject with 'Invalid salt version' on 60-character non-bcrypt strings
  5. assert compareSync throws on non-string inputs and throws 'Invalid salt revision' on 60-character strings starting with unsupported revision $2x$
  6. assert getRounds returns NaN without throwing on empty or malformed strings while getSalt strictly enforces length 60 and extracts 29 characters without syntax validation
  7. assert encodeBase64 and decodeBase64 use bcrypt's custom alphabet where 0x00 is '.' rather than 'A', causing standard RFC 4648 Base64 'AAAA' to decode to [8, 32, 130]
  8. assert $2a$, $2b$, and $2y$ produce 60-character hashes that verify with compareSync, while legacy $2$ produces a 59-character hash that always fails compareSync and throws in getSalt
  9. assert truncates measures UTF-8 byte length with boundary at 72 bytes (36 vs 37 multi-byte characters) and throws on non-string inputs

Dateien

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/bcrypt_api.mjs
  • test/contract.mjs

Quellartefakt herunterladen (tar.gz)

Ursprungs-Seeder

csx-seed