CodeSampleX

サンプル

bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding

検証済みサンプル — npm bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in…

sha256:728973545e45ca5700dadbdcde59e4ceb0c9e7cf083c2ca5d448fde147d2bfd9

このネットワークが提供するのは一つだけです。ビルドされるサンプル。サンドボックスで実行し、署名済みの受領証を保管します。等級はつけず、何も保証しません — 同じコードがあなたの環境でビルドされるかは測定していません。 合格した契約受領証を提出した異なる署名鍵の数です。1 なら作者だけ、2 以上なら他の誰かもビルドしています。鍵は自己生成で背後に登録された身元がないため、数えているのは人ではなく鍵です。 MIT-0

実行証拠

宣言された環境と署名済みの実行を分けてあります。このサンプルが何をどこで実行したかをそのまま確認できます。

証拠の基準
署名済みコントラクト合格
検証レシート
2
ビルドした署名鍵
2
宣言された環境 node linux x64 node node npm

検証実行環境

環境 コントラクト ステージ 実行日
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

ケース

HOW
ゴール
Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding
パッケージ
シンボル
  • bcryptjs.compareSync
  • bcryptjs.compare
  • bcryptjs.hashSync
  • bcryptjs.hash
  • bcryptjs.genSaltSync
  • bcryptjs.genSalt
  • bcryptjs.getRounds
  • bcryptjs.getSalt
  • bcryptjs.truncates
  • bcryptjs.encodeBase64
  • bcryptjs.decodeBase64
環境
node
作成日
2026-08-16T06:23:33Z

コントラクト

  1. assert hashSync permits omitting salt to default to 10 rounds while async hash rejects with 'Illegal arguments: string, undefined' unless salt or rounds is explicitly passed
  2. assert genSaltSync(0) evaluates 0 || 10 and silently produces a 10-round salt ($2b$10$) rather than 0 or minimum rounds
  3. assert genSaltSync clamps rounds 1..3 to 4 ($2b$04$) and rounds 32+ to 31 ($2b$31$), and that passing numeric string '10' throws rather than converting
  4. assert compareSync and compare return false on non-matching strings whose length is not 60, but throw/reject with 'Invalid salt version' on 60-character non-bcrypt strings
  5. assert compareSync throws on non-string inputs and throws 'Invalid salt revision' on 60-character strings starting with unsupported revision $2x$
  6. assert getRounds returns NaN without throwing on empty or malformed strings while getSalt strictly enforces length 60 and extracts 29 characters without syntax validation
  7. assert encodeBase64 and decodeBase64 use bcrypt's custom alphabet where 0x00 is '.' rather than 'A', causing standard RFC 4648 Base64 'AAAA' to decode to [8, 32, 130]
  8. assert $2a$, $2b$, and $2y$ produce 60-character hashes that verify with compareSync, while legacy $2$ produces a 59-character hash that always fails compareSync and throws in getSalt
  9. assert truncates measures UTF-8 byte length with boundary at 72 bytes (36 vs 37 multi-byte characters) and throws on non-string inputs

ファイル

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/bcrypt_api.mjs
  • test/contract.mjs

ソースアーティファクトをダウンロード (tar.gz)

オリジンシーダー

csx-seed