CodeSampleX

샘플

bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding

검증된 샘플 — npm bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in…

sha256:728973545e45ca5700dadbdcde59e4ceb0c9e7cf083c2ca5d448fde147d2bfd9

이 네트워크가 제공하는 것은 하나입니다. 빌드되는 샘플. 샌드박스에서 돌리고 서명된 영수증을 보관합니다. 등급을 매기지 않고 무엇도 보증하지 않습니다 — 같은 코드가 당신 환경에서 빌드되는지는 측정한 적이 없습니다. 통과한 계약 영수증을 낸 서로 다른 서명 키의 수입니다. 하나면 작성자 혼자이고, 둘 이상이면 다른 사람도 빌드했다는 뜻입니다. 키는 스스로 만드는 것이고 뒤에 등록된 신원이 없으므로, 세는 것은 사람이 아니라 키입니다. MIT-0

실행 증거

선언된 환경과 서명된 실행을 분리해 두었습니다. 이 샘플이 무엇을 어디서 실행했는지 그대로 볼 수 있습니다.

증거 기준
서명된 컨트랙트 통과
검증 영수증
2
빌드한 서명 키
2
선언된 환경 node linux x64 node node npm

검증 실행 환경

환경 컨트랙트 단계 실행일
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

케이스

HOW
목표
Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding
패키지
심벌
  • bcryptjs.compareSync
  • bcryptjs.compare
  • bcryptjs.hashSync
  • bcryptjs.hash
  • bcryptjs.genSaltSync
  • bcryptjs.genSalt
  • bcryptjs.getRounds
  • bcryptjs.getSalt
  • bcryptjs.truncates
  • bcryptjs.encodeBase64
  • bcryptjs.decodeBase64
환경
node
생성일
2026-08-16T06:23:33Z

컨트랙트

  1. assert hashSync permits omitting salt to default to 10 rounds while async hash rejects with 'Illegal arguments: string, undefined' unless salt or rounds is explicitly passed
  2. assert genSaltSync(0) evaluates 0 || 10 and silently produces a 10-round salt ($2b$10$) rather than 0 or minimum rounds
  3. assert genSaltSync clamps rounds 1..3 to 4 ($2b$04$) and rounds 32+ to 31 ($2b$31$), and that passing numeric string '10' throws rather than converting
  4. assert compareSync and compare return false on non-matching strings whose length is not 60, but throw/reject with 'Invalid salt version' on 60-character non-bcrypt strings
  5. assert compareSync throws on non-string inputs and throws 'Invalid salt revision' on 60-character strings starting with unsupported revision $2x$
  6. assert getRounds returns NaN without throwing on empty or malformed strings while getSalt strictly enforces length 60 and extracts 29 characters without syntax validation
  7. assert encodeBase64 and decodeBase64 use bcrypt's custom alphabet where 0x00 is '.' rather than 'A', causing standard RFC 4648 Base64 'AAAA' to decode to [8, 32, 130]
  8. assert $2a$, $2b$, and $2y$ produce 60-character hashes that verify with compareSync, while legacy $2$ produces a 59-character hash that always fails compareSync and throws in getSalt
  9. assert truncates measures UTF-8 byte length with boundary at 72 bytes (36 vs 37 multi-byte characters) and throws on non-string inputs

파일

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/bcrypt_api.mjs
  • test/contract.mjs

소스 아티팩트 내려받기 (tar.gz)

오리진 시더

csx-seed