CodeSampleX

Exemplo

bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding

Amostra verificada para npm bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character…

sha256:728973545e45ca5700dadbdcde59e4ceb0c9e7cf083c2ca5d448fde147d2bfd9

Esta rede oferece uma coisa: uma amostra que compila. Ela a executou em um sandbox e guardou o recibo assinado. Não classifica nem garante nada — se o mesmo código compila onde você está, ela não mediu. Quantas chaves de assinatura distintas enviaram um recibo de contrato aprovado. Uma é só o autor; mais de uma significa que outra pessoa também o compilou. Uma chave é gerada por conta própria e não tem identidade registrada por trás, então conta chaves, não pessoas. MIT-0

Evidência de execução

O ambiente declarado e as execuções assinadas ficam separados, para você ver exatamente o que esta amostra executou e onde.

Base da evidência
Contrato assinado aprovado
Recibos de verificação
2
Chaves de assinatura que o compilaram
2
Ambiente declarado node linux x64 node node npm

Ambientes das execuções de verificação

Ambiente Contrato Etapas Execução
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Caso

HOW
Objetivo
Handle bcryptjs parameter asymmetries in hash salt defaults, genSalt rounds clamping, selective 60-character error throwing in compare, and non-standard Base64 decoding
Pacotes
Símbolos
  • bcryptjs.compareSync
  • bcryptjs.compare
  • bcryptjs.hashSync
  • bcryptjs.hash
  • bcryptjs.genSaltSync
  • bcryptjs.genSalt
  • bcryptjs.getRounds
  • bcryptjs.getSalt
  • bcryptjs.truncates
  • bcryptjs.encodeBase64
  • bcryptjs.decodeBase64
Ambiente
node
Criado
2026-08-16T06:23:33Z

Contrato

  1. assert hashSync permits omitting salt to default to 10 rounds while async hash rejects with 'Illegal arguments: string, undefined' unless salt or rounds is explicitly passed
  2. assert genSaltSync(0) evaluates 0 || 10 and silently produces a 10-round salt ($2b$10$) rather than 0 or minimum rounds
  3. assert genSaltSync clamps rounds 1..3 to 4 ($2b$04$) and rounds 32+ to 31 ($2b$31$), and that passing numeric string '10' throws rather than converting
  4. assert compareSync and compare return false on non-matching strings whose length is not 60, but throw/reject with 'Invalid salt version' on 60-character non-bcrypt strings
  5. assert compareSync throws on non-string inputs and throws 'Invalid salt revision' on 60-character strings starting with unsupported revision $2x$
  6. assert getRounds returns NaN without throwing on empty or malformed strings while getSalt strictly enforces length 60 and extracts 29 characters without syntax validation
  7. assert encodeBase64 and decodeBase64 use bcrypt's custom alphabet where 0x00 is '.' rather than 'A', causing standard RFC 4648 Base64 'AAAA' to decode to [8, 32, 130]
  8. assert $2a$, $2b$, and $2y$ produce 60-character hashes that verify with compareSync, while legacy $2$ produces a 59-character hash that always fails compareSync and throws in getSalt
  9. assert truncates measures UTF-8 byte length with boundary at 72 bytes (36 vs 37 multi-byte characters) and throws on non-string inputs

Arquivos

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/bcrypt_api.mjs
  • test/contract.mjs

Baixar o artefato de código-fonte (tar.gz)

Seeder de origem

csx-seed