サンプル
bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, selective 60-character error throwing in compare, fallback random precedence, and custom Base64 encoding
検証済みサンプル — npm bcryptjs 3.0.3: Handle bcryptjs parameter asymmetries in hash salt defaults, selective 60-character error throwing in compare, fallback random…
sha256:9e53fd13103b399494311358bf94c04682964ebb0f7c6cc08d8077e3ab99f3db
このネットワークが提供するのは一つだけです。ビルドされるサンプル。サンドボックスで実行し、署名済みの受領証を保管します。等級はつけず、何も保証しません — 同じコードがあなたの環境でビルドされるかは測定していません。
合格した契約受領証を提出した異なる署名鍵の数です。1 なら作者だけ、2 以上なら他の誰かもビルドしています。鍵は自己生成で背後に登録された身元がないため、数えているのは人ではなく鍵です。
MIT-0
実行証拠
宣言された環境と署名済みの実行を分けてあります。このサンプルが何をどこで実行したかをそのまま確認できます。
- 証拠の基準
- 署名済みコントラクト合格
- 検証レシート
- 2
- ビルドした署名鍵
- 2
宣言された環境
node linux x64 node node npm
検証実行環境
| 環境 | コントラクト | ステージ | 実行日 |
|---|---|---|---|
| node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1 |
2026-08-17 |
| node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · node-typescript@1 |
2026-08-18 |
ケース
HOW- ゴール
- Handle bcryptjs parameter asymmetries in hash salt defaults, selective 60-character error throwing in compare, fallback random precedence, and custom Base64 encoding
- パッケージ
- シンボル
-
- bcryptjs.compareSync
- bcryptjs.compare
- bcryptjs.hashSync
- bcryptjs.hash
- bcryptjs.genSaltSync
- bcryptjs.genSalt
- bcryptjs.setRandomFallback
- bcryptjs.getRounds
- bcryptjs.getSalt
- bcryptjs.truncates
- bcryptjs.encodeBase64
- bcryptjs.decodeBase64
- 環境
- node
- 作成日
- 2026-08-17T15:40:43Z
コントラクト
- assert compareSync returns boolean false for mismatched hashes whose length is not 60, but throws an uncaught Error on 60-character invalid or unsupported revision strings, while async hash rejects with Illegal arguments unless rounds or salt is explicitly supplied
- assert hashSync defaults to 10 rounds producing a 60-character $2b$10$ hash when salt is omitted, whereas async hash without salt rejects with 'Illegal arguments: string, undefined'
- assert setRandomFallback does not override crypto.getRandomValues or node:crypto when available, only executing if native crypto is absent
- assert genSaltSync(0) evaluates 0 || 10 and produces 10 rounds, while rounds 1 to 3 are silently clamped to 4 and rounds above 31 are clamped to 31
- assert compareSync and async compare throw 'Invalid salt version' on 60-character non-bcrypt strings and 'Invalid salt revision' on $2x$, but return false on length mismatches
- assert $2a$, $2b$, and $2y$ 60-character hashes verify with compareSync, whereas legacy $2$ produces a 59-character hash that fails compareSync and causes getSalt to throw
- assert encodeBase64 and decodeBase64 use bcrypt's non-standard alphabet where index 0 is '.' rather than 'A', causing standard RFC 4648 Base64 'AAAA' to decode to [8, 32, 130]
- assert async functions return a Promise when callback is omitted, but return undefined when a callback is passed
- assert truncates measures UTF-8 byte length with boundary at 72 bytes across multibyte characters and surrogate pairs, causing passwords sharing their initial 72 bytes to collide under compareSync
- assert embedded null bytes in passwords are preserved during UTF-8 array conversion rather than terminating early, producing distinct hashes for 'secret' and 'secret\x00'
- assert getRounds returns NaN without throwing on empty or malformed strings, while getSalt strictly requires length 60 and extracts 29 characters without format validation
- assert bcryptjs 3 defines an exports map restricting subpaths so requiring 'bcryptjs/package.json' throws ERR_PACKAGE_PATH_NOT_EXPORTED
ファイル
- NOTES.md
- csx.json
- package-lock.json
- package.json
- src/index.mjs
- test/contract.mjs