CodeSampleX

Sample

bun 1.3.14: Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false

Verified sample for npm bun 1.3.14: Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and…

sha256:ea508eabfe658d9521fb07e9136a8dca4f4b4c634174c383130d61ce7394be4b

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-17
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false
Packages
Symbols
  • Bun.password.verify
  • Bun.password.hash
Environment
node
Created
2026-08-17T03:15:51Z

Contract

  1. Bun.password.verify throws an Error with code PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty hash strings and PASSWORD_INVALID_ENCODING for malformed prefixes rather than returning false, while an empty string hash returns false.
  2. Bun.password.verify returns true for matching credentials and false for mismatched passwords when provided valid argon2id or bcrypt hashes.
  3. Bun.password.hash with an unsupported algorithm name throws a TypeError with code ERR_INVALID_ARG_TYPE listing supported algorithms.
  4. Bun.password.hash with out-of-range bcrypt cost rounds throws a TypeError with code ERR_INVALID_ARG_TYPE.

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • test/contract.mjs
  • test/password_contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed