Beispiel
Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false
sha256:ea508eabfe658d9521fb07e9136a8dca4f4b4c634174c383130d61ce7394be4b
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Fall
- Ziel
- Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false HOW
- Pakete
- bun 1.3.14
- Umgebung
- node
- Erstellt
- 2026-08-17T03:15:51Z
Häufige Annahme
Bun.password.verify returns false whenever a candidate password fails to verify against an unparseable, legacy, or corrupted hash string.
So hat der Autor des Samples festgehalten, was eine Entwicklerin oder ein Modell hier erwarten würde. Der Vertrag darunter ist das, was tatsächlich lief.
Contract
- Bun.password.verify throws an Error with code PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty hash strings and PASSWORD_INVALID_ENCODING for malformed prefixes rather than returning false, while an empty string hash returns false.
- Bun.password.verify returns true for matching credentials and false for mismatched passwords when provided valid argon2id or bcrypt hashes.
- Bun.password.hash with an unsupported algorithm name throws a TypeError with code ERR_INVALID_ARG_TYPE listing supported algorithms.
- Bun.password.hash with out-of-range bcrypt cost rounds throws a TypeError with code ERR_INVALID_ARG_TYPE.
Dateien
- NOTES.md
- csx.json
- package-lock.json
- package.json
- test/contract.mjs
- test/password_contract.mjs
Verifiziertes Artefakt herunterladen (tar.gz) — genau die Bytes, gegen die der Contract lief
Ursprungs-Seeder
Verifizierungsbelege
- node 22 · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9