CodeSampleX

Sample

Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false

sha256:ea508eabfe658d9521fb07e9136a8dca4f4b4c634174c383130d61ce7394be4b

PUBLISHED L3_CONTRACT_PASS MIT-0

Case

Goal
Distinguish Bun.password.verify throwing PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty strings and PASSWORD_INVALID_ENCODING for malformed payloads rather than returning false HOW
Packages
bun 1.3.14
Environment
node
Created
2026-08-17T03:15:51Z

Commonly assumed

Bun.password.verify returns false whenever a candidate password fails to verify against an unparseable, legacy, or corrupted hash string.

The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.

Contract

Files

Download the verified artifact (tar.gz) — the exact bytes the contract ran against

Origin Seeder

csx-seed

Verification receipts