fix(auth): VerifyPassword 校验 PHC 参数上下界

t/p=0 会使 argon2.IDKey panic、m 超大可 OOM;越界一律返回 false(round2 P2-8),补畸形参数用例。
This commit is contained in:
2026-09-08 17:32:52 +08:00
parent a35e7fdfd3
commit ba7d5dd01f
2 changed files with 34 additions and 2 deletions
+20
View File
@@ -31,6 +31,26 @@ func TestPasswordHashRoundtrip(t *testing.T) {
}
}
// TestVerifyPasswordMalformedParams 畸形 PHC 参数安全返回 false:
// t/p=0 会使 argon2.IDKey panic、m 巨大会 OOM(评审 round2 P2-8)。
func TestVerifyPasswordMalformedParams(t *testing.T) {
salt := "AAAAAAAAAAAAAAAAAAAAAA" // 16 字节 base64(raw std)
hash := "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" // 32 字节
bad := []string{
"$argon2id$v=19$m=19456,t=0,p=1$" + salt + "$" + hash,
"$argon2id$v=19$m=19456,t=2,p=0$" + salt + "$" + hash,
"$argon2id$v=19$m=999999999,t=2,p=1$" + salt + "$" + hash,
"$argon2id$v=19$m=19456,t=999,p=1$" + salt + "$" + hash,
"$argon2id$v=19$m=19456,t=2,p=99$" + salt + "$" + hash,
"$argon2id$v=19$m=19456,t=2,p=1$" + salt + "$AAAA", // 哈希长度异常
}
for _, h := range bad {
if VerifyPassword(h, "x") {
t.Errorf("畸形参数不应通过: %s", h)
}
}
}
func TestTokenAndStrength(t *testing.T) {
tok, err := NewToken()
if err != nil {