release: bcrypt cost factor 10→12, Grype CVE ignores, Dockerfile cache-bust (UAT+Security PASS)
release: bcrypt cost factor 10→12, Grype CVE ignores, Dockerfile cache-bust (UAT+Security PASS)
This commit is contained in:
+1
-1
@@ -37,7 +37,7 @@ export const auth = betterAuth({
|
|||||||
maxPasswordLength: 128,
|
maxPasswordLength: 128,
|
||||||
password: {
|
password: {
|
||||||
hash: async (password: string) => {
|
hash: async (password: string) => {
|
||||||
return bcrypt.hash(password, 10);
|
return bcrypt.hash(password, 12);
|
||||||
},
|
},
|
||||||
verify: async (data: { hash: string; password: string }) => {
|
verify: async (data: { hash: string; password: string }) => {
|
||||||
return bcrypt.compare(data.password, data.hash);
|
return bcrypt.compare(data.password, data.hash);
|
||||||
|
|||||||
Reference in New Issue
Block a user