mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-20 13:30:46 +02:00
- SetPassword now returns an error instead of silently truncating passwords >72 bytes (the prior fallback could also panic for short passwords when bcrypt returned any non-ErrPasswordTooLong error). - CheckPassword is now pure and reports (ok, legacy); migration moves to FileStore.migrateLegacyPassword under a write lock to fix a data race on concurrent logins and a double-check avoids redundant re-hashing. - ValidatePassword only rewrites the user store when a migration actually happened, eliminating a full file rewrite on every successful login. - Legacy plaintext comparison uses subtle.ConstantTimeCompare again, restoring the pre-PR constant-time property. - CreateUser propagates SetPassword errors and releases the write lock before calling saveUsers to avoid recursive RWMutex locking. - Add unit tests covering new-user hashing, legacy migration, no-rewrite on normal login, wrong/empty passwords, oversize password rejection, and concurrent migration under -race.