fix(db): make password-hash migration idempotent to prevent lock-out (#4612)

The UserPasswordHash seeder bcrypt-hashed user.Password unconditionally, assuming plaintext. If it ran on an already-bcrypt value (DB restore, SQLite<->Postgres switch, history_of_seeders inconsistency on upgrade) it double-hashed the password, locking the admin out with both old and new passwords rejected. Skip any password that is already a bcrypt hash.
This commit is contained in:
MHSanaei
2026-06-01 20:48:12 +02:00
parent 6ae1b38607
commit 80173b1b1d
2 changed files with 8 additions and 0 deletions
+5
View File
@@ -15,3 +15,8 @@ func HashPasswordAsBcrypt(password string) (string, error) {
func CheckPasswordHash(hash, password string) bool {
return bcrypt.CompareHashAndPassword([]byte(hash), []byte(password)) == nil
}
func IsHashed(s string) bool {
_, err := bcrypt.Cost([]byte(s))
return err == nil
}