import argon2 from 'argon2'; import crypto from 'node:crypto'; export class AuthService { /** * Hashes a raw password using the Argon2id industry standard. */ async hashPassword(password: string): Promise { return argon2.hash(password, { type: argon2.argon2id, // Strongest configuration variant against timing attacks memoryCost: 2 ** 16, // 64MB memory utilization block timeCost: 3, // 3 computational passes }); } /** * Cryptographically verifies a password against a known hash. */ async verifyPassword(password: string, hash: string): Promise { try { return await argon2.verify(hash, password); } catch { return false; // Safely catches malformed hashes without crashing } } /** * Generates a unique, high-entropy 64-character hex session token. */ generateSessionToken(): string { return crypto.randomBytes(32).toString('hex'); } }