34 lines
1.0 KiB
TypeScript
34 lines
1.0 KiB
TypeScript
import argon2 from 'argon2';
|
|
import crypto from 'node:crypto';
|
|
|
|
export class AuthService {
|
|
/**
|
|
* Hashes a raw password using the Argon2id industry standard.
|
|
*/
|
|
async hashPassword(password: string): Promise<string> {
|
|
return argon2.hash(password, {
|
|
type: argon2.argon2id, // Strongest configuration variant against timing attacks
|
|
memoryCost: 2 ** 16, // 64MB memory utilization block
|
|
timeCost: 3, // 3 computational passes
|
|
});
|
|
}
|
|
|
|
/**
|
|
* Cryptographically verifies a password against a known hash.
|
|
*/
|
|
async verifyPassword(password: string, hash: string): Promise<boolean> {
|
|
try {
|
|
return await argon2.verify(hash, password);
|
|
} catch {
|
|
return false; // Safely catches malformed hashes without crashing
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Generates a unique, high-entropy 64-character hex session token.
|
|
*/
|
|
generateSessionToken(): string {
|
|
return crypto.randomBytes(32).toString('hex');
|
|
}
|
|
}
|