Skip to content

fix(security): Hash passwords with scrypt instead of SHA-256 - #22

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-hashing
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-hashing

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

CodeQL py/weak-sensitive-data-hashing: gateway login, user
creation and tenant admin creation stored unsalted SHA-256 of the
password, which is cheap to brute-force offline.

Add password_hasher (stdlib scrypt, random salt, constant-time
compare) and use it in all three places. Existing SHA-256 hashes
still verify and are replaced with scrypt on the next successful
login, so no user has to reset a password. The E2E seed now uses
the same hasher instead of its own SHA-256 copy.

🤖 Generated with Claude Code

CodeQL py/weak-sensitive-data-hashing: gateway login, user
creation and tenant admin creation stored unsalted SHA-256 of the
password, which is cheap to brute-force offline.

Add password_hasher (stdlib scrypt, random salt, constant-time
compare) and use it in all three places. Existing SHA-256 hashes
still verify and are replaced with scrypt on the next successful
login, so no user has to reset a password. The E2E seed now uses
the same hasher instead of its own SHA-256 copy.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
Comment thread services/platform/gateway/oneerp_gateway_app/services/password_hasher.py Dismissed
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit d8d9bda into main Oct 6, 2026
5 of 7 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the fix/codeql-hashing branch October 6, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants