"""Quick smoke test: can the passwords in .env be verified? (No app imports.)""" import base64, hashlib, hmac, os from pathlib import Path from dotenv import load_dotenv load_dotenv(Path(__file__).parent / ".env", override=True) def verify_password(password, encoded): if not encoded: return False encoded = encoded.strip().strip("'\"") try: prefix, raw_iters, raw_salt, raw_digest = encoded.split("$") if prefix != "pbkdf2_sha256": return False salt = base64.b64decode(raw_salt) expected = base64.b64decode(raw_digest) iterations = int(raw_iters) except (ValueError, TypeError): return False candidate = hashlib.pbkdf2_hmac("sha256", password.encode("utf-8"), salt, iterations) return hmac.compare_digest(candidate, expected) admin_hash = os.environ.get("AUTH_ADMIN_PASSWORD_HASH", "").strip().strip("'\"") user_hash = os.environ.get("AUTH_USER_PASSWORD_HASH", "").strip().strip("'\"") print(f"Admin hash prefix: {admin_hash[:20]!r}") print(f"User hash prefix: {user_hash[:20]!r}") ok1 = verify_password("admin123", admin_hash) ok2 = verify_password("DevUser!2026", user_hash) if user_hash else True print(f"Admin password ('admin123') verify: {ok1}") if user_hash: print(f"User password ('DevUser!2026') verify: {ok2}") else: print("User account is optional / unset.") if ok1 and ok2: print("\nSUCCESS - admin password verifies cleanly. Login will work.") else: print("\nFAILURE - password verification failed.") exit(1)