44 lines
1.5 KiB
Python
44 lines
1.5 KiB
Python
"""Quick smoke test: can the passwords in .env be verified? (No app imports.)"""
|
|
import base64, hashlib, hmac, os
|
|
from pathlib import Path
|
|
from dotenv import load_dotenv
|
|
|
|
load_dotenv(Path(__file__).parent / ".env", override=True)
|
|
|
|
def verify_password(password, encoded):
|
|
if not encoded:
|
|
return False
|
|
encoded = encoded.strip().strip("'\"")
|
|
try:
|
|
prefix, raw_iters, raw_salt, raw_digest = encoded.split("$")
|
|
if prefix != "pbkdf2_sha256":
|
|
return False
|
|
salt = base64.b64decode(raw_salt)
|
|
expected = base64.b64decode(raw_digest)
|
|
iterations = int(raw_iters)
|
|
except (ValueError, TypeError):
|
|
return False
|
|
candidate = hashlib.pbkdf2_hmac("sha256", password.encode("utf-8"), salt, iterations)
|
|
return hmac.compare_digest(candidate, expected)
|
|
|
|
admin_hash = os.environ.get("AUTH_ADMIN_PASSWORD_HASH", "").strip().strip("'\"")
|
|
user_hash = os.environ.get("AUTH_USER_PASSWORD_HASH", "").strip().strip("'\"")
|
|
|
|
print(f"Admin hash prefix: {admin_hash[:20]!r}")
|
|
print(f"User hash prefix: {user_hash[:20]!r}")
|
|
|
|
ok1 = verify_password("admin123", admin_hash)
|
|
ok2 = verify_password("DevUser!2026", user_hash) if user_hash else True
|
|
|
|
print(f"Admin password ('admin123') verify: {ok1}")
|
|
if user_hash:
|
|
print(f"User password ('DevUser!2026') verify: {ok2}")
|
|
else:
|
|
print("User account is optional / unset.")
|
|
|
|
if ok1 and ok2:
|
|
print("\nSUCCESS - admin password verifies cleanly. Login will work.")
|
|
else:
|
|
print("\nFAILURE - password verification failed.")
|
|
exit(1)
|