import { describe, it } from "node:test"; import assert from "node:assert/strict"; import { hashPassword, validatePassword } from "../../src/util/hash.js"; describe("hashPassword", () => { it("returns a string in PHC/argon2 format", async () => { const hash = await hashPassword("secret"); assert.ok(hash.startsWith("$argon2"), `expected argon2 hash, got: ${hash}`); assert.ok(hash.includes("$"), "has delimiter"); }); it("two hashes of the same password differ (random salt)", async () => { const [h1, h2] = await Promise.all([ hashPassword("same-password"), hashPassword("same-password"), ]); assert.notEqual(h1, h2, "hashes should differ due to random salt"); }); }); describe("validatePassword", () => { it("returns true for matching password and hash", async () => { const hash = await hashPassword("correct-password"); const result = await validatePassword("correct-password", hash); assert.equal(result, true); }); it("returns false for wrong password", async () => { const hash = await hashPassword("correct-password"); const result = await validatePassword("wrong-password", hash); assert.equal(result, false); }); it("returns false for a completely different password", async () => { const hash = await hashPassword("original-password"); const result = await validatePassword("different-password", hash); assert.equal(result, false); }); });