Coverage for server / authentication / bcrypter.py: 100%

7 statements  

« prev     ^ index     » next       coverage.py v7.13.4, created at 2026-10-04 09:33 +0000

1# TEST-ONLY as of SEC-4. Auth0 is the sole authentication authority. 

2# 

3# Nothing under server/ imports this any more: the last production caller was 

4# database.create_user, which seeded admin/staff accounts with a bcrypt hash. 

5# It now stores password="" like every other Auth0-provisioned account, so no 

6# local credential is written at runtime. 

7# 

8# What remains are ~20 test modules that call hash_password purely to populate 

9# the Account model's required `password` field. That is not a credential store 

10# — nothing verifies these hashes, in tests or in production — so this module is 

11# kept rather than rewritten across every one of those files in a security PR. 

12# 

13# DO NOT ADD PRODUCTION CALLERS. Removing it entirely is a mechanical test-only 

14# cleanup, tracked separately. 

15from passlib.context import CryptContext 

16 

17pwd_context = CryptContext(schemes=["bcrypt"], deprecated="auto", bcrypt__rounds=12) 

18 

19 

20class Hasher: 

21 def __init__(self): 

22 pass 

23 

24 def hash_password(self, password: str): 

25 """ 

26 Hash a password using bcrypt encryption. 

27 

28 Args: 

29 password (str): The plain text password to be hashed. 

30 

31 Returns: 

32 str: The hashed password string. 

33 """ 

34 return pwd_context.hash(password)