Skip to content

提升admin密码变更和OIDC客户端密钥的bcrypt哈希成本至12 - #16

Open
saaa99999999 wants to merge 1 commit into
gjovanovicst:mainfrom
saaa99999999:fix/bcrypt-defaultcost-admin-password
Open

saaa99999999 wants to merge 1 commit into
gjovanovicst:mainfrom
saaa99999999:fix/bcrypt-defaultcost-admin-password

Conversation

@saaa99999999

Copy link
Copy Markdown

问题

在审计代码时发现, 包中的密码变更()和 包中的客户端密钥生成()使用了 (成本=10),而项目中其他所有密码哈希操作(user注册/密码重置/admin初始设置)统一使用成本12。

受影响位置

  • — admin GUI 密码变更使用 DefaultCost(10)
  • — OIDC 客户端密钥哈希使用 DefaultCost(10)

影响

Admin 账户拥有管理后台的完整访问权限(租户/应用/用户/RBAC 管理),其密码被以低于项目标准的成本进行哈希。根据项目 SECURITY.md 声明("bcrypt with cost factor 12")和 OWASP 建议,应该统一使用成本12。

值得注意的是:

  • 用户密码(user service)所有路径已正确使用成本12
  • Admin 初始密码(setup 命令)已正确使用成本12
  • 仅 admin 密码变更和 OIDC 密钥生成使用了 DefaultCost

修复

将两处 替换为 ,与项目中其他 bcrypt 调用保持一致。

admin密码变更(ChangePassword)和OIDC客户端密钥生成(generateClientSecret)
使用了bcrypt.DefaultCost(成本10),而项目中其他地方(用户密码、admin初始密码)
统一使用成本12。根据项目SECURITY.md声明和OWASP建议,统一提升至成本12。

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@gjovanovicst gjovanovicst self-assigned this May 17, 2026
@gjovanovicst gjovanovicst added the bug Something isn't working label May 17, 2026
@saaa99999999

Copy link
Copy Markdown
Author

CVE Request — Action Needed from Maintainer

This PR fixes security vulnerabilities. To assign a CVE number:

GitHub only issues CVEs from the official upstream repository, not from forks.

Please:

  1. Go to this repo → Security → Advisories → New draft security advisory
  2. Add @saaa99999999 as a collaborator
  3. I will populate the full vulnerability details (CVSS, CWE, data flow, PoC) and submit the CVE request

If you prefer, I can submit the CVE via MITRE (cveform.mitre.org) instead — just let me know.

Thank you for reviewing this PR!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants