db: store all credentials in one SHA-256-hashed table

API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
This commit is contained in:
Kristoffer Dalby
2026-09-23 16:12:18 +00:00
committed by Kristoffer Dalby
parent e90500e3a9
commit 393dd3e2d9
39 changed files with 2176 additions and 680 deletions
+12 -5
View File
@@ -1,6 +1,7 @@
package integration
import (
"strconv"
"testing"
"time"
@@ -72,11 +73,17 @@ func TestApiKeyCommand(t *testing.T) {
assert.Len(t, listedAPIKeys, 5)
assert.Equal(t, "1", listedAPIKeys[0].Id)
assert.Equal(t, "2", listedAPIKeys[1].Id)
assert.Equal(t, "3", listedAPIKeys[2].Id)
assert.Equal(t, "4", listedAPIKeys[3].Id)
assert.Equal(t, "5", listedAPIKeys[4].Id)
// IDs are drawn from the shared credentials table, so they are not
// guaranteed to start at 1 (pre-auth keys created during env setup take the
// first ids). They are still listed in strictly increasing creation order.
var prevID uint64
for _, key := range listedAPIKeys {
id, err := strconv.ParseUint(key.Id, 10, 64)
require.NoError(t, err)
assert.Greater(t, id, prevID, "API key ids must be strictly increasing")
prevID = id
}
assert.NotEmpty(t, listedAPIKeys[0].Prefix)
assert.NotEmpty(t, listedAPIKeys[1].Prefix)