Skip to content

Verify production laddr password-hash format before staging cutover #25

@themightychris

Description

@themightychris

The laddr-import script writes legacy password hashes verbatim into LegacyPasswordCredential records, and the eventual account-claim endpoint will verify against them with whatever algorithm those hashes use.

Synthetic fixture data uses bcrypt (`$2y$10$...`) per common Emergence-PHP conventions, but we haven't inspected real production hashes yet. Before staging cutover:

  1. Pull the first ~20 `Password` values from a fresh production dump
  2. Confirm they all share a single algorithm prefix (`$2y$`, `$2a$`, `$6$`, etc.)
  3. If anything other than bcrypt appears, add a verifier in the account-claim plan and surface a warning in the import-laddr report

Filed as Follow-up from PR #24 (laddr-import).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions