package settings import "testing" func TestHashPasswordRoundTrip(t *testing.T) { h := HashPassword("s3cret-密码") if !IsPasswordHashed(h) { t.Fatalf("哈希格式不对: %s", h) } if !VerifyPassword("s3cret-密码", h) { t.Fatal("正确密码校验失败") } if VerifyPassword("wrong", h) { t.Fatal("错误密码竟通过校验") } if h == HashPassword("s3cret-密码") { t.Fatal("盐值未随机化") } } func TestVerifyLegacyPlaintext(t *testing.T) { if !VerifyPassword("FileCodeBox2023", "FileCodeBox2023") { t.Fatal("旧版明文兼容校验失败") } if VerifyPassword("nope", "FileCodeBox2023") { t.Fatal("明文比较不应放行其他密码") } } func TestGenerateJWTSecretLength(t *testing.T) { s := GenerateJWTSecret() if len(s) < 32 { t.Fatalf("密钥太短: %d", len(s)) } if s == GenerateJWTSecret() { t.Fatal("密钥未随机化") } }