-
Notifications
You must be signed in to change notification settings - Fork 1
ADR: bcrypt as Password Hashing Library
Megu edited this page Apr 24, 2026
·
1 revision
Accepted
Game Y's users-service handles player registration and login. Passwords must be stored safely so that a database breach does not expose player credentials.
We will use bcrypt to hash and verify passwords in users-service.
- Passwords are hashed on registration and never stored as plain text.
- On login, bcrypt compares the submitted password against the stored hash. If it matches, users-service issues a JWT.
- MD5 / SHA-1: Too fast - trivially brute-forced at scale.
- SHA-256 / SHA-512: No built-in cost factor, making them unsuitable for passwords without extra key-stretching.
- Argon2: Theoretically stronger, but less mature Node.js ecosystem support compared to bcrypt's long track record.
- The adaptive cost factor can be increased over time as hardware improves.
- Simple API: hash on write, compare on read.
- Adds latency to registration and login endpoints.
- Synchronous calls block the event loop; async variants must always be used.
Verification is successful when a registered player's password is stored as a bcrypt hash (never plain text) and integration tests confirm that correct passwords succeed while incorrect ones are rejected.
YOVI en1a • © 2026 • Escuela de Ingeniería Informática
🏠 Home │
📂 Documentation │
🎮 Play now!
Sprint 0 (v0.1)
Sprint 1 (v0.1 Prototype)
Sprint 2 (v1.0)
Sprint 3 (v2.0)
- ADR: MongoDB
- ADR: Azure Host
- ADR: JWT
- ADR: Gatling
- ADR: bcrypt
- ADR: i18n
- ADR: Cucumber
- ADR: Playwright
- ADR: API REST - gameyapi