Skip to content

ADR: bcrypt as Password Hashing Library

Megu edited this page Apr 24, 2026 · 1 revision

Status

Accepted

Context

Game Y's users-service handles player registration and login. Passwords must be stored safely so that a database breach does not expose player credentials.

Decision

We will use bcrypt to hash and verify passwords in users-service.

  • Passwords are hashed on registration and never stored as plain text.
  • On login, bcrypt compares the submitted password against the stored hash. If it matches, users-service issues a JWT.

Alternatives

  • MD5 / SHA-1: Too fast - trivially brute-forced at scale.
  • SHA-256 / SHA-512: No built-in cost factor, making them unsuitable for passwords without extra key-stretching.
  • Argon2: Theoretically stronger, but less mature Node.js ecosystem support compared to bcrypt's long track record.

Consequences

Positive

  • The adaptive cost factor can be increased over time as hardware improves.
  • Simple API: hash on write, compare on read.

Negative

  • Adds latency to registration and login endpoints.
  • Synchronous calls block the event loop; async variants must always be used.

Verification

Verification is successful when a registered player's password is stored as a bcrypt hash (never plain text) and integration tests confirm that correct passwords succeed while incorrect ones are rejected.

Clone this wiki locally