Repository navigation
crypto.pbkdf2Sync can't handle non ASCII character in Node 6.9.2 #10265
Description
Activity
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on Dec 14, 2016 - addedduplicateIssues and PRs that are duplicates of other issues or PRs.Issues and PRs that are duplicates of other issues or PRs.questionIssues asking questions about Node.js.Issues asking questions about Node.js.
on Dec 14, 2016 Yes, the default encoding for the crypto methods changed in v6.x from
latin1/binarytoutf8. If you know that you rely on a specific encoding, you might want to pass in aBuffertopbkdf2Sync(e.g.pbkdf2Sync(Buffer.from(password, "latin1"), …)).I’m closing this as this is expected behaviour, but please feel free to ask follow-up questions!
@addaleax shouldn't this be documented? https://nodejs.org/api/crypto.html#crypto_crypto_pbkdf2_password_salt_iterations_keylen_digest_callback says it was added in 0.5.5, it doesn't say it was changed in 6.x.
Reacted by David- addeddocIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Dec 14, 2016 @sam-github Yeah, maybe there should be a mention of that. It applies to virtually all
cryptofunctions, though.Then docs are needed for all crypto functions, either in each one, or once at the top of the docs.
I looked in the changelog and tried to find if any changes was made to "pbkdf2Sync", but I did not look for crypto.
Information about the crypto encoding change has been added in d27c983, I’ll closed this as a fixed issue.
After upgrading our servers from Node 4 to Node 6. I was not able to login with my password anymore, while my colleagues had no problem logging in. After some research I found that since my password contained the letter 'ö' the crypto.pbkdf2Sync failed to create the same hash in Node 6 as in Node 4. So it is broken for non ASCII characters like 'åäö'.
I made the following test that shows that the error started in version 6.0.0 of node.