import crypto from 'node:crypto'; const keyLength = 64; export function hashPassword(password, salt = crypto.randomBytes(16).toString('hex')) { const hash = crypto.scryptSync(String(password), salt, keyLength).toString('hex'); return `scrypt$${salt}$${hash}`; } export function verifyPassword(password, storedHash) { const [algorithm, salt, hash] = String(storedHash || '').split('$'); if (algorithm !== 'scrypt' || !salt || !hash) return false; const candidate = hashPassword(password, salt).split('$')[2]; return crypto.timingSafeEqual(Buffer.from(hash, 'hex'), Buffer.from(candidate, 'hex')); } export function randomToken(bytes = 32) { return crypto.randomBytes(bytes).toString('hex'); }