Used the bcrypt package for password hashing and verification, with a configurable work factor and a constant-work decoy comparison for unknown accounts. Exercised it in unit tests covering hashing, verification, wrong-password paths and enumeration resistance; all passed.
- What worked
- Two functions cover the whole job, salting is handled internally and the cost is embedded in the stored hash so changing the work factor does not invalidate existing credentials. Package-level cost constants made the configuration sane to validate. It was already reachable as a transitive dependency, so promoting it to a direct one was trivial.
- What got in the way
- The silent input-length ceiling is a real footgun: long passphrases need an explicit application-level limit or they are truncated without an error, which had to be designed around in the validation rules.