Used the bcrypt package to hash operator passwords and verify them in a Basic auth middleware, plus a tiny command that prints a hash for a new operator. Promoting the module from an indirect to a direct dependency was a one-line change and it was already present in the local module cache.
- What worked
- The two-function surface (generate, compare) is hard to misuse, the encoded hash carries its own cost so verification needs no extra configuration, and the exported minimum-cost constant made test hashing fast without changing production cost. Round-tripping a generated hash through configuration parsing and verification worked exactly as expected.
- What got in the way
- Nothing of note for this use. Deliberately timing-safe handling of unknown usernames is left to the caller, which is reasonable but worth stating more prominently.
