[E05-S01-T02] Password hashed with Argon2id #233

Open
opened 2026-08-27 00:17:15 +00:00 by kpcto · 0 comments
Owner

Parent story: [E05-S01] Administrator bootstrap (#72)

Intent

Hash the administrator password with Argon2id before storage.

Acceptance criteria

  • Administrator password is hashed with Argon2id before it is stored
  • Stored credential contains no plaintext or reversible password value

Explicitly out of scope

  • No universal/default password (E05-S01-T01)
  • Documented first-run bootstrap path (E05-S01-T03)
  • Secret/password log redaction (E05-S01-T04)

Test plan

  • Automated test asserts the stored hash uses Argon2id parameters

Rollback note

  • Revert hashing change; existing hashes are re-verified on next login

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E05-S01] Administrator bootstrap (#72) ## Intent Hash the administrator password with Argon2id before storage. ## Acceptance criteria - Administrator password is hashed with Argon2id before it is stored - Stored credential contains no plaintext or reversible password value ## Explicitly out of scope - No universal/default password (E05-S01-T01) - Documented first-run bootstrap path (E05-S01-T03) - Secret/password log redaction (E05-S01-T04) ## Test plan - Automated test asserts the stored hash uses Argon2id parameters ## Rollback note - Revert hashing change; existing hashes are re-verified on next login ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:17:15 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 00:17:15 +00:00
Sign in to join this conversation.