ok - hash returns a versioned string ok - random salts produce different hashes ok - versioned hash is recognized ok - plaintext is not recognized as a hash ok - hashed password verifies ok - hashed password is not legacy ok - current hash does not need rehashing ok - wrong hashed password is rejected ok - stored marked value cannot be replayed as the password ok - dummy verification never authenticates ok - dummy hash follows the runtime bcrypt default cost ok - credential guards are bytewise on MySQL and portable elsewhere ok - old hash parameters are detected ok - legacy plaintext verifies exactly ok - legacy plaintext is marked for migration ok - wrong legacy plaintext is rejected ok - unmarked hash-shaped plaintext remains a legacy credential ok - password zero is accepted and verifies ok - NUL password is rejected without an exception ok - leading and trailing NUL passwords are rejected before trimming ok - NUL password does not authenticate against a versioned hash ok - NUL password does not authenticate as a legacy credential ok - empty values cannot authenticate ok - empty passwords are not hashed ok - portal access without a credential is rejected ok - an existing credential allows portal access to be retained ok - password zero satisfies portal access validation ok - a NUL password fails before portal writes ok - edge NUL passwords fail before portal writes ok - sensitive DB errors cannot emit interpolated credentials ok - sensitive DB calls restore the application error callback ok - sensitive DB calls restore error handling after exceptions ALL PASSED