Files
zpan/server
saltboandClaude Opus 4.6 1071f8a343 fix(auth): use native scrypt to bypass Cloudflare Workers CPU limit
Better-auth's default password hasher is @noble/hashes scrypt (pure JS),
which consumes ~100-200ms of CPU per call. Cloudflare Workers' free tier
caps each request at 10ms of JS CPU time, so sign-up/sign-in consistently
fails with error 1102 after the initial cold-start burst budget runs out.
See better-auth/better-auth#8860 for the upstream bug.

Override emailAndPassword.password.hash/verify with node:crypto.scryptSync.
The native OpenSSL implementation runs in ~ms of wall time and is counted
as I/O rather than JS CPU time on CF Workers, so it does not touch the
CPU budget. Works identically on the Node/Docker entry because
node:crypto is native there too.

Verified end-to-end on https://af9a6fdc.zpan.pages.dev: 5 sequential
signups + 5 sequential signins all returned HTTP 200 (previously 4/4
consecutive signups hit error 1102 on the same deployment).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-11 11:19:49 -04:00
..