Documentation
¶
Overview ¶
Package auth hashes passwords, enforces their policy and throttles login attempts.
Index ¶
- Constants
- Variables
- func BearerToken(r *http.Request) (string, bool)
- func HashPassword(password string) (string, error)
- func PeerHost(r *http.Request) string
- func SpendHashingTime(password string)
- func ValidatePassword(username, password string) error
- func VerifyPassword(password, encoded string) (bool, error)
- type Limiter
- type Proxies
Constants ¶
const ( // MinPasswordLength and MaxPasswordLength bound what is accepted: the lower // bound against guessing, the upper against a request that makes the // server hash megabytes. MinPasswordLength = 12 MaxPasswordLength = 128 )
Variables ¶
var ErrBusy = errors.New("too many passwords are being checked at once")
ErrBusy is returned when too many passwords are being hashed at once.
Functions ¶
func BearerToken ¶ added in v1.1.0
BearerToken returns the token of an "Authorization: Bearer" header.
func HashPassword ¶
HashPassword returns an encoded argon2id hash with a random salt.
func PeerHost ¶ added in v1.1.0
PeerHost is the address of the connection, not of a client behind a proxy.
func SpendHashingTime ¶ added in v1.1.0
func SpendHashingTime(password string)
SpendHashingTime does the work of a verification that cannot succeed, so that answering for an unknown user takes as long as for a known one.
func ValidatePassword ¶
ValidatePassword reports why a password is refused.
func VerifyPassword ¶
VerifyPassword compares a password with an encoded hash in constant time. An error means the hash itself is unusable, not that the password is wrong.
Types ¶
type Limiter ¶ added in v1.1.0
type Limiter struct {
// contains filtered or unexported fields
}
Limiter refuses a key once it failed too many times within a window.
func NewLimiter ¶ added in v1.1.0
NewLimiter allows max failures per key in each window.
type Proxies ¶ added in v1.1.0
type Proxies struct {
// contains filtered or unexported fields
}
Proxies are the reverse proxies trusted to say who the client is. Behind a proxy every request shares its address, so the failure limits would lock everyone out together. The zero value trusts none.
func ParseProxies ¶ added in v1.1.0
ParseProxies reads addresses or CIDR ranges of proxies. A range that holds every address is refused: it would trust every sender.