Documentation
¶
Index ¶
Constants ¶
View Source
const ( DefaultMinLength = 8 DefaultMaxLength = 128 // MaxLengthCeiling bounds MaxLength so request bodies and KDF input stay small. MaxLengthCeiling = 1024 )
Default password length bounds, in characters (Unicode code points).
Variables ¶
View Source
var ( ErrTooShort = errors.New("password_too_short") ErrTooLong = errors.New("password_too_long") )
View Source
var ErrInvalidHash = errors.New("invalid_password_hash")
ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.
Functions ¶
func HashArgon2id ¶
HashArgon2id returns a PHC-encoded string.
func IsBcryptHash ¶
IsBcryptHash detects common bcrypt PHC prefixes.
func ValidateHash ¶ added in v0.100.0
ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.
func VerifyArgon2id ¶
VerifyArgon2id checks a password against a PHC-encoded hash.
func VerifyBcrypt ¶
VerifyBcrypt compares a bcrypt hash with a plaintext password.
Types ¶
type Params ¶
type Params struct {
Time uint32 // iterations
Memory uint32 // KiB
Threads uint8
SaltLen uint32
KeyLen uint32
}
Params defines Argon2id parameters.
func DefaultParams ¶
func DefaultParams() Params
Click to show internal directories.
Click to hide internal directories.