password

package
v0.129.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultMinLength = 8
	DefaultMaxLength = 128
	// MaxLengthCeiling bounds MaxLength so request bodies and KDF input stay small.
	MaxLengthCeiling = 1024
)

Default password length bounds, in characters (Unicode code points).

Variables

View Source
var (
	ErrTooShort = errors.New("password_too_short")
	ErrTooLong  = errors.New("password_too_long")
)
View Source
var ErrInvalidHash = errors.New("invalid_password_hash")

ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.

Functions

func HashArgon2id

func HashArgon2id(password string) (string, error)

HashArgon2id returns a PHC-encoded string.

func IsBcryptHash

func IsBcryptHash(hash string) bool

IsBcryptHash detects common bcrypt PHC prefixes.

func ValidateHash added in v0.100.0

func ValidateHash(hash, algorithm string) error

ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.

func VerifyArgon2id

func VerifyArgon2id(encoded, password string) (bool, error)

VerifyArgon2id checks a password against a PHC-encoded hash.

func VerifyBcrypt

func VerifyBcrypt(hash, password string) (bool, error)

VerifyBcrypt compares a bcrypt hash with a plaintext password.

Types

type Params

type Params struct {
	Time    uint32 // iterations
	Memory  uint32 // KiB
	Threads uint8
	SaltLen uint32
	KeyLen  uint32
}

Params defines Argon2id parameters.

func DefaultParams

func DefaultParams() Params

type Policy added in v0.129.0

type Policy struct {
	MinLength int
	MaxLength int
}

Policy is the operator-configured password rule. Zero fields take defaults.

func (Policy) Normalize added in v0.129.0

func (p Policy) Normalize() (Policy, error)

Normalize fills defaults and rejects an inconsistent policy.

func (Policy) Validate added in v0.129.0

func (p Policy) Validate(pw string) error

Validate checks pw's length in characters against a normalized policy.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL