Documentation
¶
Index ¶
- Constants
- Variables
- func EmailLocalPart(email string) string
- func HashArgon2id(password string) (string, error)
- func IsBcryptHash(hash string) bool
- func ValidateHash(hash, algorithm string) error
- func VerifyArgon2id(encoded, password string) (bool, error)
- func VerifyBcrypt(hash, password string) (bool, error)
- type Params
- type Policy
- type RequirementsError
Constants ¶
const ( DefaultMinLength = 8 DefaultMaxLength = 128 // MaxLengthCeiling bounds MaxLength so request bodies and KDF input stay small. MaxLengthCeiling = 1024 // MinIdentifierLength is the shortest identifier a password may not contain. MinIdentifierLength = 4 )
Default password length bounds, in characters (Unicode code points).
const ( ClassUppercase = "uppercase" ClassLowercase = "lowercase" ClassDigit = "digit" ClassSymbol = "symbol" )
Character classes named by RequirementsError.Missing.
Variables ¶
var ( ErrTooShort = errors.New("password_too_short") ErrTooLong = errors.New("password_too_long") ErrTooCommon = errors.New("password_too_common") ErrContainsIdentifier = errors.New("password_contains_identifier") )
var ErrInvalidHash = errors.New("invalid_password_hash")
ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.
Functions ¶
func EmailLocalPart ¶ added in v0.130.0
EmailLocalPart returns the part of email before its last '@', or "".
func HashArgon2id ¶
HashArgon2id returns a PHC-encoded string.
func IsBcryptHash ¶
IsBcryptHash detects common bcrypt PHC prefixes.
func ValidateHash ¶ added in v0.100.0
ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.
func VerifyArgon2id ¶
VerifyArgon2id checks a password against a PHC-encoded hash.
func VerifyBcrypt ¶
VerifyBcrypt compares a bcrypt hash with a plaintext password.
Types ¶
type Params ¶
type Params struct {
Time uint32 // iterations
Memory uint32 // KiB
Threads uint8
SaltLen uint32
KeyLen uint32
}
Params defines Argon2id parameters.
func DefaultParams ¶
func DefaultParams() Params
type Policy ¶ added in v0.129.0
type Policy struct {
MinLength int
MaxLength int
// Uppercase/lowercase/digit use Unicode categories (unicode.IsUpper,
// IsLower, IsDigit); a symbol is any rune that is neither a letter nor a
// digit, including spaces and punctuation.
RequireUppercase bool
RequireLowercase bool
RequireDigit bool
RequireSymbol bool
// AllowCommon disables the embedded common-password blocklist.
AllowCommon bool
}
Policy is the operator-configured password rule. The zero value is the NIST SP 800-63B-style default: 8..128 characters, no composition rules, common passwords rejected. Composition rules are opt-in.
func (Policy) Normalize ¶ added in v0.129.0
Normalize fills defaults and rejects an inconsistent policy.
type RequirementsError ¶ added in v0.130.0
type RequirementsError struct{ Missing []string }
RequirementsError lists the required character classes a password lacks.
func (*RequirementsError) Error ¶ added in v0.130.0
func (e *RequirementsError) Error() string