password

package
v0.141.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 25, 2026 License: MIT Imports: 15 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultMinLength = 8
	DefaultMaxLength = 128
	// MaxLengthCeiling bounds MaxLength so request bodies and KDF input stay small.
	MaxLengthCeiling = 1024
	// MinIdentifierLength is the shortest identifier a password may not contain.
	MinIdentifierLength = 4
)

Default password length bounds, in characters (Unicode code points).

View Source
const (
	ClassUppercase = "uppercase"
	ClassLowercase = "lowercase"
	ClassDigit     = "digit"
	ClassSymbol    = "symbol"
)

Character classes named by RequirementsError.Missing.

Variables

View Source
var (
	ErrTooShort           = errors.New("password_too_short")
	ErrTooLong            = errors.New("password_too_long")
	ErrTooCommon          = errors.New("password_too_common")
	ErrContainsIdentifier = errors.New("password_contains_identifier")
)
View Source
var ErrInvalidHash = errors.New("invalid_password_hash")

ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.

Functions

func EmailLocalPart added in v0.130.0

func EmailLocalPart(email string) string

EmailLocalPart returns the part of email before its last '@', or "".

func HashArgon2id

func HashArgon2id(password string) (string, error)

HashArgon2id returns a PHC-encoded string.

func IsBcryptHash

func IsBcryptHash(hash string) bool

IsBcryptHash detects common bcrypt PHC prefixes.

func IsCommon added in v0.130.1

func IsCommon(pw string) bool

IsCommon reports whether pw (case-insensitive) is on the embedded blocklist.

func ValidateHash added in v0.100.0

func ValidateHash(hash, algorithm string) error

ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.

func VerifyArgon2id

func VerifyArgon2id(encoded, password string) (bool, error)

VerifyArgon2id checks a password against a PHC-encoded hash.

func VerifyBcrypt

func VerifyBcrypt(hash, password string) (bool, error)

VerifyBcrypt compares a bcrypt hash with a plaintext password.

Types

type Params

type Params struct {
	Time    uint32 // iterations
	Memory  uint32 // KiB
	Threads uint8
	SaltLen uint32
	KeyLen  uint32
}

Params defines Argon2id parameters.

func DefaultParams

func DefaultParams() Params

type Policy added in v0.129.0

type Policy struct {
	MinLength int
	MaxLength int
	// Uppercase/lowercase/digit use Unicode categories (unicode.IsUpper,
	// IsLower, IsDigit); a symbol is any rune that is neither a letter nor a
	// digit, including spaces and punctuation.
	RequireUppercase bool
	RequireLowercase bool
	RequireDigit     bool
	RequireSymbol    bool
	// AllowCommon disables the embedded common-password blocklist.
	AllowCommon bool
}

Policy is the operator-configured password rule. The zero value is the NIST SP 800-63B-style default: 8..128 characters, no composition rules, common passwords rejected. Composition rules are opt-in.

func (Policy) Normalize added in v0.129.0

func (p Policy) Normalize() (Policy, error)

Normalize fills defaults and rejects an inconsistent policy.

func (Policy) Validate added in v0.129.0

func (p Policy) Validate(pw string, identifiers ...string) error

Validate checks pw against a normalized policy. identifiers are the account's username and email local-part; pw may not contain any of at least MinIdentifierLength characters, compared case-insensitively.

type RequirementsError added in v0.130.0

type RequirementsError struct{ Missing []string }

RequirementsError lists the required character classes a password lacks.

func (*RequirementsError) Error added in v0.130.0

func (e *RequirementsError) Error() string

Directories

Path Synopsis
internal
commongen command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL