password

package
v0.147.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Index

Constants

View Source
const (
	ClassUppercase = "uppercase"
	ClassLowercase = "lowercase"
	ClassDigit     = "digit"
	ClassSymbol    = "symbol"
)

Character classes named by RequirementsError.Missing.

View Source
const MinIdentifierLength = 4

MinIdentifierLength is the shortest identifier a password may not contain.

Variables

View Source
var (
	ErrTooShort           = errors.New("password_too_short")
	ErrTooLong            = errors.New("password_too_long")
	ErrTooCommon          = errors.New("password_too_common")
	ErrContainsIdentifier = errors.New("password_contains_identifier")
)
View Source
var ErrInvalidHash = errors.New("invalid_password_hash")

ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.

Functions

func EmailLocalPart

func EmailLocalPart(email string) string

EmailLocalPart returns the part of email before its last '@', or "".

func HashArgon2id

func HashArgon2id(password string) (string, error)

HashArgon2id returns a PHC-encoded string.

func IsBcryptHash

func IsBcryptHash(hash string) bool

IsBcryptHash detects common bcrypt PHC prefixes.

func IsCommon

func IsCommon(pw string) bool

IsCommon reports whether pw (case-insensitive) is on the embedded blocklist.

func Validate

func Validate(p config.PasswordPolicy, pw string, identifiers ...string) error

Validate checks pw against a normalized policy. identifiers are the account's username and email local-part; pw may not contain any of at least MinIdentifierLength characters, compared case-insensitively.

func ValidateHash

func ValidateHash(hash, algorithm string) error

ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.

func VerifyArgon2id

func VerifyArgon2id(encoded, password string) (bool, error)

VerifyArgon2id checks a password against a PHC-encoded hash.

func VerifyBcrypt

func VerifyBcrypt(hash, password string) (bool, error)

VerifyBcrypt compares a bcrypt hash with a plaintext password.

Types

type Params

type Params struct {
	Time    uint32 // iterations
	Memory  uint32 // KiB
	Threads uint8
	SaltLen uint32
	KeyLen  uint32
}

Params defines Argon2id parameters.

func DefaultParams

func DefaultParams() Params

type RequirementsError

type RequirementsError struct{ Missing []string }

RequirementsError lists the required character classes a password lacks.

func (*RequirementsError) Error

func (e *RequirementsError) Error() string

Directories

Path Synopsis
internal
commongen command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL