Documentation
¶
Index ¶
- Constants
- Variables
- func EmailLocalPart(email string) string
- func HashArgon2id(ctx context.Context, password string) (string, error)
- func InFlightLimit() int64
- func IsBcryptHash(hash string) bool
- func IsCommon(pw string) bool
- func Validate(p config.PasswordPolicy, pw string, identifiers ...string) error
- func ValidateHash(hash, algorithm string) error
- func VerifyArgon2id(ctx context.Context, encoded, password string) (bool, error)
- func VerifyBcrypt(ctx context.Context, hash, password string) (bool, error)
- type Params
- type RequirementsError
Constants ¶
const ( ClassUppercase = "uppercase" ClassLowercase = "lowercase" ClassDigit = "digit" ClassSymbol = "symbol" )
Character classes named by RequirementsError.Missing.
const MinIdentifierLength = 4
MinIdentifierLength is the shortest identifier a password may not contain.
Variables ¶
var ( ErrTooShort = errors.New("password_too_short") ErrTooLong = errors.New("password_too_long") ErrTooCommon = errors.New("password_too_common") ErrContainsIdentifier = errors.New("password_contains_identifier") )
var ErrBusy = errmodel.E(errmodel.CodeServerBusy, errmodel.WithMeta("retry_after_seconds", int(busyWait/time.Second)))
ErrBusy is 503 server_busy with Retry-After: the password-hashing budget stayed full for busyWait.
var ErrInvalidHash = errors.New("invalid_password_hash")
ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.
Functions ¶
func EmailLocalPart ¶
EmailLocalPart returns the part of email before its last '@', or "".
func HashArgon2id ¶
HashArgon2id returns a PHC-encoded string, or ErrBusy (see work.go).
func InFlightLimit ¶ added in v0.148.0
func InFlightLimit() int64
InFlightLimit is the most memory, in bytes, password hashing holds at once: the budget, or a single hash of the costliest accepted parameters.
func IsBcryptHash ¶
IsBcryptHash detects common bcrypt PHC prefixes.
func Validate ¶
func Validate(p config.PasswordPolicy, pw string, identifiers ...string) error
Validate checks pw against a normalized policy. identifiers are the account's username and email local-part; pw may not contain any of at least MinIdentifierLength characters, compared case-insensitively.
func ValidateHash ¶
ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.
func VerifyArgon2id ¶
VerifyArgon2id checks a password against a PHC-encoded hash, or fails with ErrBusy (see work.go).
Types ¶
type Params ¶
type Params struct {
Time uint32 // iterations
Memory uint32 // KiB
Threads uint8
SaltLen uint32
KeyLen uint32
}
Params defines Argon2id parameters.
func DefaultParams ¶
func DefaultParams() Params
type RequirementsError ¶
type RequirementsError struct{ Missing []string }
RequirementsError lists the required character classes a password lacks.
func (*RequirementsError) Error ¶
func (e *RequirementsError) Error() string
Directories
¶
| Path | Synopsis |
|---|---|
|
internal
|
|
|
commongen
command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
|
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`. |