password

package
v1.0.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 21 Imported by: 0

Documentation

Index

Constants

View Source
const (
	ClassUppercase = "uppercase"
	ClassLowercase = "lowercase"
	ClassDigit     = "digit"
	ClassSymbol    = "symbol"
)

Character classes named by RequirementsError.Missing.

View Source
const MinIdentifierLength = 4

MinIdentifierLength is the shortest identifier a password may not contain.

Variables

View Source
var (
	ErrTooShort           = errors.New("password_too_short")
	ErrTooLong            = errors.New("password_too_long")
	ErrTooCommon          = errors.New("password_too_common")
	ErrContainsIdentifier = errors.New("password_contains_identifier")
)

ErrBusy is 503 server_busy with Retry-After: the password-hashing budget stayed full for busyWait.

View Source
var ErrInvalidHash = errors.New("invalid_password_hash")

ErrInvalidHash means a stored hash is malformed or outside the supported work policy. Callers may require a password reset; verification never runs its KDF.

Functions

func EmailLocalPart

func EmailLocalPart(email string) string

EmailLocalPart returns the part of email before its last '@', or "".

func HashArgon2id

func HashArgon2id(ctx context.Context, password string) (string, error)

HashArgon2id returns a PHC-encoded string, or ErrBusy (see work.go).

func InFlightLimit added in v0.148.0

func InFlightLimit() int64

InFlightLimit is the most memory, in bytes, password hashing holds at once: the budget, or a single hash of the costliest accepted parameters.

func IsBcryptHash

func IsBcryptHash(hash string) bool

IsBcryptHash detects common bcrypt PHC prefixes.

func IsCommon

func IsCommon(pw string) bool

IsCommon reports whether pw (case-insensitive) is on the embedded blocklist.

func Validate

func Validate(p config.PasswordPolicy, pw string, identifiers ...string) error

Validate checks pw against a normalized policy. identifiers are the account's username and email local-part; pw may not contain any of at least MinIdentifierLength characters, compared case-insensitively.

func ValidateHash

func ValidateHash(hash, algorithm string) error

ValidateHash checks a supported hash without computing the password KDF. The algorithm must be explicit; imports normalize their source format.

func VerifyArgon2id

func VerifyArgon2id(ctx context.Context, encoded, password string) (bool, error)

VerifyArgon2id checks a password against a PHC-encoded hash, or fails with ErrBusy (see work.go).

func VerifyBcrypt

func VerifyBcrypt(ctx context.Context, hash, password string) (bool, error)

VerifyBcrypt compares a bcrypt hash with a plaintext password, or fails with ErrBusy (see work.go).

Types

type Params

type Params struct {
	Time    uint32 // iterations
	Memory  uint32 // KiB
	Threads uint8
	SaltLen uint32
	KeyLen  uint32
}

Params defines Argon2id parameters.

func DefaultParams

func DefaultParams() Params

type RequirementsError

type RequirementsError struct{ Missing []string }

RequirementsError lists the required character classes a password lacks.

func (*RequirementsError) Error

func (e *RequirementsError) Error() string

Directories

Path Synopsis
internal
commongen command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL