123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112 |
- // MIT (c) alexedwards [https://gist.github.com/alexedwards/34277fae0f48abe36822b375f0f6a621]
- // move to https://github.com/alexedwards/argon2id instead of vendoring
- package main
- import (
- "crypto/rand"
- "crypto/subtle"
- "encoding/base64"
- "errors"
- "fmt"
- "strings"
- "golang.org/x/crypto/argon2"
- )
- var (
- ErrInvalidHash = errors.New("the encoded hash is not in the correct format")
- ErrIncompatibleVersion = errors.New("incompatible version of argon2")
- )
- type params struct {
- memory uint32
- iterations uint32
- parallelism uint8
- saltLength uint32
- keyLength uint32
- }
- func GenerateFromPassword(password string) (encodedHash string, err error) {
- p := ¶ms{
- memory: 64 * 1024,
- iterations: 3,
- parallelism: 2,
- saltLength: 16,
- keyLength: 32,
- }
- salt, err := generateRandomBytes(p.saltLength)
- if err != nil {
- return "", err
- }
- hash := argon2.IDKey([]byte(password), salt, p.iterations, p.memory, p.parallelism, p.keyLength)
- b64Salt := base64.RawStdEncoding.EncodeToString(salt)
- b64Hash := base64.RawStdEncoding.EncodeToString(hash)
- encodedHash = fmt.Sprintf("$argon2id$v=%d$m=%d,t=%d,p=%d$%s$%s", argon2.Version, p.memory, p.iterations, p.parallelism, b64Salt, b64Hash)
- return encodedHash, nil
- }
- func generateRandomBytes(n uint32) ([]byte, error) {
- b := make([]byte, n)
- _, err := rand.Read(b)
- if err != nil {
- return nil, err
- }
- return b, nil
- }
- func ComparePasswordAndHash(password, encodedHash string) (match bool, err error) {
- p, salt, hash, err := decodeHash(encodedHash)
- if err != nil {
- return false, err
- }
- otherHash := argon2.IDKey([]byte(password), salt, p.iterations, p.memory, p.parallelism, p.keyLength)
- if subtle.ConstantTimeCompare(hash, otherHash) == 1 {
- return true, nil
- }
- return false, nil
- }
- func decodeHash(encodedHash string) (p *params, salt, hash []byte, err error) {
- vals := strings.Split(encodedHash, "$")
- if len(vals) != 6 {
- return nil, nil, nil, ErrInvalidHash
- }
- var version int
- _, err = fmt.Sscanf(vals[2], "v=%d", &version)
- if err != nil {
- return nil, nil, nil, err
- }
- if version != argon2.Version {
- return nil, nil, nil, ErrIncompatibleVersion
- }
- p = ¶ms{}
- _, err = fmt.Sscanf(vals[3], "m=%d,t=%d,p=%d", &p.memory, &p.iterations, &p.parallelism)
- if err != nil {
- return nil, nil, nil, err
- }
- salt, err = base64.RawStdEncoding.DecodeString(vals[4])
- if err != nil {
- return nil, nil, nil, err
- }
- p.saltLength = uint32(len(salt))
- hash, err = base64.RawStdEncoding.DecodeString(vals[5])
- if err != nil {
- return nil, nil, nil, err
- }
- p.keyLength = uint32(len(hash))
- return p, salt, hash, nil
- }
|