1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101
|
package bcrypt
import (
"crypto/hmac"
"crypto/sha256"
"encoding/base64"
"fmt"
"github.com/go-crypt/x/bcrypt"
)
// NewVariant converts an identifier string to a bcrypt.Variant.
func NewVariant(identifier string) (variant Variant) {
switch identifier {
case AlgIdentifier, AlgIdentifierVerA, AlgIdentifierVerX, AlgIdentifierVerY, "", VariantNameStandard, "common":
return VariantStandard
case AlgIdentifierVariantSHA256, VariantNameSHA256:
return VariantSHA256
default:
return VariantNone
}
}
// Variant is a variant of the bcrypt.Digest.
type Variant int
const (
// VariantNone is a variant of the bcrypt.Digest which is unknown.
VariantNone Variant = iota
// VariantStandard is the standard variant of bcrypt.Digest.
VariantStandard
// VariantSHA256 is the variant of bcrypt.Digest which hashes the password with HMAC-SHA256.
VariantSHA256
)
// String implements the fmt.Stringer returning a string representation of the bcrypt.Variant.
func (v Variant) String() (name string) {
switch v {
case VariantStandard:
return VariantNameStandard
case VariantSHA256:
return VariantNameSHA256
default:
return
}
}
// Prefix returns the bcrypt.Variant prefix identifier.
func (v Variant) Prefix() (prefix string) {
switch v {
case VariantStandard:
return AlgIdentifier
case VariantSHA256:
return AlgIdentifierVariantSHA256
default:
return
}
}
// PasswordMaxLength returns -1 if the variant has no max length, otherwise returns the maximum password length.
func (v Variant) PasswordMaxLength() int {
switch v {
case VariantSHA256:
return -1
default:
return PasswordInputSizeMax
}
}
// Encode formats the variant encoded bcrypt.Digest.
func (v Variant) Encode(cost int, version string, salt, key []byte) (f string) {
switch v {
case VariantStandard:
return fmt.Sprintf(EncodingFmt, version, cost, salt, key)
case VariantSHA256:
return fmt.Sprintf(EncodingFmtSHA256, v.Prefix(), version, cost, salt, key)
default:
return
}
}
// EncodeInput returns the appropriate algorithm input.
func (v Variant) EncodeInput(src, salt []byte) (dst []byte) {
switch v {
case VariantSHA256:
h := hmac.New(sha256.New, bcrypt.Base64Encode(salt))
h.Write(src)
digest := h.Sum(nil)
dst = make([]byte, base64.StdEncoding.EncodedLen(len(digest)))
base64.StdEncoding.Encode(dst, digest)
return dst
default:
return src
}
}
|