Functional Weave
Code in Rust

auth.password-hash@1.0.0

impl/rust/password_needs_rehash.rs

1,073 bytes · the Rust implementation · view raw

Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.

use super::funejson::Value;  ← the fune runtime: the JSON value the test vectors use; fune build keeps it only where a signature takes one
use super::auth_password_hash_verify_password::parse_stored_hash;  ← verifyPassword, another function of this group · built into the same file, even by a slim install

/// Was this hash made more weakly than hashes are made today? Call it after
/// a successful login and re-hash and save when it answers true.
///
/// # Panics
/// Panics on fewer than 1000 iterations or a stored string not in the
/// pbkdf2_sha256 form.
pub fn password_needs_rehash(stored: &str, iterations: i64) -> bool {
    if iterations < 1000 {
        panic!("iterations must be a whole number of at least 1000");
    }
    let (stored_iterations, salt, expected) = parse_stored_hash(stored);
    stored_iterations < iterations || salt.len() < 16 || expected.len() != 32
}

pub fn fune_vector(args: &[Value]) -> Value {
    let stored = match &args[0] {
        Value::Str(s) => s.as_str(),
        _ => panic!("stored password hash must be a string"),
    };
    let iterations = match &args[1] {
        Value::Int(i) => *i,
        _ => panic!("iterations must be a whole number of at least 1000"),
    };
    Value::Bool(password_needs_rehash(stored, iterations))
}