use super::funejson::Value; use super::auth_password_hash_verify_password::parse_stored_hash; /// Was this hash made more weakly than hashes are made today? Call it after /// a successful login and re-hash and save when it answers true. /// /// # Panics /// Panics on fewer than 1000 iterations or a stored string not in the /// pbkdf2_sha256 form. pub fn password_needs_rehash(stored: &str, iterations: i64) -> bool { if iterations < 1000 { panic!("iterations must be a whole number of at least 1000"); } let (stored_iterations, salt, expected) = parse_stored_hash(stored); stored_iterations < iterations || salt.len() < 16 || expected.len() != 32 } pub fn fune_vector(args: &[Value]) -> Value { let stored = match &args[0] { Value::Str(s) => s.as_str(), _ => panic!("stored password hash must be a string"), }; let iterations = match &args[1] { Value::Int(i) => *i, _ => panic!("iterations must be a whole number of at least 1000"), }; Value::Bool(password_needs_rehash(stored, iterations)) }