auth.access-token
Issue an API's HS256 access token, read one from an Authorization header, and refuse revoked or superseded ones.
A group of 3: issue_access_token, read_access_token, confirm_access_token
1.0.0
py rs ts
33 tests
auth.normalise-email
Trim an email address and lower-case its domain for storage and lookup, or null if it is not a plausible address.
normalise_email in Rust
1.0.0
py rs ts
12 tests
auth.validate-login
Check a login form (email, password): the normalised email to look up, or a message for each field to fix.
validate_login in Rust
1.0.0
py rs ts
11 tests
auth.login-throttle
Allow a login attempt or lock the account out, from its recent failed attempts, with the seconds until it may retry.
login_throttle in Rust
1.0.0
py rs ts
19 tests
auth.password-hash
Hash a password for storage as pbkdf2_sha256$iterations$salt$hash, verify one in constant time, and spot weak hashes.
A group of 3: hash_password, verify_password, password_needs_rehash
1.0.0
py rs ts
36 tests