impl/python/password_needs_rehash.py
603 bytes · the Python implementation · view raw
Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.
from .auth_password_hash_verify_password import parse_stored_hash ← verifyPassword, another function of this group · built into the same file, even by a slim install
def password_needs_rehash(stored: str, iterations: int) -> bool:
"""Was this hash made more weakly than hashes are made today? Call it after
a successful login and re-hash and save when it answers True."""
if isinstance(iterations, bool) or not isinstance(iterations, int) or iterations < 1000:
raise ValueError("iterations must be a whole number of at least 1000")
stored_iterations, salt, expected = parse_stored_hash(stored)
return stored_iterations < iterations or len(salt) < 16 or len(expected) != 32