impl/rust/password_needs_rehash.rs
1,073 bytes · the Rust implementation · view raw
Imports name this capability’s declared dependencies, which fune builds next to it in your project; each one links to its page.
use super::funejson::Value; ← the fune runtime: the JSON value the test vectors use; fune build keeps it only where a signature takes one
use super::auth_password_hash_verify_password::parse_stored_hash; ← verifyPassword, another function of this group · built into the same file, even by a slim install
/// Was this hash made more weakly than hashes are made today? Call it after
/// a successful login and re-hash and save when it answers true.
///
/// # Panics
/// Panics on fewer than 1000 iterations or a stored string not in the
/// pbkdf2_sha256 form.
pub fn password_needs_rehash(stored: &str, iterations: i64) -> bool {
if iterations < 1000 {
panic!("iterations must be a whole number of at least 1000");
}
let (stored_iterations, salt, expected) = parse_stored_hash(stored);
stored_iterations < iterations || salt.len() < 16 || expected.len() != 32
}
pub fn fune_vector(args: &[Value]) -> Value {
let stored = match &args[0] {
Value::Str(s) => s.as_str(),
_ => panic!("stored password hash must be a string"),
};
let iterations = match &args[1] {
Value::Int(i) => *i,
_ => panic!("iterations must be a whole number of at least 1000"),
};
Value::Bool(password_needs_rehash(stored, iterations))
}