Files
summercms/wristband/crypto.go
Jakub Zych c026b83f41 test(08-02): add failing RFC 7591 registration RED test in wristband
- TestPhase8RedRegistration asserts the exact public-client DCR success
  contract and fails while Server.Register is a 501 stub
- adds the Backend/Tx transaction-scoped store bundle (ClientStore,
  AuthCodeStore, RefreshTokenStore, AccessTokenIssuer) and wristband's own
  in-memory implementation for framework-level tests (D-07)
- adds crypto.go's fixed-transform helpers (random base64url, sha256 hex,
  constant-time compare, S256) and Options/Server seams for the DCR
  lifetimes, cap, sweep age and 64 KiB body bound (D-03/D-21)
2026-09-23 19:37:03 +02:00

42 lines
1.3 KiB
Go

package wristband
import (
"crypto/rand"
"crypto/sha256"
"crypto/subtle"
"encoding/base64"
"encoding/hex"
)
// randomBase64URL returns n cryptographically random bytes, base64url
// (RawURLEncoding, no padding) encoded, matching PHP's
// rtrim(strtr(base64_encode(random_bytes(n)), '+/', '-_'), '=') byte for
// byte (D-01/D-04).
func randomBase64URL(n int) (string, error) {
buf := make([]byte, n)
if _, err := rand.Read(buf); err != nil {
return "", err
}
return base64.RawURLEncoding.EncodeToString(buf), nil
}
// sha256Hex is the fixed transform every opaque secret (client secret, code,
// refresh token) is compared and persisted through: never the raw variable-
// length secret (D-04).
func sha256Hex(raw string) string {
sum := sha256.Sum256([]byte(raw))
return hex.EncodeToString(sum[:])
}
// constantEqual compares two fixed-transform strings (sha256 hex digests or
// PKCE S256 challenges) in constant time (D-04; RFC 7636 verifier compare).
func constantEqual(a, b string) bool {
return subtle.ConstantTimeCompare([]byte(a), []byte(b)) == 1
}
// s256Challenge is the RFC 7636 S256 transform: base64url(sha256(verifier)).
func s256Challenge(verifier string) string {
sum := sha256.Sum256([]byte(verifier))
return base64.RawURLEncoding.EncodeToString(sum[:])
}