28 lines
791 B
Go
28 lines
791 B
Go
package bouncer
|
|
|
|
import "golang.org/x/crypto/bcrypt"
|
|
|
|
// HashPassword returns a bcrypt hash of plain at the given cost.
|
|
func HashPassword(cost int, plain string) (string, error) {
|
|
b, err := bcrypt.GenerateFromPassword([]byte(plain), cost)
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
return string(b), nil
|
|
}
|
|
|
|
// CheckPassword reports whether plain matches hash. A malformed hash returns false.
|
|
func CheckPassword(hash, plain string) bool {
|
|
return bcrypt.CompareHashAndPassword([]byte(hash), []byte(plain)) == nil
|
|
}
|
|
|
|
// NeedsRehash reports whether hash was produced below configuredCost.
|
|
// A hash bcrypt cannot parse needs a rehash.
|
|
func NeedsRehash(hash string, configuredCost int) bool {
|
|
cost, err := bcrypt.Cost([]byte(hash))
|
|
if err != nil {
|
|
return true
|
|
}
|
|
return cost < configuredCost
|
|
}
|