Skip to main content

authenticate

Function authenticate 

Source
pub async fn authenticate(
    username: &str,
    plaintext: &str,
    database: Arc<Database>,
) -> Result<AuthOutcome, Error>
Expand description

Checks a username and password, re-hashing the stored digest if it was written under parameters this build has moved past.

The KDF runs even when the username is unknown, against password::dummy_hash. Without that, an unknown user answers in microseconds and a known one in a quarter-second, and login latency enumerates the operator table.

Does not stamp last_login_at or create a session: a login is not complete until a session exists, which for a user with a second factor is two requests away. The caller decides when that happened.