pub async fn authenticate(
username: &str,
plaintext: &str,
database: Arc<Database>,
) -> Result<AuthOutcome, Error>Expand description
Checks a username and password, re-hashing the stored digest if it was written under parameters this build has moved past.
The KDF runs even when the username is unknown, against
password::dummy_hash. Without that, an unknown user answers in
microseconds and a known one in a quarter-second, and login latency
enumerates the operator table.
Does not stamp last_login_at or create a session: a login is not
complete until a session exists, which for a user with a second factor is
two requests away. The caller decides when that happened.