#![cfg(feature = "include_simple")]
use alloc::{vec, string::String};
use core::convert::TryInto;
use crate::errors::CheckError;
use base64;
use hmac::Hmac;
use sha2::Sha256;
use subtle::ConstantTimeEq;
use rand_core::RngCore;
use super::pbkdf2;
#[cfg(not(features = "thread_rng"))]
type DefaultRng = rand_core::OsRng;
#[cfg(features = "thread_rng")]
type DefaultRng = rand::ThreadRng;
pub fn pbkdf2_simple(password: &str, rounds: u32) -> Result<String, rand_core::Error> {
let mut salt = [0u8; 16];
DefaultRng::default().try_fill_bytes(&mut salt)?;
let mut dk = [0u8; 32];
pbkdf2::<Hmac<Sha256>>(password.as_bytes(), &salt, rounds, &mut dk);
let mut result = String::with_capacity(90);
result.push_str("$rpbkdf2$0$");
result.push_str(&base64::encode(&rounds.to_be_bytes()));
result.push('$');
result.push_str(&base64::encode(&salt));
result.push('$');
result.push_str(&base64::encode(&dk));
result.push('$');
Ok(result)
}
pub fn pbkdf2_check(password: &str, hashed_value: &str) -> Result<(), CheckError> {
let mut parts = hashed_value.split('$');
let buf = [
parts.next(), parts.next(), parts.next(), parts.next(),
parts.next(), parts.next(), parts.next(), parts.next(),
];
let (count, salt, hash) = match buf {
[
Some(""), Some("rpbkdf2"), Some("0"), Some(c),
Some(s), Some(h), Some(""), None
] => (c, s, h),
_ => return Err(CheckError::InvalidFormat),
};
let count_arr = base64::decode(count)?
.as_slice()
.try_into()
.map_err(|_| CheckError::InvalidFormat)?;
let count = u32::from_be_bytes(count_arr);
let salt = base64::decode(salt)?;
let hash = base64::decode(hash)?;
let mut output = vec![0u8; hash.len()];
pbkdf2::<Hmac<Sha256>>(password.as_bytes(), &salt, count, &mut output);
if output.ct_eq(&hash).unwrap_u8() == 1 {
Ok(())
} else {
Err(CheckError::HashMismatch)
}
}