1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
#![cfg(feature = "include_simple")]
use alloc::{string::String, vec};
use core::convert::TryInto;
use crate::errors::CheckError;
use hmac::Hmac;
use rand_core::RngCore;
use sha2::Sha256;
use subtle::ConstantTimeEq;
use super::pbkdf2;
#[cfg(not(features = "thread_rng"))]
type DefaultRng = rand_core::OsRng;
#[cfg(features = "thread_rng")]
type DefaultRng = rand::ThreadRng;
pub fn pbkdf2_simple(password: &str, rounds: u32) -> Result<String, rand_core::Error> {
let mut salt = [0u8; 16];
DefaultRng::default().try_fill_bytes(&mut salt)?;
let mut dk = [0u8; 32];
pbkdf2::<Hmac<Sha256>>(password.as_bytes(), &salt, rounds, &mut dk);
let mut result = String::with_capacity(90);
result.push_str("$rpbkdf2$0$");
result.push_str(&base64::encode(&rounds.to_be_bytes()));
result.push('$');
result.push_str(&base64::encode(&salt));
result.push('$');
result.push_str(&base64::encode(&dk));
result.push('$');
Ok(result)
}
pub fn pbkdf2_check(password: &str, hashed_value: &str) -> Result<(), CheckError> {
let mut parts = hashed_value.split('$');
let buf = [
parts.next(),
parts.next(),
parts.next(),
parts.next(),
parts.next(),
parts.next(),
parts.next(),
parts.next(),
];
let (count, salt, hash) = match buf {
[Some(""), Some("rpbkdf2"), Some("0"), Some(c), Some(s), Some(h), Some(""), None] => {
(c, s, h)
}
_ => return Err(CheckError::InvalidFormat),
};
let count_arr = base64::decode(count)?
.as_slice()
.try_into()
.map_err(|_| CheckError::InvalidFormat)?;
let count = u32::from_be_bytes(count_arr);
let salt = base64::decode(salt)?;
let hash = base64::decode(hash)?;
let mut output = vec![0u8; hash.len()];
pbkdf2::<Hmac<Sha256>>(password.as_bytes(), &salt, count, &mut output);
if output.ct_eq(&hash).unwrap_u8() == 1 {
Ok(())
} else {
Err(CheckError::HashMismatch)
}
}