gitoriaLog in with ident

notes

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit8cda54128cda5412notes mission 002 (1/4): code order — files moved: lib/notes.hl, lib/users.hl, lib/jsoncheck.hl, components/styles.hl (imports only); gates 50/0 + 18/0, live-data run identicalmre8cda5412/plugins/crypto/server.hl

4.5 KB

  1. \* hl:crypto — passwords first. Native realm wrapper (see server.js for the JS twin).
  2. The whole surface is eight calls, and six of them exist to serve the first two.
  3. What this plugin is FOR is that an application never stores a password: it
  4. stores the answer to "could this password have produced that", and the answer
  5. carries its own algorithm and cost so it stays readable when both change.
  6. hash(password, options) the stored value — a PHC string
  7. verify(password, stored) true / false, in constant time
  8. parsePhc(stored) what a stored value says about itself
  9. kdf() which algorithm THIS host hashes with
  10. sha256(data) content hashing (fast on purpose — not for passwords)
  11. randomBytes(n, encoding) n bytes from the kernel CSPRNG
  12. toBase64(data) a String's or a Bytes' bytes as base64 text
  13. fromBase64(text) base64 text back to a Bytes (null if it is not base64)
  14. The realm is SERVER (plugin.json). A password never crosses to the client, so
  15. importing this file is also a declaration about where the importing code runs. *\
  16. \* Hash a password for storage. Returns a self-describing PHC string:
  17. $argon2id$v=19$m=32768,t=2,p=1$<salt>$<hash>
  18. $scrypt$ln=15,r=8,p=1$<salt>$<hash>
  19. Every call salts freshly, so hashing the same password twice gives two
  20. different strings and both verify.
  21. `options` is optional: { cost = 15; kdf = "argon2id" }
  22. cost base-2 log of the working memory in KiB — 15 is 32 MiB, the default.
  23. CAPPED to 10..17 (1 MiB .. 128 MiB); the string records what was
  24. actually used, so asking for 999 and reading the result back is how
  25. you see the cap rather than being told about it.
  26. kdf force an algorithm instead of taking the host's best one. Normally
  27. unnecessary: `hash` picks argon2id when the system libcrypto has it
  28. (OpenSSL >= 3.2) and scrypt otherwise, and `verify` reads both. *\
  29. hash(password, options) {
  30. return __native("crypto.hash", password, options)
  31. }
  32. \* Check a password against a stored PHC string. The comparison is constant-time
  33. and the answer is a plain boolean: a wrong password, a truncated string, a
  34. flipped character and a string that is not PHC at all are all `false`. A
  35. stored string whose ALGORITHM this host cannot compute is a loud error
  36. instead, because answering `false` to that would read as "wrong password". *\
  37. verify(password, stored) {
  38. return __native("crypto.verify", password, stored)
  39. }
  40. \* Read a stored string without the password:
  41. { kdf = "argon2id"; version = 19; params = { m; t; p }; saltLen; hashLen }
  42. { kdf = "scrypt"; version = null; params = { ln; r; p }; saltLen; hashLen }
  43. `null` when the string is not a PHC string this plugin understands — which is
  44. also the cheapest way to spot a store that was never migrated. *\
  45. parsePhc(stored) {
  46. return __native("crypto.parse", stored)
  47. }
  48. \* Which algorithm `hash()` writes with on this host. Reporting only — nothing
  49. needs to branch on it, because every stored string names its own. *\
  50. kdf() {
  51. return __native("crypto.kdf")
  52. }
  53. \* SHA-256 of a string, as 64 lowercase hex characters. Content hashing: fast by
  54. design, and therefore exactly the wrong tool for a password. *\
  55. sha256(data) {
  56. return __native("crypto.sha256", data)
  57. }
  58. \* n random bytes from the kernel CSPRNG, rendered as "hex" (the default) or
  59. "base64". n is 1..1024. Suitable for session ids, one-time tokens and nonces. *\
  60. randomBytes(n, encoding) {
  61. return __native("crypto.random_bytes", n, encoding)
  62. }
  63. \* Base64 (the standard alphabet, padded) of a String's bytes — its UTF-8 — or
  64. of a Bytes, byte for byte:
  65. toBase64('user:pa55') \\ "dXNlcjpwYTU1"
  66. toBase64(req.bytes) \\ any bytes at all, NUL and 0xff included *\
  67. toBase64(
  68. data \\ a String or a Bytes
  69. ) {
  70. if (hlTypeName(data) == 'Bytes') {
  71. return __native("crypto.base64_encode_hex", data.hex())
  72. }
  73. return __native("crypto.base64_encode", data)
  74. }
  75. \* Base64 text back to its bytes, as a Bytes; `.toString()` of it is the text
  76. when the bytes are UTF-8. Padded and unpadded text both decode; anything
  77. that is not base64 in the standard alphabet is null, not an error — a
  78. malformed `Authorization: Basic` header is an answer, not a crash:
  79. let b = fromBase64(req.headers.authorization.slice(6))
  80. if (b != null) { let pair = b.toString() } \\ "user:pa55" *\
  81. fromBase64(String text) {
  82. let raw = __native("crypto.base64_decode", text)
  83. if (raw == null) {
  84. return null
  85. }
  86. return toBytes(raw)
  87. }

Branches

Latest commits

  • 8cda5412notes mission 002 (1/4): code order — files moved: lib/notes.hl, lib/users.hl, lib/jsoncheck.hl, components/styles.hl (imports only); gates 50/0 + 18/0, live-data run identicalmre
  • 47dad68bnotes: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 50/0 + 18/0mre
  • a4a2b2aeantcolony#40: tracker missions moved too — references to them in missions/reports/LOG.md updatedmre
  • 3dea0ef2notes: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 50/0mre
  • e27c7d71notes: Hybriel master 8efba065 (#126 GC by bytes, #48 lambda params copy; audit: nothing to fix; gate 50/0)mre
  • 124613b6antcolony#40: mission references point to the moved missionsmre
  • 1ca2f34dantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 2bebebdanotes: Hybriel master ff51cf46 (re-vendor round)mre
  • 3eff126dnotes#3: installable app (manifest + own icon/favicon; notes' own sw.js kept)mre
  • 9883c540deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • eee693b8deploy.sh: never send .git or .gitignore to Byrodinmre
  • c8904061State of 2026-09-27, before the move to gitoriamre