Use less secure hashing in test mode
All checks were successful
Push Workflows / rustfmt (push) Successful in 6s
Push Workflows / tailwind-build (push) Successful in 7s
Push Workflows / docs (push) Successful in 21s
Push Workflows / clippy (push) Successful in 18s
Push Workflows / test (push) Successful in 25s
Push Workflows / build (push) Successful in 47s
Push Workflows / nix-build (push) Successful in 5m15s
All checks were successful
Push Workflows / rustfmt (push) Successful in 6s
Push Workflows / tailwind-build (push) Successful in 7s
Push Workflows / docs (push) Successful in 21s
Push Workflows / clippy (push) Successful in 18s
Push Workflows / test (push) Successful in 25s
Push Workflows / build (push) Successful in 47s
Push Workflows / nix-build (push) Successful in 5m15s
This commit is contained in:
@@ -43,6 +43,20 @@ use crate::util::error::{Error, Result};
|
|||||||
#[diesel(sql_type = sql_types::Text)]
|
#[diesel(sql_type = sql_types::Text)]
|
||||||
pub struct HashedPassword(String);
|
pub struct HashedPassword(String);
|
||||||
|
|
||||||
|
/// Get a `Pbkdf2` instance for hashing
|
||||||
|
fn get_pbkdf2() -> Pbkdf2 {
|
||||||
|
use pbkdf2::{Algorithm, Params};
|
||||||
|
|
||||||
|
if cfg!(test) {
|
||||||
|
// Use lower security in testing mode so it doesn't take as long
|
||||||
|
// `Params::new` panics only if `rounds` < `MIN_ROUNDS`
|
||||||
|
Pbkdf2::new(Algorithm::default(), Params::new(Params::MIN_ROUNDS).expect("failed creating Pbkdf2 Params"))
|
||||||
|
} else {
|
||||||
|
// Default uses a sufficiently secure configuration
|
||||||
|
Pbkdf2::default()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl HashedPassword {
|
impl HashedPassword {
|
||||||
/// Check a password attempt against this hashed password
|
/// Check a password attempt against this hashed password
|
||||||
///
|
///
|
||||||
@@ -55,7 +69,7 @@ impl HashedPassword {
|
|||||||
let pw_hash = PasswordHash::new(&self.0)
|
let pw_hash = PasswordHash::new(&self.0)
|
||||||
.map_err(|e| Error::message_here(format!("Error parsing `HashedPassword`: {e}")))?;
|
.map_err(|e| Error::message_here(format!("Error parsing `HashedPassword`: {e}")))?;
|
||||||
|
|
||||||
match Pbkdf2::default().verify_password(password_attempt.as_bytes(), &pw_hash) {
|
match get_pbkdf2().verify_password(password_attempt.as_bytes(), &pw_hash) {
|
||||||
Ok(()) => Ok(true),
|
Ok(()) => Ok(true),
|
||||||
Err(PasswordInvalid) => Ok(false),
|
Err(PasswordInvalid) => Ok(false),
|
||||||
Err(e) => Err(Error::message_here(format!(
|
Err(e) => Err(Error::message_here(format!(
|
||||||
@@ -134,7 +148,7 @@ impl UserCredentials {
|
|||||||
/// Attempt to convert into `HashedUserCredentials` by hashing the password. Yields a PBKDF2
|
/// Attempt to convert into `HashedUserCredentials` by hashing the password. Yields a PBKDF2
|
||||||
/// error on failure.
|
/// error on failure.
|
||||||
pub fn try_hash(self) -> Result<HashedUserCredentials, pbkdf2::password_hash::Error> {
|
pub fn try_hash(self) -> Result<HashedUserCredentials, pbkdf2::password_hash::Error> {
|
||||||
let hashed_password = Pbkdf2::default().hash_password(self.password.as_bytes())?;
|
let hashed_password = get_pbkdf2().hash_password(self.password.as_bytes())?;
|
||||||
|
|
||||||
Ok(HashedUserCredentials {
|
Ok(HashedUserCredentials {
|
||||||
username: self.username,
|
username: self.username,
|
||||||
|
|||||||
Reference in New Issue
Block a user