Skip to main content

verify

Function verify 

Source
pub async fn verify(password: &str, digest: &str) -> Result<bool>
Expand description

Whether password matches digest (made by hash), compared in constant time.

The password is hashed with the digest’s own salt and iteration count, so digests made with an older ITERATIONS still verify. A wrong password is Ok(false), not an error.

Cost: one PBKDF2 run with the stored iteration count (5.5 ms of CPU on Workers at 100,000). To keep timing from revealing which emails have accounts, verify against some digest even when the user is unknown.

§Errors

  • Error::Internal (500) when digest is not in the pbkdf2_sha256$<iterations>$<salt>$<hash> format (corrupted data, not a failed login).
  • On Workers, Error::Internal when WebCrypto fails.

§Examples

let digest = ocre::password::hash("correct horse").await?;
assert!(ocre::password::verify("correct horse", &digest).await?);
assert!(!ocre::password::verify("wrong horse", &digest).await?);
assert!(ocre::password::verify("correct horse", "plaintext").await.is_err());