fix(auth): bind current local registry and CORS
This commit is contained in:
@@ -20,13 +20,6 @@ const (
|
||||
argon2SaltBytes = 16
|
||||
argon2KeyBytes uint32 = 32
|
||||
|
||||
argon2MaximumMemoryKiB uint32 = 256 * 1024
|
||||
argon2MaximumPasses uint32 = 10
|
||||
argon2MaximumParallel uint8 = 4
|
||||
argon2MinimumSaltBytes = 16
|
||||
argon2MaximumSaltBytes = 64
|
||||
argon2MinimumKeyBytes uint32 = 16
|
||||
argon2MaximumKeyBytes uint32 = 64
|
||||
maximumPHCBytes = 256
|
||||
)
|
||||
|
||||
@@ -55,7 +48,7 @@ func HashPassword(password []byte, random io.Reader) (string, error) {
|
||||
return "$argon2id$v=19$m=65536,t=3,p=1$" + base64.RawStdEncoding.EncodeToString(salt) + "$" + base64.RawStdEncoding.EncodeToString(digest), nil
|
||||
}
|
||||
|
||||
// VerifyPassword accepts only bounded, canonical Argon2id v19 PHC strings.
|
||||
// VerifyPassword accepts only the exact canonical Argon2id v19 policy.
|
||||
func VerifyPassword(password []byte, encoded string) bool {
|
||||
if !validPassword(password) {
|
||||
return false
|
||||
@@ -84,11 +77,11 @@ func parsePHC(encoded string) (argon2Parameters, bool) {
|
||||
if !ok {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
salt, ok := decodePHCBase64(parts[4], argon2MinimumSaltBytes, argon2MaximumSaltBytes)
|
||||
salt, ok := decodePHCBase64(parts[4], argon2SaltBytes, argon2SaltBytes)
|
||||
if !ok {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
digest, ok := decodePHCBase64(parts[5], int(argon2MinimumKeyBytes), int(argon2MaximumKeyBytes))
|
||||
digest, ok := decodePHCBase64(parts[5], int(argon2KeyBytes), int(argon2KeyBytes))
|
||||
if !ok {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
@@ -102,16 +95,16 @@ func parsePHCParameters(value string) (argon2Parameters, bool) {
|
||||
if len(parts) != 3 || !strings.HasPrefix(parts[0], "m=") || !strings.HasPrefix(parts[1], "t=") || !strings.HasPrefix(parts[2], "p=") {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
memory, ok := parseDecimal(parts[0][2:], uint64(argon2MaximumMemoryKiB))
|
||||
if !ok || memory < 8 {
|
||||
memory, ok := parseDecimal(parts[0][2:], uint64(argon2MemoryKiB))
|
||||
if !ok || memory != uint64(argon2MemoryKiB) {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
passes, ok := parseDecimal(parts[1][2:], uint64(argon2MaximumPasses))
|
||||
if !ok || passes == 0 {
|
||||
passes, ok := parseDecimal(parts[1][2:], uint64(argon2Passes))
|
||||
if !ok || passes != uint64(argon2Passes) {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
parallelism, ok := parseDecimal(parts[2][2:], uint64(argon2MaximumParallel))
|
||||
if !ok || parallelism == 0 || memory < 8*parallelism {
|
||||
parallelism, ok := parseDecimal(parts[2][2:], uint64(argon2Parallel))
|
||||
if !ok || parallelism != uint64(argon2Parallel) {
|
||||
return argon2Parameters{}, false
|
||||
}
|
||||
return argon2Parameters{memory: uint32(memory), passes: uint32(passes), parallelism: uint8(parallelism)}, true
|
||||
|
||||
@@ -57,6 +57,7 @@ func TestVerifyPasswordRejectsMalformedAndOversizedPHCBeforeHashing(t *testing.T
|
||||
"memory too large": "$argon2id$v=19$m=262145,t=1,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4",
|
||||
"passes too large": "$argon2id$v=19$m=65536,t=11,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4",
|
||||
"parallelism too large": "$argon2id$v=19$m=65536,t=3,p=5$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4",
|
||||
"weak bounded policy": "$argon2id$v=19$m=8,t=1,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4",
|
||||
"short salt": "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0O$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4",
|
||||
"long digest": "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
|
||||
} {
|
||||
|
||||
Reference in New Issue
Block a user