DataFlex Requires Chilkat v11.6.0+
DataFlex
Verify an Argon2 Password with a Secret and Memory Guard
Demonstrates Crypt2.Argon2VerifyPassword when the hash was created with a secret (pepper) or ad, and the use of maxMemoryKb to guard against untrusted hash strings.
Background. Only the
secret, ad, encoding, passwordCharset, and maxMemoryKb options are used during verification; everything else is ignored. Because the memory cost is taken from the hash string, setting maxMemoryKb for hashes from an untrusted source prevents an enormous claimed cost from exhausting memory; it is checked before any allocation. The method returns 1 for a match, 0 for no match, and -1 if the verification could not be performed; always test for a match with == 1.Chilkat DataFlex Downloads
Use ChilkatAx-win32.pkg
Procedure Test
Handle hoCrypt
String sPassword
String sPhcHash
Handle hoJson
Boolean iSuccess
Integer iVerifyResult
String sTemp1
Get Create (RefClass(cComChilkatCrypt2)) To hoCrypt
If (Not(IsComObjectCreated(hoCrypt))) Begin
Send CreateComObject of hoCrypt
End
// The password should come from a secure source rather than being hard-coded.
Move "correct horse battery staple" To sPassword
Move "$argon2id$v=19$m=131072,t=4,p=2$c29tZXJhbmRvbXNhbHQ$3fJ7v1qKcVJ0lHqXjBQZ8mYm3sNTfSPRt0bqDl9kEyM" To sPhcHash
// When the hash was created with a secret (pepper) or ad, the same values must be supplied to verify.
// Only the secret, ad, encoding, passwordCharset, and maxMemoryKb members of the options are used;
// everything else is ignored.
Get Create (RefClass(cComChilkatJsonObject)) To hoJson
If (Not(IsComObjectCreated(hoJson))) Begin
Send CreateComObject of hoJson
End
Get ComUpdateString Of hoJson "secret" "application-wide-pepper" To iSuccess
Get ComUpdateString Of hoJson "secretEncoding" "utf-8" To iSuccess
// maxMemoryKb guards against a hash from an untrusted source claiming an enormous memory cost. The
// memory cost is taken from the hash string, so this limit is checked before any memory is allocated.
// It defaults to 2 GB.
Get ComUpdateInt Of hoJson "maxMemoryKb" 262144 To iSuccess
// Argon2VerifyPassword returns 1 if the password matched, 0 if it did not match, and -1 if the
// verification could not be performed. Always test for a match with == 1.
Get ComEmit Of hoJson To sTemp1
Get ComArgon2VerifyPassword Of hoCrypt sPassword sTemp1 sPhcHash To iVerifyResult
If (iVerifyResult = 1) Begin
Showln "The password is verified."
End
Else Begin
If (iVerifyResult = 0) Begin
Showln "The password does not match."
End
Else Begin
Get ComLastErrorText Of hoCrypt To sTemp1
Showln "The verification could not be performed: " sTemp1
End
End
End_Procedure