Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 0 additions & 4 deletions algorithm/md5crypt/digest.go
Original file line number Diff line number Diff line change
Expand Up @@ -89,8 +89,4 @@ func (d *Digest) defaults() {
default:
d.variant = variantDefault
}

if d.iterations < IterationsMin {
d.iterations = IterationsDefault
}
}
5 changes: 5 additions & 0 deletions algorithm/md5crypt/hasher.go
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ type Hasher struct {
variant Variant

iterations uint32
i bool

bytesSalt int

Expand Down Expand Up @@ -128,6 +129,10 @@ func (h *Hasher) defaults() {

h.d = true

if !h.i {
h.iterations = IterationsDefault
}

if h.bytesSalt < SaltLengthMin {
h.bytesSalt = SaltLengthDefault
}
Expand Down
5 changes: 3 additions & 2 deletions algorithm/md5crypt/opts.go
Original file line number Diff line number Diff line change
Expand Up @@ -47,14 +47,15 @@ func WithVariantName(identifier string) Opt {
}

// WithIterations sets the iterations parameter of the resulting md5crypt.Digest. Only valid for the Sun variant. This
// is encoded in the hash with the 'iterations' parameter.
// Minimum is 0, Maximum is 4294967295. Default is 34000.
// is encoded in the hash with the 'rounds' parameter.
// Minimum is 0, Maximum is 4294963199. Default is 34000.
func WithIterations(iterations uint32) Opt {
return func(h *Hasher) (err error) {
if iterations < IterationsMin || iterations > IterationsMax {
return fmt.Errorf(algorithm.ErrFmtHasherValidation, AlgName, fmt.Errorf(algorithm.ErrFmtInvalidIntParameter, algorithm.ErrParameterInvalid, "iterations", IterationsMin, "", IterationsMax, iterations))
}

h.i = true
h.iterations = iterations

return nil
Expand Down
45 changes: 45 additions & 0 deletions algorithm/md5crypt/regression_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -79,3 +79,48 @@ func TestWithIterationsRejectsRoundsThatOverflow(t *testing.T) {

assert.NoError(t, err)
}

func TestSunVariantAppliesDefaultIterations(t *testing.T) {
hasher, err := New(WithVariant(VariantSun))
require.NoError(t, err)

digest, err := hasher.Hash("password")
require.NoError(t, err)

encoded := digest.Encode()
assert.Contains(t, encoded, "$md5,rounds=34000$")

decoded, err := Decode(encoded)
require.NoError(t, err, "encoded digest %q could not be decoded", encoded)

assert.Equal(t, encoded, decoded.Encode())
assert.True(t, decoded.Match("password"))
assert.False(t, decoded.Match("incorrect"))
}

func TestSunVariantHonoursExplicitZeroIterations(t *testing.T) {
hasher, err := New(WithVariant(VariantSun), WithIterations(0))
require.NoError(t, err)

digest, err := hasher.Hash("password")
require.NoError(t, err)

encoded := digest.Encode()
assert.Regexp(t, `^\$md5\$[^$]+\$\$[^$]+$`, encoded)

decoded, err := Decode(encoded)
require.NoError(t, err)

assert.True(t, decoded.Match("password"))
}

func TestStandardVariantUnaffectedByDefaultIterations(t *testing.T) {
hasher, err := New()
require.NoError(t, err)

digest, err := hasher.Hash("password")
require.NoError(t, err)

assert.Regexp(t, `^\$1\$[^$]+\$[^$]+$`, digest.Encode())
assert.True(t, digest.Match("password"))
}
Loading