droplet 1.3.0
A multipurpose Discord bot with the hacker in mind
Loading...
Searching...
No Matches
AuthUtils.hpp
Go to the documentation of this file.
1/*
2 * (c) Copyright erarnitox.de - All rights reserved
3 * Author: Erarnitox <david@erarnitox.de>
4 *
5 * License: MIT License
6 *
7 * Description:
8 *
9 * Documentation: https://droplet.erarnitox.de/doxygen/html/
10 */
11
12#pragma once
13
14#include <cstddef>
15#include <string>
16#include <string_view>
17
18#include "Poco/Net/HTTPServerRequest.h"
19
20constexpr std::size_t k_jwt_secret_min_bytes{32};
21constexpr std::size_t k_password_min_length{8};
22
23[[nodiscard]] bool constant_time_equal(std::string_view a, std::string_view b) noexcept;
24
25[[nodiscard]] bool jwt_secret_is_strong(std::string_view secret) noexcept;
26
27[[nodiscard]] std::string hashPassword(const std::string& password);
28
29[[nodiscard]] bool verifyPassword(const std::string& password, const std::string& storedHash);
30
31[[nodiscard]] bool jwt_grants_clearance(const std::string& jwt, const std::string& hmac_secret, int min_clearance);
32
33enum class AuthClearance { NONE = 0, PUBLIC = 10, PRIVATE = 100, SECRET = 1000, TOP_SECRET = 10000, BLACK = 100000 };
34
35struct AuthUtil {
36 [[nodiscard]] static bool is_authorized(const Poco::Net::HTTPServerRequest& req,
38};
std::string hashPassword(const std::string &password)
Definition AuthUtils.cpp:128
bool verifyPassword(const std::string &password, const std::string &storedHash)
Definition AuthUtils.cpp:149
bool jwt_grants_clearance(const std::string &jwt, const std::string &hmac_secret, int min_clearance)
Definition AuthUtils.cpp:159
bool jwt_secret_is_strong(std::string_view secret) noexcept
Definition AuthUtils.cpp:124
bool constant_time_equal(std::string_view a, std::string_view b) noexcept
Definition AuthUtils.cpp:113
constexpr std::size_t k_password_min_length
Definition AuthUtils.hpp:21
constexpr std::size_t k_jwt_secret_min_bytes
Definition AuthUtils.hpp:20
AuthClearance
Definition AuthUtils.hpp:33
@ BLACK
Definition AuthUtils.hpp:33
@ SECRET
Definition AuthUtils.hpp:33
@ PRIVATE
Definition AuthUtils.hpp:33
@ TOP_SECRET
Definition AuthUtils.hpp:33
@ NONE
Definition AuthUtils.hpp:33
@ PUBLIC
Definition AuthUtils.hpp:33
Definition AuthUtils.hpp:35
static bool is_authorized(const Poco::Net::HTTPServerRequest &req, AuthClearance minClearance=AuthClearance::SECRET)
Definition AuthUtils.cpp:186