Source code for flux_restful.core.security

import bcrypt

# bcrypt silently ignored bytes past 72 in older versions and raises in >= 5.0.
# We reject longer passwords explicitly so behavior is the same everywhere.
MAX_PASSWORD_BYTES = 72


def _password_bytes(password: str) -> bytes:
    encoded = password.encode("utf-8")
    if len(encoded) > MAX_PASSWORD_BYTES:
        raise ValueError(f"Password cannot be longer than {MAX_PASSWORD_BYTES} bytes.")
    return encoded


[docs]def verify_password(plain_password: str, hashed_password: str) -> bool: """ Verify a plain password against a stored bcrypt hash. """ try: return bcrypt.checkpw( _password_bytes(plain_password), hashed_password.encode("utf-8") ) except ValueError: # Over-long password or malformed stored hash: never a match return False
[docs]def get_password_hash(password: str) -> str: """ Hash a password with bcrypt (a random salt is generated per hash). """ return bcrypt.hashpw(_password_bytes(password), bcrypt.gensalt()).decode("utf-8")