Package com.codename1.backend.security.crypto


package com.codename1.backend.security.crypto
Password hashing: the PasswordEncoder contract, the delegating encoder that reads the {id} in front of a stored password, and the encoders behind it.
  • Class
    Description
    bcrypt, as OpenBSD defined it and Spring's BCryptPasswordEncoder writes it: $2a$, $2b$ or $2y$, a cost, a 16 byte salt and a 23 byte hash.
    Reads which scheme a stored password was made with from the {id} in front of it, so one user store can hold passwords of several ages:
    The little ASN.1 DER a server needs to move keys and signatures between the shapes they travel in: a JSON Web Key's numbers and the SubjectPublicKeyInfo that Crypto.verify(String, byte[], byte[], byte[]) takes; a PKCS#1 or SEC 1 private key out of an older PEM file and the PKCS#8 that Crypto.sign(String, byte[], byte[]) takes; an ECDSA signature as OpenSSL and the JDK write it and as a JSON Web Signature carries it.
    One key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret.
    A set of keys, as a JSON Web Key Set publishes one (RFC 7517 5): what a server that signs tokens serves at its jwks_uri, and what a server that verifies them reads from there.
    Where keys come from: a set held in memory, a file read at start-up, another server's published set.
    Reads keys out of PEM text, in the shapes key files come in, and hands back the one shape the runtime signs and verifies with: PKCS#8 DER for a private key, SubjectPublicKeyInfo DER for a public one.
    Stores a password as it is: {noop}secret.
    Turns a password into what is stored, and checks a password against it.
    Makes the PasswordEncoder an application should use unless it has a reason to choose its own.
    Reads the PBKDF2 passwords Spring Security's Pbkdf2PasswordEncoder wrote, so a user table brought over from a Spring application signs its users in as it is.
    PBKDF2-HMAC-SHA256 through the runtime's own Crypto.hashPassword(String) and Crypto.verifyPassword(String, String): a random salt per password, and the round count written into the result, so a stored value says how it is to be checked.
    Makes and checks the tokens a server mails out: the link that confirms an address, the link that resets a password, an invitation.