U
vfJ @ s& d dl mZ d dlZd dlZd dlmZ d dlmZ ej j
Zej jZ
ej jZej jZej jZej jZed Zej jZej jZej jZej jZej jZ ej j!Z"ej j#Z$ej j%Z&ej j'Z(ej j)Z*de$ Z+de& Z,e(e*ej-j.fe/e0e0e/e/ej-j1e0ddd Z2e$e&fe0e/e/e0d
ddZ3e0e0e4d
ddZ5dS ) )castN)
exceptions)ensure )sizepasswordsaltopslimitmemlimitencoderreturnc
C sz t tdtjd t t|tkdtt|f tjd tj ||\}}}|d } |
tjj||tt
d| ||| | dS )al
Derive a ``size`` bytes long key from a caller-supplied
``password`` and ``salt`` pair using the scryptsalsa208sha256
memory-hard construct.
the enclosing module provides the constants
- :py:const:`.OPSLIMIT_INTERACTIVE`
- :py:const:`.MEMLIMIT_INTERACTIVE`
- :py:const:`.OPSLIMIT_SENSITIVE`
- :py:const:`.MEMLIMIT_SENSITIVE`
- :py:const:`.OPSLIMIT_MODERATE`
- :py:const:`.MEMLIMIT_MODERATE`
as a guidance for correct settings respectively for the
interactive login and the long term key protecting sensitive data
use cases.
:param size: derived key size, must be between
:py:const:`.BYTES_MIN` and
:py:const:`.BYTES_MAX`
:type size: int
:param password: password used to seed the key derivation procedure;
it length must be between
:py:const:`.PASSWD_MIN` and
:py:const:`.PASSWD_MAX`
:type password: bytes
:param salt: **RANDOM** salt used in the key derivation procedure;
its length must be exactly :py:const:`.SALTBYTES`
:type salt: bytes
:param opslimit: the time component (operation count)
of the key derivation procedure's computational cost;
it must be between
:py:const:`.OPSLIMIT_MIN` and
:py:const:`.OPSLIMIT_MAX`
:type opslimit: int
:param memlimit: the memory occupation component
of the key derivation procedure's computational cost;
it must be between
:py:const:`.MEMLIMIT_MIN` and
:py:const:`.MEMLIMIT_MAX`
:type memlimit: int
:rtype: bytes
:raises nacl.exceptions.UnavailableError: If called when using a
minimal build of libsodium.
.. versionadded:: 1.2
Not available in minimal buildZraisingz.The salt must be exactly %s, not %s bytes longi )maxmemZdklen)r AVAILABLEexcUnavailableErrorlen SALTBYTES
ValueErrornaclbindingsZ nacl_bindings_pick_scrypt_paramsencodeZ%crypto_pwhash_scryptsalsa208sha256_llr int)
r r r r
r r Zn_log2rpr r E/opt/alt/python38/lib64/python3.8/site-packages/nacl/pwhash/scrypt.pykdf; s8 9
r )r r
r r
c C s t tdtjd tj| ||S )a$
Hashes a password with a random salt, using the memory-hard
scryptsalsa208sha256 construct and returning an ascii string
that has all the needed info to check against a future password
The default settings for opslimit and memlimit are those deemed
correct for the interactive user login case.
:param bytes password:
:param int opslimit:
:param int memlimit:
:rtype: bytes
:raises nacl.exceptions.UnavailableError: If called when using a
minimal build of libsodium.
.. versionadded:: 1.2
r r )r r r r r r Z&crypto_pwhash_scryptsalsa208sha256_str)r r
r r r r str s r! )
password_hashr r
c C s> t tdtjd t t| tkdtjj tj d tj
| |S )aW
Takes the output of scryptsalsa208sha256 and compares it against
a user provided password to see if they are the same
:param password_hash: bytes
:param password: bytes
:rtype: boolean
:raises nacl.exceptions.UnavailableError: If called when using a
minimal build of libsodium.
.. versionadded:: 1.2
r r z/The password hash must be exactly %s bytes long)r r r r r PWHASH_SIZEr r +crypto_pwhash_scryptsalsa208sha256_STRBYTESr Z-crypto_pwhash_scryptsalsa208sha256_str_verify)r" r r r r verify s
r% )6typingr Z
nacl.bindingsr Z
nacl.encodingr r Znacl.exceptionsr r r$ Z_strbytes_plus_oneZ&has_crypto_pwhash_scryptsalsa208sha256r Z,crypto_pwhash_scryptsalsa208sha256_STRPREFIXZ STRPREFIXZ,crypto_pwhash_scryptsalsa208sha256_SALTBYTESr Z-crypto_pwhash_scryptsalsa208sha256_PASSWD_MINZ
PASSWD_MINZ-crypto_pwhash_scryptsalsa208sha256_PASSWD_MAXZ
PASSWD_MAXr# Z,crypto_pwhash_scryptsalsa208sha256_BYTES_MINZ BYTES_MINZ,crypto_pwhash_scryptsalsa208sha256_BYTES_MAXZ BYTES_MAXZ/crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MINZMEMLIMIT_MINZ/crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_MAXZMEMLIMIT_MAXZ/crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MINZOPSLIMIT_MINZ/crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_MAXZOPSLIMIT_MAXZ7crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_INTERACTIVEZOPSLIMIT_INTERACTIVEZ7crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_INTERACTIVEZMEMLIMIT_INTERACTIVEZ5crypto_pwhash_scryptsalsa208sha256_OPSLIMIT_SENSITIVEZOPSLIMIT_SENSITIVEZ5crypto_pwhash_scryptsalsa208sha256_MEMLIMIT_SENSITIVEZMEMLIMIT_SENSITIVEZOPSLIMIT_MODERATEZMEMLIMIT_MODERATEencodingZ
RawEncoderr bytesZEncoderr r! boolr% r r r r