| | | 1 | | using Anichron.API.Settings; |
| | | 2 | | using Konscious.Security.Cryptography; |
| | | 3 | | using System.Security.Cryptography; |
| | | 4 | | using System.Text; |
| | | 5 | | |
| | | 6 | | namespace Anichron.API.Security; |
| | | 7 | | |
| | | 8 | | public interface IPasswordHasher |
| | | 9 | | { |
| | | 10 | | string Hash(string password); |
| | | 11 | | |
| | | 12 | | // storedHash is null when no such account exists. A null hash still costs a full Argon2 |
| | | 13 | | // pass, so verification itself takes the same time either way. That removes the HASHING |
| | | 14 | | // asymmetry only — it does not make a caller's whole code path constant-time. |
| | | 15 | | bool Verify(string password, string? storedHash); |
| | | 16 | | } |
| | | 17 | | |
| | | 18 | | public sealed class Argon2PasswordHasher : IPasswordHasher |
| | | 19 | | { |
| | | 20 | | public string Hash(string password) |
| | 3 | 21 | | { |
| | 3 | 22 | | var salt = RandomNumberGenerator.GetBytes(AppDefaults.Argon2.SaltLength); |
| | 3 | 23 | | var hash = RunArgon2idSecure(password, salt); |
| | | 24 | | |
| | 3 | 25 | | var combined = new byte[salt.Length + hash.Length]; |
| | 3 | 26 | | salt.CopyTo(combined, 0); |
| | 3 | 27 | | hash.CopyTo(combined, salt.Length); |
| | 3 | 28 | | return Convert.ToBase64String(combined); |
| | 3 | 29 | | } |
| | | 30 | | |
| | | 31 | | public bool Verify(string password, string? storedHash) |
| | 8 | 32 | | { |
| | | 33 | | // ⛔ Equal work, not an early return. Verifying a missing account must cost the same |
| | | 34 | | // Argon2 pass as verifying a real one, so this method leaks nothing about account |
| | | 35 | | // existence. ⚠️ Whether the CALLER leaks it is the caller's problem — AuthService.Login |
| | | 36 | | // still does a database write for a known user that it skips for an unknown one. |
| | | 37 | | // |
| | | 38 | | // The invariant lives here because this class owns the cost. It used to live in an |
| | | 39 | | // AuthService field initializer, which — AuthService being Scoped — burned 64 MiB and |
| | | 40 | | // three Argon2 passes on every request that resolved IAuthService, including ones that |
| | | 41 | | // never read the value. See #173. |
| | | 42 | | // |
| | | 43 | | // ⚠️ `return false` unconditionally, rather than comparing against random bytes: |
| | | 44 | | // correctness must not rest on two random values differing. The FixedTimeEquals of the |
| | | 45 | | // real path is deliberately not mirrored here — it is microseconds against ~100 ms of |
| | | 46 | | // Argon2, so adding it back would buy nothing and reintroduce that dependency. |
| | 8 | 47 | | if (storedHash is null) |
| | 2 | 48 | | { |
| | 2 | 49 | | var throwawaySalt = RandomNumberGenerator.GetBytes(AppDefaults.Argon2.SaltLength); |
| | 2 | 50 | | CryptographicOperations.ZeroMemory(RunArgon2idSecure(password, throwawaySalt)); |
| | 2 | 51 | | return false; |
| | | 52 | | } |
| | | 53 | | |
| | 6 | 54 | | var combined = Convert.FromBase64String(storedHash); |
| | 5 | 55 | | var salt = combined[..AppDefaults.Argon2.SaltLength]; |
| | 4 | 56 | | var expected = combined[AppDefaults.Argon2.SaltLength..]; |
| | 4 | 57 | | var actual = RunArgon2idSecure(password, salt); |
| | 4 | 58 | | return CryptographicOperations.FixedTimeEquals(actual, expected); |
| | 6 | 59 | | } |
| | | 60 | | |
| | | 61 | | private static byte[] RunArgon2idSecure(string password, byte[] salt) |
| | 9 | 62 | | { |
| | 9 | 63 | | var passwordBytes = Encoding.UTF8.GetBytes(password); |
| | | 64 | | try |
| | 9 | 65 | | { |
| | 9 | 66 | | return RunArgon2id(passwordBytes, salt); |
| | | 67 | | } |
| | | 68 | | finally |
| | 9 | 69 | | { |
| | 9 | 70 | | CryptographicOperations.ZeroMemory(passwordBytes); |
| | 9 | 71 | | } |
| | 9 | 72 | | } |
| | | 73 | | |
| | | 74 | | private static byte[] RunArgon2id(byte[] password, byte[] salt) |
| | 9 | 75 | | { |
| | 9 | 76 | | using var argon2 = new Argon2id(password) |
| | 9 | 77 | | { |
| | 9 | 78 | | Salt = salt, |
| | 9 | 79 | | DegreeOfParallelism = AppDefaults.Argon2.Parallelism, |
| | 9 | 80 | | Iterations = AppDefaults.Argon2.Iterations, |
| | 9 | 81 | | MemorySize = AppDefaults.Argon2.MemoryKiB, |
| | 9 | 82 | | }; |
| | 9 | 83 | | return argon2.GetBytes(AppDefaults.Argon2.HashLength); |
| | 9 | 84 | | } |
| | | 85 | | } |