diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/users.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/users.py | 24 |
1 files changed, 12 insertions, 12 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/users.py b/packages/meshbay-hub/src/meshbay_hub/api/users.py index 2a6baf0..05f58cd 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/users.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/users.py @@ -24,11 +24,11 @@ from meshbay_hub.auth import ( encrypt_email, generate_refresh_token, hash_email_blind, - hash_password, + hash_password_off_loop, hash_refresh_token, issue_access_token, pw_needs_rehash, - verify_password, + verify_password_off_loop, ) from meshbay_hub.config import HubConfig from meshbay_hub.db.engine import get_db @@ -192,7 +192,7 @@ async def register( if not credential: raise HTTPException(status_code=400, detail="auth_key or password required") - pw_hash, pw_salt = hash_password(credential) + pw_hash, pw_salt = await hash_password_off_loop(credential) pw_ver = current_pw_version() if body.auth_key else 2 hub_id = _cfg.identity.id if _cfg else "meshbay.org" user = User( @@ -346,7 +346,7 @@ async def login( if user.pw_version >= 3: # New scheme: verify auth_key - if not body.auth_key or not verify_password( + if not body.auth_key or not await verify_password_off_loop( body.auth_key, user.pw_hash, user.pw_salt, version=user.pw_version ): await _login_failed(db, body.username, ip, user.id) @@ -357,19 +357,19 @@ async def login( await login_throttle.release(db, body.username) await db.commit() raise HTTPException(status_code=401, detail="auth_upgrade_required") - if not verify_password( + if not await verify_password_off_loop( body.password, user.pw_hash, user.pw_salt, version=user.pw_version ): await _login_failed(db, body.username, ip, user.id) # Migrate to new scheme if auth_key provided alongside password if body.auth_key: - new_hash, new_salt = hash_password(body.auth_key) + new_hash, new_salt = await hash_password_off_loop(body.auth_key) user.pw_hash = new_hash user.pw_salt = new_salt user.pw_version = current_pw_version() elif user.pw_version < 2: # Legacy rehash: upgrade Argon2 params within the password scheme (v1 -> v2) - new_hash, new_salt = hash_password(body.password) + new_hash, new_salt = await hash_password_off_loop(body.password) user.pw_hash = new_hash user.pw_salt = new_salt user.pw_version = 2 @@ -386,7 +386,7 @@ async def login( # Rehash within the auth_key scheme if Argon2 params upgraded beyond v3 if user.pw_version >= 3 and pw_needs_rehash(user.pw_version): - new_hash, new_salt = hash_password(body.auth_key) + new_hash, new_salt = await hash_password_off_loop(body.auth_key) user.pw_hash = new_hash user.pw_salt = new_salt user.pw_version = current_pw_version() @@ -885,7 +885,7 @@ async def change_password( db: AsyncSession = Depends(get_db), ): await _take_login_attempt(db, current_user.username) - if not verify_password(body.old_auth_key, current_user.pw_hash, + if not await verify_password_off_loop(body.old_auth_key, current_user.pw_hash, current_user.pw_salt, current_user.pw_version): raise HTTPException(status_code=403, detail="Current passphrase does not match") @@ -894,7 +894,7 @@ async def change_password( raise HTTPException(status_code=400, detail="New passphrase must differ from the current one") - new_hash, new_salt = hash_password(body.new_auth_key) + new_hash, new_salt = await hash_password_off_loop(body.new_auth_key) current_user.pw_hash = new_hash current_user.pw_salt = new_salt current_user.pw_version = current_pw_version() @@ -1077,7 +1077,7 @@ async def password_reset( raise HTTPException(status_code=400, detail="Invalid code") verif.verified_at = now - new_hash, new_salt = hash_password(body.new_auth_key) + new_hash, new_salt = await hash_password_off_loop(body.new_auth_key) user.pw_hash = new_hash user.pw_salt = new_salt user.pw_version = current_pw_version() @@ -1330,7 +1330,7 @@ async def delete_own_account( still never sees the passphrase itself. """ await _take_login_attempt(db, current_user.username) - if not verify_password(body.auth_key, current_user.pw_hash, current_user.pw_salt, + if not await verify_password_off_loop(body.auth_key, current_user.pw_hash, current_user.pw_salt, current_user.pw_version): raise HTTPException(status_code=403, detail="Passphrase does not match") await login_throttle.clear(db, current_user.username) |