aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/users.py
diff options
context:
space:
mode:
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/users.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/users.py24
1 files changed, 12 insertions, 12 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/users.py b/packages/meshbay-hub/src/meshbay_hub/api/users.py
index 2a6baf0..05f58cd 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/users.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/users.py
@@ -24,11 +24,11 @@ from meshbay_hub.auth import (
encrypt_email,
generate_refresh_token,
hash_email_blind,
- hash_password,
+ hash_password_off_loop,
hash_refresh_token,
issue_access_token,
pw_needs_rehash,
- verify_password,
+ verify_password_off_loop,
)
from meshbay_hub.config import HubConfig
from meshbay_hub.db.engine import get_db
@@ -192,7 +192,7 @@ async def register(
if not credential:
raise HTTPException(status_code=400, detail="auth_key or password required")
- pw_hash, pw_salt = hash_password(credential)
+ pw_hash, pw_salt = await hash_password_off_loop(credential)
pw_ver = current_pw_version() if body.auth_key else 2
hub_id = _cfg.identity.id if _cfg else "meshbay.org"
user = User(
@@ -346,7 +346,7 @@ async def login(
if user.pw_version >= 3:
# New scheme: verify auth_key
- if not body.auth_key or not verify_password(
+ if not body.auth_key or not await verify_password_off_loop(
body.auth_key, user.pw_hash, user.pw_salt, version=user.pw_version
):
await _login_failed(db, body.username, ip, user.id)
@@ -357,19 +357,19 @@ async def login(
await login_throttle.release(db, body.username)
await db.commit()
raise HTTPException(status_code=401, detail="auth_upgrade_required")
- if not verify_password(
+ if not await verify_password_off_loop(
body.password, user.pw_hash, user.pw_salt, version=user.pw_version
):
await _login_failed(db, body.username, ip, user.id)
# Migrate to new scheme if auth_key provided alongside password
if body.auth_key:
- new_hash, new_salt = hash_password(body.auth_key)
+ new_hash, new_salt = await hash_password_off_loop(body.auth_key)
user.pw_hash = new_hash
user.pw_salt = new_salt
user.pw_version = current_pw_version()
elif user.pw_version < 2:
# Legacy rehash: upgrade Argon2 params within the password scheme (v1 -> v2)
- new_hash, new_salt = hash_password(body.password)
+ new_hash, new_salt = await hash_password_off_loop(body.password)
user.pw_hash = new_hash
user.pw_salt = new_salt
user.pw_version = 2
@@ -386,7 +386,7 @@ async def login(
# Rehash within the auth_key scheme if Argon2 params upgraded beyond v3
if user.pw_version >= 3 and pw_needs_rehash(user.pw_version):
- new_hash, new_salt = hash_password(body.auth_key)
+ new_hash, new_salt = await hash_password_off_loop(body.auth_key)
user.pw_hash = new_hash
user.pw_salt = new_salt
user.pw_version = current_pw_version()
@@ -885,7 +885,7 @@ async def change_password(
db: AsyncSession = Depends(get_db),
):
await _take_login_attempt(db, current_user.username)
- if not verify_password(body.old_auth_key, current_user.pw_hash,
+ if not await verify_password_off_loop(body.old_auth_key, current_user.pw_hash,
current_user.pw_salt, current_user.pw_version):
raise HTTPException(status_code=403,
detail="Current passphrase does not match")
@@ -894,7 +894,7 @@ async def change_password(
raise HTTPException(status_code=400,
detail="New passphrase must differ from the current one")
- new_hash, new_salt = hash_password(body.new_auth_key)
+ new_hash, new_salt = await hash_password_off_loop(body.new_auth_key)
current_user.pw_hash = new_hash
current_user.pw_salt = new_salt
current_user.pw_version = current_pw_version()
@@ -1077,7 +1077,7 @@ async def password_reset(
raise HTTPException(status_code=400, detail="Invalid code")
verif.verified_at = now
- new_hash, new_salt = hash_password(body.new_auth_key)
+ new_hash, new_salt = await hash_password_off_loop(body.new_auth_key)
user.pw_hash = new_hash
user.pw_salt = new_salt
user.pw_version = current_pw_version()
@@ -1330,7 +1330,7 @@ async def delete_own_account(
still never sees the passphrase itself.
"""
await _take_login_attempt(db, current_user.username)
- if not verify_password(body.auth_key, current_user.pw_hash, current_user.pw_salt,
+ if not await verify_password_off_loop(body.auth_key, current_user.pw_hash, current_user.pw_salt,
current_user.pw_version):
raise HTTPException(status_code=403, detail="Passphrase does not match")
await login_throttle.clear(db, current_user.username)