| [62b2964] | 1 | const nodeCrypto = require('crypto')
|
|---|
| 2 |
|
|---|
| 3 | module.exports = {
|
|---|
| 4 | postgresMd5PasswordHash,
|
|---|
| 5 | randomBytes,
|
|---|
| 6 | deriveKey,
|
|---|
| 7 | sha256,
|
|---|
| 8 | hashByName,
|
|---|
| 9 | hmacSha256,
|
|---|
| 10 | md5,
|
|---|
| 11 | }
|
|---|
| 12 |
|
|---|
| 13 | /**
|
|---|
| 14 | * The Web Crypto API - grabbed from the Node.js library or the global
|
|---|
| 15 | * @type Crypto
|
|---|
| 16 | */
|
|---|
| 17 | // eslint-disable-next-line no-undef
|
|---|
| 18 | const webCrypto = nodeCrypto.webcrypto || globalThis.crypto
|
|---|
| 19 | /**
|
|---|
| 20 | * The SubtleCrypto API for low level crypto operations.
|
|---|
| 21 | * @type SubtleCrypto
|
|---|
| 22 | */
|
|---|
| 23 | const subtleCrypto = webCrypto.subtle
|
|---|
| 24 | const textEncoder = new TextEncoder()
|
|---|
| 25 |
|
|---|
| 26 | /**
|
|---|
| 27 | *
|
|---|
| 28 | * @param {*} length
|
|---|
| 29 | * @returns
|
|---|
| 30 | */
|
|---|
| 31 | function randomBytes(length) {
|
|---|
| 32 | return webCrypto.getRandomValues(Buffer.alloc(length))
|
|---|
| 33 | }
|
|---|
| 34 |
|
|---|
| 35 | async function md5(string) {
|
|---|
| 36 | try {
|
|---|
| 37 | return nodeCrypto.createHash('md5').update(string, 'utf-8').digest('hex')
|
|---|
| 38 | } catch (e) {
|
|---|
| 39 | // `createHash()` failed so we are probably not in Node.js, use the WebCrypto API instead.
|
|---|
| 40 | // Note that the MD5 algorithm on WebCrypto is not available in Node.js.
|
|---|
| 41 | // This is why we cannot just use WebCrypto in all environments.
|
|---|
| 42 | const data = typeof string === 'string' ? textEncoder.encode(string) : string
|
|---|
| 43 | const hash = await subtleCrypto.digest('MD5', data)
|
|---|
| 44 | return Array.from(new Uint8Array(hash))
|
|---|
| 45 | .map((b) => b.toString(16).padStart(2, '0'))
|
|---|
| 46 | .join('')
|
|---|
| 47 | }
|
|---|
| 48 | }
|
|---|
| 49 |
|
|---|
| 50 | // See AuthenticationMD5Password at https://www.postgresql.org/docs/current/static/protocol-flow.html
|
|---|
| 51 | async function postgresMd5PasswordHash(user, password, salt) {
|
|---|
| 52 | const inner = await md5(password + user)
|
|---|
| 53 | const outer = await md5(Buffer.concat([Buffer.from(inner), salt]))
|
|---|
| 54 | return 'md5' + outer
|
|---|
| 55 | }
|
|---|
| 56 |
|
|---|
| 57 | /**
|
|---|
| 58 | * Create a SHA-256 digest of the given data
|
|---|
| 59 | * @param {Buffer} data
|
|---|
| 60 | */
|
|---|
| 61 | async function sha256(text) {
|
|---|
| 62 | return await subtleCrypto.digest('SHA-256', text)
|
|---|
| 63 | }
|
|---|
| 64 |
|
|---|
| 65 | async function hashByName(hashName, text) {
|
|---|
| 66 | return await subtleCrypto.digest(hashName, text)
|
|---|
| 67 | }
|
|---|
| 68 |
|
|---|
| 69 | /**
|
|---|
| 70 | * Sign the message with the given key
|
|---|
| 71 | * @param {ArrayBuffer} keyBuffer
|
|---|
| 72 | * @param {string} msg
|
|---|
| 73 | */
|
|---|
| 74 | async function hmacSha256(keyBuffer, msg) {
|
|---|
| 75 | const key = await subtleCrypto.importKey('raw', keyBuffer, { name: 'HMAC', hash: 'SHA-256' }, false, ['sign'])
|
|---|
| 76 | return await subtleCrypto.sign('HMAC', key, textEncoder.encode(msg))
|
|---|
| 77 | }
|
|---|
| 78 |
|
|---|
| 79 | /**
|
|---|
| 80 | * Derive a key from the password and salt
|
|---|
| 81 | * @param {string} password
|
|---|
| 82 | * @param {Uint8Array} salt
|
|---|
| 83 | * @param {number} iterations
|
|---|
| 84 | */
|
|---|
| 85 | async function deriveKey(password, salt, iterations) {
|
|---|
| 86 | const key = await subtleCrypto.importKey('raw', textEncoder.encode(password), 'PBKDF2', false, ['deriveBits'])
|
|---|
| 87 | const params = { name: 'PBKDF2', hash: 'SHA-256', salt: salt, iterations: iterations }
|
|---|
| 88 | return await subtleCrypto.deriveBits(params, key, 32 * 8, ['deriveBits'])
|
|---|
| 89 | }
|
|---|