<!DOCTYPE html>
<html lang="en">
	<head>
		<title>authenticate - secure.go</title>
		<link type="text/css" rel="stylesheet" href="/style/src.css">
	</head>
	<body>
		<h1><a href="/authenticate">authenticate</a> - secure.go</h1>
		<pre>
<span class="hidden"><a id="L1" href="#L1">     1</a>  </span><span class="text">// Package authenticate provides a simple interface to encrypt and authenticate a message.</span>
<span class="hidden"><a id="L2" href="#L2">     2</a>  </span><span>package authenticate </span><span class="text">// import &#34;vimagination.zapto.org/authenticate&#34;</span>
<span class="hidden"><a id="L3" href="#L3">     3</a>  </span>
<span class="hidden"><a id="L4" href="#L4">     4</a>  </span><span>import (</span>
<span class="hidden"><a id="L5" href="#L5">     5</a>  </span><span>	&#34;crypto</span><span>/aes&#34;</span>
<span class="hidden"><a id="L6" href="#L6">     6</a>  </span><span>	&#34;crypto</span><span>/cipher&#34;</span>
<span class="hidden"><a id="L7" href="#L7">     7</a>  </span><span>	&#34;encoding</span><span>/binary&#34;</span>
<span class="hidden"><a id="L8" href="#L8">     8</a>  </span><span>	&#34;errors&#34;</span>
<span class="hidden"><a id="L9" href="#L9">     9</a>  </span><span>	&#34;fmt&#34;</span>
<span class="hidden"><a id="L10" href="#L10">    10</a>  </span><span>	&#34;time&#34;</span>
<span class="hidden"><a id="L11" href="#L11">    11</a>  </span><span>)</span>
<span class="hidden"><a id="L12" href="#L12">    12</a>  </span>
<span class="hidden"><a id="L13" href="#L13">    13</a>  </span><span>var timeNow = time.Now</span>
<span class="hidden"><a id="L14" href="#L14">    14</a>  </span>
<span class="hidden"><a id="L15" href="#L15">    15</a>  </span><span>const nonceSize = 12</span>
<span class="hidden"><a id="L16" href="#L16">    16</a>  </span>
<span class="hidden"><a id="L17" href="#L17">    17</a>  </span><span class="text">// Codec represents an initialised encoder/decoder.</span>
<span class="hidden"><a id="L18" href="#L18">    18</a>  </span><span>type Codec struct {</span>
<span class="hidden"><a id="L19" href="#L19">    19</a>  </span><span>	aead   cipher.AEAD</span>
<span class="hidden"><a id="L20" href="#L20">    20</a>  </span><span>	maxAge time.Duration</span>
<span class="hidden"><a id="L21" href="#L21">    21</a>  </span><span>}</span>
<span class="hidden"><a id="L22" href="#L22">    22</a>  </span>
<span class="hidden"><a id="L23" href="#L23">    23</a>  </span><span class="text">// NewCodec takes the encryption key, which should be 16, 24 or 32 bytes long,</span>
<span class="hidden"><a id="L24" href="#L24">    24</a>  </span><span class="text">// and an optional duration to create a new Codec.</span>
<span class="hidden"><a id="L25" href="#L25">    25</a>  </span><span class="text">//</span>
<span class="hidden"><a id="L26" href="#L26">    26</a>  </span><span class="text">// The optional Duration is used to allow messages to only be valid while it is</span>
<span class="hidden"><a id="L27" href="#L27">    27</a>  </span><span class="text">// younger than the given time. Set to 0 to disable expiration checking.</span>
<span class="hidden"><a id="L28" href="#L28">    28</a>  </span><span>func NewCodec(key []byte, maxAge time.Duration) (*Codec, error) {</span>
<span class="hidden"><a id="L29" href="#L29">    29</a>  </span><span>	if l := len(key); l != 16 &amp;&amp; l != 24 &amp;&amp; l != 32 {</span>
<span class="hidden"><a id="L30" href="#L30">    30</a>  </span><span>		return nil, ErrInvalidAES</span>
<span class="hidden"><a id="L31" href="#L31">    31</a>  </span><span>	}</span>
<span class="hidden"><a id="L32" href="#L32">    32</a>  </span>
<span class="hidden"><a id="L33" href="#L33">    33</a>  </span><span>	a := make([]byte, len(key))</span>
<span class="hidden"><a id="L34" href="#L34">    34</a>  </span>
<span class="hidden"><a id="L35" href="#L35">    35</a>  </span><span>	copy(a, key)</span>
<span class="hidden"><a id="L36" href="#L36">    36</a>  </span>
<span class="hidden"><a id="L37" href="#L37">    37</a>  </span><span>	block, _ := aes.NewCipher(a)</span>
<span class="hidden"><a id="L38" href="#L38">    38</a>  </span><span>	aead, _ := cipher.NewGCMWithNonceSize(block, nonceSize)</span>
<span class="hidden"><a id="L39" href="#L39">    39</a>  </span>
<span class="hidden"><a id="L40" href="#L40">    40</a>  </span><span>	return &amp;Codec{</span>
<span class="hidden"><a id="L41" href="#L41">    41</a>  </span><span>		aead:   aead,</span>
<span class="hidden"><a id="L42" href="#L42">    42</a>  </span><span>		maxAge: maxAge,</span>
<span class="hidden"><a id="L43" href="#L43">    43</a>  </span><span>	}, nil</span>
<span class="hidden"><a id="L44" href="#L44">    44</a>  </span><span>}</span>
<span class="hidden"><a id="L45" href="#L45">    45</a>  </span>
<span class="hidden"><a id="L46" href="#L46">    46</a>  </span><span class="text">// Encode takes a data slice and a destination buffer and returns the encrypted</span>
<span class="hidden"><a id="L47" href="#L47">    47</a>  </span><span class="text">// data.</span>
<span class="hidden"><a id="L48" href="#L48">    48</a>  </span><span class="text">//</span>
<span class="hidden"><a id="L49" href="#L49">    49</a>  </span><span class="text">// If the destination buffer is too small, or nil, it will be allocated accordingly.</span>
<span class="hidden"><a id="L50" href="#L50">    50</a>  </span><span>func (c *Codec) Encode(data, dst []byte) []byte {</span>
<span class="hidden"><a id="L51" href="#L51">    51</a>  </span><span>	if cap(dst) &lt; nonceSize {</span>
<span class="hidden"><a id="L52" href="#L52">    52</a>  </span><span>		dst = make([]byte, nonceSize, len(data)&#43;c.Overhead())</span>
<span class="hidden"><a id="L53" href="#L53">    53</a>  </span><span>	} else {</span>
<span class="hidden"><a id="L54" href="#L54">    54</a>  </span><span>		dst = dst[:nonceSize]</span>
<span class="hidden"><a id="L55" href="#L55">    55</a>  </span><span>	}</span>
<span class="hidden"><a id="L56" href="#L56">    56</a>  </span>
<span class="hidden"><a id="L57" href="#L57">    57</a>  </span><span>	t := timeNow()</span>
<span class="hidden"><a id="L58" href="#L58">    58</a>  </span>
<span class="hidden"><a id="L59" href="#L59">    59</a>  </span><span>	binary.LittleEndian.PutUint64(dst, uint64(t.Nanosecond())) </span><span class="text">// last four bytes are overridden</span>
<span class="hidden"><a id="L60" href="#L60">    60</a>  </span><span>	binary.BigEndian.PutUint64(dst[4:], uint64(t.Unix()))</span>
<span class="hidden"><a id="L61" href="#L61">    61</a>  </span>
<span class="hidden"><a id="L62" href="#L62">    62</a>  </span><span>	return c.aead.Seal(dst, dst, data, nil)</span>
<span class="hidden"><a id="L63" href="#L63">    63</a>  </span><span>}</span>
<span class="hidden"><a id="L64" href="#L64">    64</a>  </span>
<span class="hidden"><a id="L65" href="#L65">    65</a>  </span><span class="text">// Decode takes a cipher text slice and a destination buffer and returns the</span>
<span class="hidden"><a id="L66" href="#L66">    66</a>  </span><span class="text">// decrypted data or an error if the cipher text is invalid or expired.</span>
<span class="hidden"><a id="L67" href="#L67">    67</a>  </span><span class="text">//</span>
<span class="hidden"><a id="L68" href="#L68">    68</a>  </span><span class="text">// If the destination buffer is too small, or nil, it will be allocated accordingly.</span>
<span class="hidden"><a id="L69" href="#L69">    69</a>  </span><span>func (c *Codec) Decode(cipherText, dst []byte) ([]byte, error) {</span>
<span class="hidden"><a id="L70" href="#L70">    70</a>  </span><span>	if len(cipherText) &lt; nonceSize {</span>
<span class="hidden"><a id="L71" href="#L71">    71</a>  </span><span>		return nil, ErrInvalidData</span>
<span class="hidden"><a id="L72" href="#L72">    72</a>  </span><span>	}</span>
<span class="hidden"><a id="L73" href="#L73">    73</a>  </span>
<span class="hidden"><a id="L74" href="#L74">    74</a>  </span><span>	timestamp := time.Unix(int64(binary.BigEndian.Uint64(cipherText[4:12])), 0)</span>
<span class="hidden"><a id="L75" href="#L75">    75</a>  </span>
<span class="hidden"><a id="L76" href="#L76">    76</a>  </span><span>	if c.maxAge &gt; 0 {</span>
<span class="hidden"><a id="L77" href="#L77">    77</a>  </span><span>		if t := timeNow().Sub(timestamp); t &gt; c.maxAge || t &lt; 0 {</span>
<span class="hidden"><a id="L78" href="#L78">    78</a>  </span><span>			return nil, ErrExpired</span>
<span class="hidden"><a id="L79" href="#L79">    79</a>  </span><span>		}</span>
<span class="hidden"><a id="L80" href="#L80">    80</a>  </span><span>	}</span>
<span class="hidden"><a id="L81" href="#L81">    81</a>  </span>
<span class="hidden"><a id="L82" href="#L82">    82</a>  </span><span>	var err error</span>
<span class="hidden"><a id="L83" href="#L83">    83</a>  </span>
<span class="hidden"><a id="L84" href="#L84">    84</a>  </span><span>	dst, err = c.aead.Open(dst, cipherText[:nonceSize], cipherText[nonceSize:], nil)</span>
<span class="hidden"><a id="L85" href="#L85">    85</a>  </span><span>	if err != nil {</span>
<span class="hidden"><a id="L86" href="#L86">    86</a>  </span><span>		return nil, fmt.Errorf(&#34;error opening cipher text: %w&#34;, err)</span>
<span class="hidden"><a id="L87" href="#L87">    87</a>  </span><span>	}</span>
<span class="hidden"><a id="L88" href="#L88">    88</a>  </span>
<span class="hidden"><a id="L89" href="#L89">    89</a>  </span><span>	return dst, nil</span>
<span class="hidden"><a id="L90" href="#L90">    90</a>  </span><span>}</span>
<span class="hidden"><a id="L91" href="#L91">    91</a>  </span>
<span class="hidden"><a id="L92" href="#L92">    92</a>  </span><span class="text">// Sign takes a data slice and a destination buffer and returns the data with a</span>
<span class="hidden"><a id="L93" href="#L93">    93</a>  </span><span class="text">// signature appended</span>
<span class="hidden"><a id="L94" href="#L94">    94</a>  </span><span class="text">//</span>
<span class="hidden"><a id="L95" href="#L95">    95</a>  </span><span class="text">// If the destination buffer is too small, or nil, it will be allocated accordingly.</span>
<span class="hidden"><a id="L96" href="#L96">    96</a>  </span><span>func (c *Codec) Sign(data, dst []byte) []byte {</span>
<span class="hidden"><a id="L97" href="#L97">    97</a>  </span><span>	if cap(dst) &lt; len(data)&#43;c.Overhead() {</span>
<span class="hidden"><a id="L98" href="#L98">    98</a>  </span><span>		dst = make([]byte, nonceSize, len(data)&#43;c.Overhead())</span>
<span class="hidden"><a id="L99" href="#L99">    99</a>  </span><span>	} else {</span>
<span class="hidden"><a id="L100" href="#L100">   100</a>  </span><span>		dst = dst[:len(data)&#43;c.Overhead()]</span>
<span class="hidden"><a id="L101" href="#L101">   101</a>  </span><span>	}</span>
<span class="hidden"><a id="L102" href="#L102">   102</a>  </span>
<span class="hidden"><a id="L103" href="#L103">   103</a>  </span><span>	var nonce [12]byte</span>
<span class="hidden"><a id="L104" href="#L104">   104</a>  </span>
<span class="hidden"><a id="L105" href="#L105">   105</a>  </span><span>	_ = append(dst[:0], data...)</span>
<span class="hidden"><a id="L106" href="#L106">   106</a>  </span>
<span class="hidden"><a id="L107" href="#L107">   107</a>  </span><span>	t := timeNow()</span>
<span class="hidden"><a id="L108" href="#L108">   108</a>  </span>
<span class="hidden"><a id="L109" href="#L109">   109</a>  </span><span>	binary.LittleEndian.PutUint64(nonce[1:], uint64(t.Nanosecond())) </span><span class="text">// last five bytes are overridden</span>
<span class="hidden"><a id="L110" href="#L110">   110</a>  </span><span>	binary.BigEndian.PutUint64(nonce[4:], uint64(t.Unix()))</span>
<span class="hidden"><a id="L111" href="#L111">   111</a>  </span><span>	copy(dst[len(data):len(data)&#43;nonceSize], nonce[1:])</span>
<span class="hidden"><a id="L112" href="#L112">   112</a>  </span>
<span class="hidden"><a id="L113" href="#L113">   113</a>  </span><span>	dst = dst[:len(c.aead.Seal(dst[:len(data)&#43;nonceSize-1], nonce[:], nil, data))&#43;1]</span>
<span class="hidden"><a id="L114" href="#L114">   114</a>  </span>
<span class="hidden"><a id="L115" href="#L115">   115</a>  </span><span>	dst[len(dst)-1] = byte(len(dst) - len(data))</span>
<span class="hidden"><a id="L116" href="#L116">   116</a>  </span>
<span class="hidden"><a id="L117" href="#L117">   117</a>  </span><span>	return dst</span>
<span class="hidden"><a id="L118" href="#L118">   118</a>  </span><span>}</span>
<span class="hidden"><a id="L119" href="#L119">   119</a>  </span>
<span class="hidden"><a id="L120" href="#L120">   120</a>  </span><span class="text">// Verify takes data returned from the Sign method and returns the unsigned</span>
<span class="hidden"><a id="L121" href="#L121">   121</a>  </span><span class="text">// data, or and error if the signature is invalid or the optional exiration has</span>
<span class="hidden"><a id="L122" href="#L122">   122</a>  </span><span class="text">// been exceeded.</span>
<span class="hidden"><a id="L123" href="#L123">   123</a>  </span><span class="text">//</span>
<span class="hidden"><a id="L124" href="#L124">   124</a>  </span><span class="text">// If the destination buffer is too small, or nil, it will be allocated accordingly.</span>
<span class="hidden"><a id="L125" href="#L125">   125</a>  </span><span>func (c *Codec) Verify(data []byte) ([]byte, error) {</span>
<span class="hidden"><a id="L126" href="#L126">   126</a>  </span><span>	if len(data) &lt; nonceSize {</span>
<span class="hidden"><a id="L127" href="#L127">   127</a>  </span><span>		return nil, ErrInvalidData</span>
<span class="hidden"><a id="L128" href="#L128">   128</a>  </span><span>	}</span>
<span class="hidden"><a id="L129" href="#L129">   129</a>  </span>
<span class="hidden"><a id="L130" href="#L130">   130</a>  </span><span>	var nonce [12]byte</span>
<span class="hidden"><a id="L131" href="#L131">   131</a>  </span>
<span class="hidden"><a id="L132" href="#L132">   132</a>  </span><span>	sigLen := int(data[len(data)-1])</span>
<span class="hidden"><a id="L133" href="#L133">   133</a>  </span><span>	plain := data[:len(data)-sigLen]</span>
<span class="hidden"><a id="L134" href="#L134">   134</a>  </span><span>	copy(nonce[1:], data[len(plain):])</span>
<span class="hidden"><a id="L135" href="#L135">   135</a>  </span>
<span class="hidden"><a id="L136" href="#L136">   136</a>  </span><span>	sig := data[len(plain)&#43;nonceSize-1 : len(data)-1]</span>
<span class="hidden"><a id="L137" href="#L137">   137</a>  </span>
<span class="hidden"><a id="L138" href="#L138">   138</a>  </span><span>	if c.maxAge &gt; 0 {</span>
<span class="hidden"><a id="L139" href="#L139">   139</a>  </span><span>		if t := timeNow().Sub(time.Unix(int64(binary.BigEndian.Uint64(nonce[4:12])), 0)); t &gt; c.maxAge || t &lt; 0 {</span>
<span class="hidden"><a id="L140" href="#L140">   140</a>  </span><span>			return nil, ErrExpired</span>
<span class="hidden"><a id="L141" href="#L141">   141</a>  </span><span>		}</span>
<span class="hidden"><a id="L142" href="#L142">   142</a>  </span><span>	}</span>
<span class="hidden"><a id="L143" href="#L143">   143</a>  </span>
<span class="hidden"><a id="L144" href="#L144">   144</a>  </span><span>	if _, err := c.aead.Open(nil, nonce[:], sig, plain); err != nil {</span>
<span class="hidden"><a id="L145" href="#L145">   145</a>  </span><span>		return nil, fmt.Errorf(&#34;error verifying signature: %w&#34;, err)</span>
<span class="hidden"><a id="L146" href="#L146">   146</a>  </span><span>	}</span>
<span class="hidden"><a id="L147" href="#L147">   147</a>  </span>
<span class="hidden"><a id="L148" href="#L148">   148</a>  </span><span>	return plain, nil</span>
<span class="hidden"><a id="L149" href="#L149">   149</a>  </span><span>}</span>
<span class="hidden"><a id="L150" href="#L150">   150</a>  </span>
<span class="hidden"><a id="L151" href="#L151">   151</a>  </span><span class="text">// Overhead returns the maximum number of bytes that the cipher text will be</span>
<span class="hidden"><a id="L152" href="#L152">   152</a>  </span><span class="text">// longer than the plain text.</span>
<span class="hidden"><a id="L153" href="#L153">   153</a>  </span><span>func (c *Codec) Overhead() int {</span>
<span class="hidden"><a id="L154" href="#L154">   154</a>  </span><span>	return c.aead.Overhead() &#43; nonceSize</span>
<span class="hidden"><a id="L155" href="#L155">   155</a>  </span><span>}</span>
<span class="hidden"><a id="L156" href="#L156">   156</a>  </span>
<span class="hidden"><a id="L157" href="#L157">   157</a>  </span><span class="text">// Errors.</span>
<span class="hidden"><a id="L158" href="#L158">   158</a>  </span><span>var (</span>
<span class="hidden"><a id="L159" href="#L159">   159</a>  </span><span>	ErrInvalidAES  = errors.New(&#34;invalid AES key, must be 16, 24 or 32 bytes&#34;)</span>
<span class="hidden"><a id="L160" href="#L160">   160</a>  </span><span>	ErrInvalidData = errors.New(&#34;invalid cipher text&#34;)</span>
<span class="hidden"><a id="L161" href="#L161">   161</a>  </span><span>	ErrExpired     = errors.New(&#34;data expired&#34;)</span>
<span class="hidden"><a id="L162" href="#L162">   162</a>  </span><span>)</span>
<span class="hidden"><a id="L163" href="#L163">   163</a>  </span></pre>
	</body>
</html>
