Sovite.SASL (sovite v0.2.0)

Copy Markdown View Source

SASL authentication (RFC 4422), server and client side.

Mechanisms:

Sovite.SASL.Server runs the server side against a Sovite.SASL.Backend, which checks the credentials. Backends:

Sovite.SASL.Dovecot hands the whole exchange to a Dovecot auth server instead. Sovite.SASL.Password hashes and checks stored passwords.

Summary

Functions

Prepares a password or user name for comparison, a close approximation of SASLprep (RFC 4013): non-ASCII spaces become spaces, characters "commonly mapped to nothing" are removed, and the result is NFKC normalized. Returns :error for invalid UTF-8 or prohibited characters (controls).

Compares two binaries in constant time (for equal sizes).

Functions

saslprep(string)

@spec saslprep(binary()) :: {:ok, String.t()} | :error

Prepares a password or user name for comparison, a close approximation of SASLprep (RFC 4013): non-ASCII spaces become spaces, characters "commonly mapped to nothing" are removed, and the result is NFKC normalized. Returns :error for invalid UTF-8 or prohibited characters (controls).

iex> Sovite.SASL.saslprep("I\u00ADX")
{:ok, "IX"}
iex> Sovite.SASL.saslprep("\u2168")
{:ok, "IX"}
iex> Sovite.SASL.saslprep("a\u0007")
:error

secure_compare(a, b)

@spec secure_compare(binary(), binary()) :: boolean()

Compares two binaries in constant time (for equal sizes).