diff options
| author | Rose Hogenson <rosehogenson@posteo.net> | 2025-09-23 22:33:30 -0700 |
|---|---|---|
| committer | Rose Hogenson <rosehogenson@posteo.net> | 2025-09-23 22:33:30 -0700 |
| commit | 40ad220fd0e26e3bf3be93c536b25cde1c00490f (patch) | |
| tree | 1752e13e3bf0d93a5b25a71743eb4d2ce851263b /roseh.moe.go | |
| parent | 24bdae7a803461bd9b13408f4fd332ebed5b5ac3 (diff) | |
| download | roseh.moe-40ad220fd0e26e3bf3be93c536b25cde1c00490f.tar.zst | |
Combine password hash and salt secrets
Diffstat (limited to 'roseh.moe.go')
| -rw-r--r-- | roseh.moe.go | 8 |
1 files changed, 2 insertions, 6 deletions
diff --git a/roseh.moe.go b/roseh.moe.go index c75acca..f24bc58 100644 --- a/roseh.moe.go +++ b/roseh.moe.go @@ -50,15 +50,11 @@ func loadSecrets() error { } for _, line := range bytes.Split(bytes.TrimSuffix(secrets, []byte("\n")), []byte("\n")) { if pw, ok := bytes.CutPrefix(line, []byte("notepad-password=")); ok { - notepadPassword = make([]byte, hex.DecodedLen(len(pw))) + buf := make([]byte, hex.DecodedLen(len(pw))) if _, err := hex.Decode(notepadPassword, pw); err != nil { return err } - } else if salt, ok := bytes.CutPrefix(line, []byte("salt=")); ok { - notepadPasswordSalt = make([]byte, hex.DecodedLen(len(salt))) - if _, err := hex.Decode(notepadPasswordSalt, salt); err != nil { - return err - } + notepadPasswordSalt, notepadPassword = buf[:pwhash.SaltLen], buf[pwhash.SaltLen:] } else if key, ok := bytes.CutPrefix(line, []byte("secret-key=")); ok { if hex.DecodedLen(len(key)) != sha512.Size256 { return fmt.Errorf("invalid HMAC-SHA512/256 key") |
