Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
package com.codename1.backend.security.crypto
Password hashing: the
PasswordEncoder contract, the delegating encoder that
reads the {id} in front of a stored password, and the encoders behind it.Types
class BCryptPasswordEncoder | bcrypt, as OpenBSD defined it and Spring’s BCryptPasswordEncoder writes it: $2a$, $2b$ or $2y$, a cost, a 16 byte salt and a 23 byte hash. |
class DelegatingPasswordEncoder | Reads which scheme a stored password was made with from the {id} in front of it, so one user store can hold passwords of several ages: |
class Der | The little ASN.1 DER a server needs to move keys and signatures between the shapes they travel in: a JSON Web Key’s numbers and the SubjectPublicKeyInfo that Crypto.verify takes; a PKCS#1 or SEC 1 private key out of an older PEM file and the PKCS#8 that Crypto.sign takes; an ECDSA signature as OpenSSL and the JDK write it and as a JSON Web Signature carries it. |
class Jwk | One key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret. |
class JwkSet | A set of keys, as a JSON Web Key Set publishes one (RFC 7517 5): what a server that signs tokens serves at its jwks_uri, and what a server that verifies them reads from there. |
interface JwkSource | Where keys come from: a set held in memory, a file read at start-up, another server’s published set. |
class KeyFiles | Reads keys out of PEM text, in the shapes key files come in, and hands back the one shape the runtime signs and verifies with: PKCS#8 DER for a private key, SubjectPublicKeyInfo DER for a public one. |
class NoOpPasswordEncoder | Stores a password as it is: {noop}secret. |
interface PasswordEncoder | Turns a password into what is stored, and checks a password against it. |
class PasswordEncoderFactories | Makes the PasswordEncoder an application should use unless it has a reason to choose its own. |
class Pbkdf2PasswordEncoder | Reads the PBKDF2 passwords Spring Security’s Pbkdf2PasswordEncoder wrote, so a user table brought over from a Spring application signs its users in as it is. |
class Pbkdf2Sha256PasswordEncoder | PBKDF2-HMAC-SHA256 through the runtime’s own Crypto.hashPassword and Crypto.verifyPassword: a random salt per password, and the round count written into the result, so a stored value says how it is to be checked. |
class SignedTokens | Makes and checks the tokens a server mails out: the link that confirms an address, the link that resets a password, an invitation. |