Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

package com.codename1.backend.security.crypto

Password hashing: the PasswordEncoder contract, the delegating encoder that reads the {id} in front of a stored password, and the encoders behind it.

Types

class BCryptPasswordEncoderbcrypt, as OpenBSD defined it and Spring’s BCryptPasswordEncoder writes it: $2a$, $2b$ or $2y$, a cost, a 16 byte salt and a 23 byte hash.
class DelegatingPasswordEncoderReads which scheme a stored password was made with from the {id} in front of it, so one user store can hold passwords of several ages:
class DerThe little ASN.1 DER a server needs to move keys and signatures between the shapes they travel in: a JSON Web Key’s numbers and the SubjectPublicKeyInfo that Crypto.verify takes; a PKCS#1 or SEC 1 private key out of an older PEM file and the PKCS#8 that Crypto.sign takes; an ECDSA signature as OpenSSL and the JDK write it and as a JSON Web Signature carries it.
class JwkOne key, as a JSON Web Key describes it (RFC 7517): an RSA key, an EC key on P-256 or P-384, or a shared secret.
class JwkSetA set of keys, as a JSON Web Key Set publishes one (RFC 7517 5): what a server that signs tokens serves at its jwks_uri, and what a server that verifies them reads from there.
interface JwkSourceWhere keys come from: a set held in memory, a file read at start-up, another server’s published set.
class KeyFilesReads keys out of PEM text, in the shapes key files come in, and hands back the one shape the runtime signs and verifies with: PKCS#8 DER for a private key, SubjectPublicKeyInfo DER for a public one.
class NoOpPasswordEncoderStores a password as it is: {noop}secret.
interface PasswordEncoderTurns a password into what is stored, and checks a password against it.
class PasswordEncoderFactoriesMakes the PasswordEncoder an application should use unless it has a reason to choose its own.
class Pbkdf2PasswordEncoderReads the PBKDF2 passwords Spring Security’s Pbkdf2PasswordEncoder wrote, so a user table brought over from a Spring application signs its users in as it is.
class Pbkdf2Sha256PasswordEncoderPBKDF2-HMAC-SHA256 through the runtime’s own Crypto.hashPassword and Crypto.verifyPassword: a random salt per password, and the round count written into the result, so a stored value says how it is to be checked.
class SignedTokensMakes and checks the tokens a server mails out: the link that confirms an address, the link that resets a password, an invitation.