- Rename getHash() to computeHash(): get.. suggests it's just retrieving some field but it's really doing a computation, which is quite complex depending on the hash algorithm
34 lines
1.1 KiB
Java
34 lines
1.1 KiB
Java
package fr.xephi.authme.security.crypts;
|
|
|
|
import java.math.BigInteger;
|
|
import java.security.MessageDigest;
|
|
import java.security.NoSuchAlgorithmException;
|
|
|
|
/**
|
|
*/
|
|
public class SHA256 implements EncryptionMethod {
|
|
|
|
private static String getSHA256(String message)
|
|
throws NoSuchAlgorithmException {
|
|
MessageDigest sha256 = MessageDigest.getInstance("SHA-256");
|
|
sha256.reset();
|
|
sha256.update(message.getBytes());
|
|
byte[] digest = sha256.digest();
|
|
return String.format("%0" + (digest.length << 1) + "x", new BigInteger(1, digest));
|
|
}
|
|
|
|
@Override
|
|
public String computeHash(String password, String salt, String name)
|
|
throws NoSuchAlgorithmException {
|
|
return "$SHA$" + salt + "$" + getSHA256(getSHA256(password) + salt);
|
|
}
|
|
|
|
@Override
|
|
public boolean comparePassword(String hash, String password,
|
|
String playerName) throws NoSuchAlgorithmException {
|
|
String[] line = hash.split("\\$");
|
|
return hash.equals(computeHash(password, line[2], ""));
|
|
}
|
|
|
|
}
|