mirror of
https://github.com/bitwarden/server.git
synced 2025-07-03 09:02:48 -05:00
[PS-2267] Add KdfMemory and KDFParallelism fields (#2583)
* Add KdfMemory and KDFParallelism fields * Revise argon2 support This pull request makes the new attribues for argon2, kdfMemory and kdfParallelism optional. Furthermore it adds checks for the argon2 parametrs and improves the database migration script. * Add validation for argon2 in RegisterRequestModel * update validation messages * update sql scripts * register data protection with migration factories * add ef migrations * update kdf option validation * adjust validation * Centralize and Test KDF Validation Co-authored-by: Kyle Spearrin <kspearrin@users.noreply.github.com> Co-authored-by: Kyle Spearrin <kyle.spearrin@gmail.com> Co-authored-by: Justin Baur <19896123+justindbaur@users.noreply.github.com>
This commit is contained in:
37
src/Core/Utilities/KdfSettingsValidator.cs
Normal file
37
src/Core/Utilities/KdfSettingsValidator.cs
Normal file
@ -0,0 +1,37 @@
|
||||
using System.ComponentModel.DataAnnotations;
|
||||
using Bit.Core.Enums;
|
||||
|
||||
namespace Bit.Core.Utilities;
|
||||
|
||||
public static class KdfSettingsValidator
|
||||
{
|
||||
public static IEnumerable<ValidationResult> Validate(KdfType kdfType, int kdfIterations, int? kdfMemory, int? kdfParallelism)
|
||||
{
|
||||
switch (kdfType)
|
||||
{
|
||||
case KdfType.PBKDF2_SHA256:
|
||||
if (kdfIterations < 5000 || kdfIterations > 2_000_000)
|
||||
{
|
||||
yield return new ValidationResult("KDF iterations must be between 5000 and 2000000.");
|
||||
}
|
||||
break;
|
||||
case KdfType.Argon2id:
|
||||
if (kdfIterations <= 0)
|
||||
{
|
||||
yield return new ValidationResult("Argon2 iterations must be greater than 0.");
|
||||
}
|
||||
else if (!kdfMemory.HasValue || kdfMemory.Value < 15 || kdfMemory.Value > 1024)
|
||||
{
|
||||
yield return new ValidationResult("Argon2 memory must be between 15mb and 1024mb.");
|
||||
}
|
||||
else if (!kdfParallelism.HasValue || kdfParallelism.Value < 1 || kdfParallelism.Value > 16)
|
||||
{
|
||||
yield return new ValidationResult("Argon2 parallelism must be between 1 and 16.");
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
Reference in New Issue
Block a user