std.krypto
std.krypto gathers cryptography and security in one place: hashing, password handling, signing and verifying, random tokens and UUIDs — the right modern choices, made easy to reach.
std.krypto gathers cryptography and security in one place: hashing, password handling, signing and verifying, random tokens and UUIDs. The point is that the right, modern choices should be easy to reach — so you do not have to be a cryptographer to do things safely.
Here you find hash_passord and sjekk_passord for storing passwords properly, token and uuid4 for unpredictable identifiers, signer and verifiser for protecting data you send out and take in, and hash functions such as sha256 and hmac_sha256. Older algorithms like md5 are included only to read old data — never use them for anything new.
When to use it
Use std.krypto when you need to store passwords safely, make unpredictable tokens, sign data you send out and verify what comes in, or hash content. The safe choices are already made for you — you just need to pick the right function.
Getting started
bruk std.krypto som krypto
funksjon start() -> heiltall {
la hash = krypto.hash_passord("hemmeleg") // store this, not the password
hvis krypto.sjekk_passord("hemmeleg", hash) {
skriv("riktig passord")
}
la id = krypto.uuid4() // unpredictable identifier
skriv(id)
returner 0
}Always store the result of hash_passord, never the password itself. sjekk_passord compares an attempt against the stored hash in a safe way.
The functions
The functions group by purpose: identifiers and tokens (uuid4, uuid_kompakt, token, token_url, token_sifre), hashing (sha256, sha256_med_salt, hmac_sha256, pbkdf2_sha256), passwords (hash_passord, sjekk_passord, er_sterkt_passord), signing (signer, verifiser, usigner, and the variants with expiry), and helpers such as konstant_lik and base64.
uuid_kompakt() -> tekst— Returns a UUID without hyphens.er_gyldig_uuid(s: tekst) -> boolsk— True if the text is a valid UUID.token(n_bytes: heltall) -> tekst— A random token withn_bytesbytes of randomness.token_url(n_bytes: heltall) -> tekst— A URL-safe random token.token_sifre(n: heltall) -> tekst— A random token made up of digits only.hash_passord(passord: tekst) -> tekst— Hashes a password safely for storage (with salt, deliberately slow).sjekk_passord(passord: tekst, lagra_hash: tekst) -> boolsk— Checks a password attempt against a stored hash.er_sterkt_passord(passord: tekst) -> boolsk— True if the password meets the strength requirements.signer(hemmeleg: tekst, data: tekst) -> tekst— Signs data with a secret, so you can verify it later.verifiser(hemmeleg: tekst, signert: tekst) -> boolsk— True if a signature is valid for the secret.usigner(hemmeleg: tekst, signert: tekst) -> tekst— Extracts the original data from something signed.signer_med_utløp(hemmeleg: tekst, data: tekst, ttl_sek: heltall) -> tekst— Signs data with a lifetime in seconds.usigner_med_utløp(hemmeleg: tekst, signert: tekst) -> tekst— Extracts data, but fails if the signature has expired.konstant_lik(a: tekst, b: tekst) -> boolsk— Compares two texts in constant time, without leaking through timing.
Good to know
- Never store passwords in clear text — use
hash_passord, and check withsjekk_passord. konstant_likcompares without leaking information through how long it takes; use it when you compare secrets.md5is included only for backwards compatibility; choosesha256or stronger for anything new.
std.krypto is one of the modules in the standard library. Everything ships with the runtime — no installation, no external dependencies. See also Documentation for the language and the runtime.
Related
- std.tekststd.tekst is the toolbox for everything to do with text — searching and checking, splitting and joining, trimming whitespace, changing case, and converting to and from numbers.
- std.httpstd.http is a client for talking to other services over HTTP and HTTPS. You can fetch data, send data, and interpret the response — including JSON — without building the request by hand.
- std.dbstd.db gives you access to databases with a small, familiar set of functions: open a connection, run SQL, fetch values and rows, and control transactions.