ludic/crypto-ct_equal.html
2026-09-17 22:10:03 +00:00

33 lines
No EOL
2.5 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Crypto.ct_equal — Ludic</title>
<meta name="description" content="Constant-time string equality for secrets.">
<link rel="stylesheet" href="base.css">
<link rel="stylesheet" href="docs.css">
</head>
<body>
<header class="nav"><div class="wrap nav-in"><a class="brand" href="index.html"><span class="logo">L</span> Ludic</a><button class="nav-toggle" aria-label="Toggle menu" aria-expanded="false">☰</button><nav class="nav-links"><a href="index.html">Home</a><a href="api.html">API Reference</a><a class="nav-cta" href="https://git.workshopsoft.io/workshopsoft/ludic">Source ↗</a></nav></div></header>
<main class="wrap item">
<div class="crumbs"><a href="api.html">API Reference</a> <span>›</span> <a href="ns-crypto.html">Crypto</a> <span>›</span> <span class="here">Crypto.ct_equal</span></div>
<div class="item-head">
<span class="kind-badge kind-method">method</span>
<h1 id="top">Crypto.ct_equal</h1>
</div>
<code class="sig">Crypto.ct_equal(a, b) -&gt; bool</code>
<div class="desc"><p>Compares two strings for equality without short-circuiting: every character is examined even once a difference is found, so the time taken does not reveal where — or whether — the strings first diverged. Reach for it whenever you compare a secret, token, or MAC that an attacker might be probing. For the common case of checking a message tag, <a href="crypto-verify_hmac"><code>Crypto.verify_hmac</code></a> already does this for you; use <code>ct_equal</code> directly when you hold both values yourself. Strings of different length return <code>false</code> at once (length is not secret). For ordinary, non-secret text just use <code>==</code> — the constant-time guarantee is not free.</p></div>
<div class="params"><h2>Parameters</h2><div class="param" id="param-a"><code class="pname">a</code><span class="pdesc">one string</span></div><div class="param" id="param-b"><code class="pname">b</code><span class="pdesc">the other string</span></div></div>
<div class="examples"><h2>Example</h2><pre data-lang="ludic">program CompareToken {
entry {
if Crypto.ct_equal("abc", "abc") { print(1) } else { print(0) } # 1
if Crypto.ct_equal("abc", "abd") { print(1) } else { print(0) } # 0
}
}</pre></div>
<a class="back" href="api.html">← All symbols</a>
</main>
<script src="ludic-highlight.js"></script>
<script>Ludic.highlightAll(); Ludic.installCards(); Ludic.flashTarget();</script>
</body></html>