ludic/crypto-hmac_sha256.html
2026-09-17 22:10:03 +00:00

35 lines
No EOL
2.4 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Crypto.hmac_sha256 — Ludic</title>
<meta name="description" content="Sign a message with a shared secret key.">
<link rel="stylesheet" href="base.css">
<link rel="stylesheet" href="docs.css">
</head>
<body>
<header class="nav"><div class="wrap nav-in"><a class="brand" href="index.html"><span class="logo">L</span> Ludic</a><button class="nav-toggle" aria-label="Toggle menu" aria-expanded="false">☰</button><nav class="nav-links"><a href="index.html">Home</a><a href="api.html">API Reference</a><a class="nav-cta" href="https://git.workshopsoft.io/workshopsoft/ludic">Source ↗</a></nav></div></header>
<main class="wrap item">
<div class="crumbs"><a href="api.html">API Reference</a> <span>›</span> <a href="ns-crypto.html">Crypto</a> <span>›</span> <span class="here">Crypto.hmac_sha256</span></div>
<div class="item-head">
<span class="kind-badge kind-method">method</span>
<h1 id="top">Crypto.hmac_sha256</h1>
</div>
<code class="sig">Crypto.hmac_sha256(key, msg) -&gt; string</code>
<div class="desc"><p>Computes HMAC-SHA256 over <code>msg</code> under the secret <code>key</code> (RFC 2104) and returns the 64-character lowercase hex tag. Unlike a bare hash, a MAC cannot be recomputed without the key, so it authenticates the message: attach the tag to a save file or a network packet, and a receiver who shares the key can tell whether the payload was altered or forged. To check the tag on the other side, pass it to <a href="crypto-verify_hmac"><code>Crypto.verify_hmac</code></a> rather than comparing hex with <code>==</code>.</p></div>
<div class="params"><h2>Parameters</h2><div class="param" id="param-key"><code class="pname">key</code><span class="pdesc">the shared secret; keep it out of the shipped client where you can</span></div><div class="param" id="param-msg"><code class="pname">msg</code><span class="pdesc">the payload being signed</span></div></div>
<div class="examples"><h2>Example</h2><pre data-lang="ludic">program SignSave {
entry {
let key = "s3cret"
let payload = "score=9001;level=12"
let mac = Crypto.hmac_sha256(key, payload)
print(mac)
}
}</pre></div>
<a class="back" href="api.html">← All symbols</a>
</main>
<script src="ludic-highlight.js"></script>
<script>Ludic.highlightAll(); Ludic.installCards(); Ludic.flashTarget();</script>
</body></html>