ludic/crypto-random_bytes.html
2026-09-17 22:10:03 +00:00

33 lines
No EOL
2.6 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Crypto.random_bytes — Ludic</title>
<meta name="description" content="n bytes from the OS CSPRNG, as a 2n-character hex string.">
<link rel="stylesheet" href="base.css">
<link rel="stylesheet" href="docs.css">
</head>
<body>
<header class="nav"><div class="wrap nav-in"><a class="brand" href="index.html"><span class="logo">L</span> Ludic</a><button class="nav-toggle" aria-label="Toggle menu" aria-expanded="false">☰</button><nav class="nav-links"><a href="index.html">Home</a><a href="api.html">API Reference</a><a class="nav-cta" href="https://git.workshopsoft.io/workshopsoft/ludic">Source ↗</a></nav></div></header>
<main class="wrap item">
<div class="crumbs"><a href="api.html">API Reference</a> <span>›</span> <a href="ns-crypto.html">Crypto</a> <span>›</span> <span class="here">Crypto.random_bytes</span></div>
<div class="item-head">
<span class="kind-badge kind-method">method</span>
<h1 id="top">Crypto.random_bytes</h1>
</div>
<code class="sig">Crypto.random_bytes(n) -&gt; string</code>
<div class="desc"><p>Draws <code>n</code> bytes from the operating system's cryptographically-secure random number generator and returns them as a <code>2n</code>-character lowercase hex string. Use it for unguessable tokens, nonces, and session secrets — anything whose whole value is that an attacker cannot predict it. The result is hex rather than raw bytes for the same reason digests are: a <code>str</code> is null-terminated and raw random bytes can contain a zero byte, so hex is the form you can safely store and compare.</p><p>This is deliberately **non-deterministic** — it must never seed the lockstep simulation RNG (<a href="ns-Random"><code>Random</code></a>). Two calls return different values. On a platform without an OS CSPRNG (for example a bare wasm target) the draw degrades to zeroes rather than faulting; treat a real CSPRNG there as a platform-layer responsibility.</p></div>
<div class="params"><h2>Parameters</h2><div class="param" id="param-n"><code class="pname">n</code><span class="pdesc">the number of secure random bytes to draw</span></div></div>
<div class="examples"><h2>Example</h2><pre data-lang="ludic">program Token {
entry {
let session = Crypto.random_bytes(16) # 32 hex chars, unguessable
print(len(session)) # 32
}
}</pre></div>
<a class="back" href="api.html">← All symbols</a>
</main>
<script src="ludic-highlight.js"></script>
<script>Ludic.highlightAll(); Ludic.installCards(); Ludic.flashTarget();</script>
</body></html>