ludic/crypto-verify_hmac.html
2026-09-17 22:10:03 +00:00

39 lines
No EOL
2.8 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Crypto.verify_hmac — Ludic</title>
<meta name="description" content="Constant-time check that a MAC matches.">
<link rel="stylesheet" href="base.css">
<link rel="stylesheet" href="docs.css">
</head>
<body>
<header class="nav"><div class="wrap nav-in"><a class="brand" href="index.html"><span class="logo">L</span> Ludic</a><button class="nav-toggle" aria-label="Toggle menu" aria-expanded="false">☰</button><nav class="nav-links"><a href="index.html">Home</a><a href="api.html">API Reference</a><a class="nav-cta" href="https://git.workshopsoft.io/workshopsoft/ludic">Source ↗</a></nav></div></header>
<main class="wrap item">
<div class="crumbs"><a href="api.html">API Reference</a> <span>›</span> <a href="ns-crypto.html">Crypto</a> <span>›</span> <span class="here">Crypto.verify_hmac</span></div>
<div class="item-head">
<span class="kind-badge kind-method">method</span>
<h1 id="top">Crypto.verify_hmac</h1>
</div>
<code class="sig">Crypto.verify_hmac(key, msg, mac) -&gt; bool</code>
<div class="desc"><p>Recomputes HMAC-SHA256(<code>key</code>, <code>msg</code>) and compares it to the supplied <code>mac</code> hex string, returning <code>true</code> only if they match. The comparison is <em>constant-time</em>: it never stops early on the first differing character, so it does not leak — through how long the check took — how many leading bytes of a forged tag happened to be right. That leak is exactly what lets an attacker guess a MAC one byte at a time, which is why you should always verify with this and never with <code>==</code>. A mismatched length returns <code>false</code> immediately (the length of a MAC is not a secret).</p></div>
<div class="params"><h2>Parameters</h2><div class="param" id="param-key"><code class="pname">key</code><span class="pdesc">the shared secret used to sign</span></div><div class="param" id="param-msg"><code class="pname">msg</code><span class="pdesc">the payload as received</span></div><div class="param" id="param-mac"><code class="pname">mac</code><span class="pdesc">the hex tag to check, e.g. from <a href="crypto-hmac_sha256"><code>Crypto.hmac_sha256</code></a></span></div></div>
<div class="examples"><h2>Example</h2><pre data-lang="ludic">program CheckSave {
entry {
let key = "s3cret"
let payload = "score=9001;level=12"
let mac = Crypto.hmac_sha256(key, payload)
if Crypto.verify_hmac(key, payload, mac) {
print(1) # untampered
} else {
print(0) # altered or forged
}
}
}</pre></div>
<a class="back" href="api.html">← All symbols</a>
</main>
<script src="ludic-highlight.js"></script>
<script>Ludic.highlightAll(); Ludic.installCards(); Ludic.flashTarget();</script>
</body></html>