├── .gitignore ├── .travis.yml ├── ChangeLog.md ├── LICENSE-APL2.txt ├── LICENSE-EPL.txt ├── README.md ├── project.clj ├── src └── clojure │ └── clojurewerkz │ └── scrypt │ └── core.clj └── test └── clojurewerkz └── scrypt └── core_test.clj /.gitignore: -------------------------------------------------------------------------------- 1 | pom.xml 2 | *jar 3 | /lib/ 4 | /classes/ 5 | .lein-* 6 | TAGS 7 | checkouts/* 8 | .nrepl-* 9 | -------------------------------------------------------------------------------- /.travis.yml: -------------------------------------------------------------------------------- 1 | language: clojure 2 | lein: lein2 3 | script: lein2 all test 4 | jdk: 5 | - openjdk6 6 | - openjdk7 7 | - oraclejdk7 8 | - oraclejdk8 9 | -------------------------------------------------------------------------------- /ChangeLog.md: -------------------------------------------------------------------------------- 1 | # Changes Between 1.1.0 and 1.2.0 2 | 3 | ## Clojure 1.6 4 | 5 | The library now depends on Clojure 1.6. 6 | 7 | 8 | # Changes Between 1.0.0 and 1.1.0 9 | 10 | ## Lambdaworks Scrypt Upgrade 11 | 12 | [Lambdaworks Scrypt](https://github.com/wg/scrypt) is updated to `1.4.0`, 13 | which makes it possible to use a native implementation of the library. 14 | 15 | To quote the docs: 16 | 17 | ``` 18 | The system property "com.lambdaworks.jni.loader" may be set to override 19 | the default native library loader with one of the following values: 20 | 21 | * nil: refuse to load native libraries and revert to pure Java implementation 22 | * jar: extract native library from jar and load with System.load 23 | * sys: use System.loadLibrary, which may require java.library.path to be set 24 | ``` 25 | 26 | ## Clojure 1.3 Support Dropped 27 | 28 | Scrypt no longer officially supports Clojure 1.3. 29 | -------------------------------------------------------------------------------- /LICENSE-APL2.txt: -------------------------------------------------------------------------------- 1 | 2 | Apache License 3 | Version 2.0, January 2004 4 | http://www.apache.org/licenses/ 5 | 6 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 7 | 8 | 1. Definitions. 9 | 10 | "License" shall mean the terms and conditions for use, reproduction, 11 | and distribution as defined by Sections 1 through 9 of this document. 12 | 13 | "Licensor" shall mean the copyright owner or entity authorized by 14 | the copyright owner that is granting the License. 15 | 16 | "Legal Entity" shall mean the union of the acting entity and all 17 | other entities that control, are controlled by, or are under common 18 | control with that entity. For the purposes of this definition, 19 | "control" means (i) the power, direct or indirect, to cause the 20 | direction or management of such entity, whether by contract or 21 | otherwise, or (ii) ownership of fifty percent (50%) or more of the 22 | outstanding shares, or (iii) beneficial ownership of such entity. 23 | 24 | "You" (or "Your") shall mean an individual or Legal Entity 25 | exercising permissions granted by this License. 26 | 27 | "Source" form shall mean the preferred form for making modifications, 28 | including but not limited to software source code, documentation 29 | source, and configuration files. 30 | 31 | "Object" form shall mean any form resulting from mechanical 32 | transformation or translation of a Source form, including but 33 | not limited to compiled object code, generated documentation, 34 | and conversions to other media types. 35 | 36 | "Work" shall mean the work of authorship, whether in Source or 37 | Object form, made available under the License, as indicated by a 38 | copyright notice that is included in or attached to the work 39 | (an example is provided in the Appendix below). 40 | 41 | "Derivative Works" shall mean any work, whether in Source or Object 42 | form, that is based on (or derived from) the Work and for which the 43 | editorial revisions, annotations, elaborations, or other modifications 44 | represent, as a whole, an original work of authorship. For the purposes 45 | of this License, Derivative Works shall not include works that remain 46 | separable from, or merely link (or bind by name) to the interfaces of, 47 | the Work and Derivative Works thereof. 48 | 49 | "Contribution" shall mean any work of authorship, including 50 | the original version of the Work and any modifications or additions 51 | to that Work or Derivative Works thereof, that is intentionally 52 | submitted to Licensor for inclusion in the Work by the copyright owner 53 | or by an individual or Legal Entity authorized to submit on behalf of 54 | the copyright owner. For the purposes of this definition, "submitted" 55 | means any form of electronic, verbal, or written communication sent 56 | to the Licensor or its representatives, including but not limited to 57 | communication on electronic mailing lists, source code control systems, 58 | and issue tracking systems that are managed by, or on behalf of, the 59 | Licensor for the purpose of discussing and improving the Work, but 60 | excluding communication that is conspicuously marked or otherwise 61 | designated in writing by the copyright owner as "Not a Contribution." 62 | 63 | "Contributor" shall mean Licensor and any individual or Legal Entity 64 | on behalf of whom a Contribution has been received by Licensor and 65 | subsequently incorporated within the Work. 66 | 67 | 2. Grant of Copyright License. Subject to the terms and conditions of 68 | this License, each Contributor hereby grants to You a perpetual, 69 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 70 | copyright license to reproduce, prepare Derivative Works of, 71 | publicly display, publicly perform, sublicense, and distribute the 72 | Work and such Derivative Works in Source or Object form. 73 | 74 | 3. Grant of Patent License. Subject to the terms and conditions of 75 | this License, each Contributor hereby grants to You a perpetual, 76 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 77 | (except as stated in this section) patent license to make, have made, 78 | use, offer to sell, sell, import, and otherwise transfer the Work, 79 | where such license applies only to those patent claims licensable 80 | by such Contributor that are necessarily infringed by their 81 | Contribution(s) alone or by combination of their Contribution(s) 82 | with the Work to which such Contribution(s) was submitted. If You 83 | institute patent litigation against any entity (including a 84 | cross-claim or counterclaim in a lawsuit) alleging that the Work 85 | or a Contribution incorporated within the Work constitutes direct 86 | or contributory patent infringement, then any patent licenses 87 | granted to You under this License for that Work shall terminate 88 | as of the date such litigation is filed. 89 | 90 | 4. Redistribution. You may reproduce and distribute copies of the 91 | Work or Derivative Works thereof in any medium, with or without 92 | modifications, and in Source or Object form, provided that You 93 | meet the following conditions: 94 | 95 | (a) You must give any other recipients of the Work or 96 | Derivative Works a copy of this License; and 97 | 98 | (b) You must cause any modified files to carry prominent notices 99 | stating that You changed the files; and 100 | 101 | (c) You must retain, in the Source form of any Derivative Works 102 | that You distribute, all copyright, patent, trademark, and 103 | attribution notices from the Source form of the Work, 104 | excluding those notices that do not pertain to any part of 105 | the Derivative Works; and 106 | 107 | (d) If the Work includes a "NOTICE" text file as part of its 108 | distribution, then any Derivative Works that You distribute must 109 | include a readable copy of the attribution notices contained 110 | within such NOTICE file, excluding those notices that do not 111 | pertain to any part of the Derivative Works, in at least one 112 | of the following places: within a NOTICE text file distributed 113 | as part of the Derivative Works; within the Source form or 114 | documentation, if provided along with the Derivative Works; or, 115 | within a display generated by the Derivative Works, if and 116 | wherever such third-party notices normally appear. The contents 117 | of the NOTICE file are for informational purposes only and 118 | do not modify the License. You may add Your own attribution 119 | notices within Derivative Works that You distribute, alongside 120 | or as an addendum to the NOTICE text from the Work, provided 121 | that such additional attribution notices cannot be construed 122 | as modifying the License. 123 | 124 | You may add Your own copyright statement to Your modifications and 125 | may provide additional or different license terms and conditions 126 | for use, reproduction, or distribution of Your modifications, or 127 | for any such Derivative Works as a whole, provided Your use, 128 | reproduction, and distribution of the Work otherwise complies with 129 | the conditions stated in this License. 130 | 131 | 5. Submission of Contributions. Unless You explicitly state otherwise, 132 | any Contribution intentionally submitted for inclusion in the Work 133 | by You to the Licensor shall be under the terms and conditions of 134 | this License, without any additional terms or conditions. 135 | Notwithstanding the above, nothing herein shall supersede or modify 136 | the terms of any separate license agreement you may have executed 137 | with Licensor regarding such Contributions. 138 | 139 | 6. Trademarks. This License does not grant permission to use the trade 140 | names, trademarks, service marks, or product names of the Licensor, 141 | except as required for reasonable and customary use in describing the 142 | origin of the Work and reproducing the content of the NOTICE file. 143 | 144 | 7. Disclaimer of Warranty. Unless required by applicable law or 145 | agreed to in writing, Licensor provides the Work (and each 146 | Contributor provides its Contributions) on an "AS IS" BASIS, 147 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or 148 | implied, including, without limitation, any warranties or conditions 149 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A 150 | PARTICULAR PURPOSE. You are solely responsible for determining the 151 | appropriateness of using or redistributing the Work and assume any 152 | risks associated with Your exercise of permissions under this License. 153 | 154 | 8. Limitation of Liability. In no event and under no legal theory, 155 | whether in tort (including negligence), contract, or otherwise, 156 | unless required by applicable law (such as deliberate and grossly 157 | negligent acts) or agreed to in writing, shall any Contributor be 158 | liable to You for damages, including any direct, indirect, special, 159 | incidental, or consequential damages of any character arising as a 160 | result of this License or out of the use or inability to use the 161 | Work (including but not limited to damages for loss of goodwill, 162 | work stoppage, computer failure or malfunction, or any and all 163 | other commercial damages or losses), even if such Contributor 164 | has been advised of the possibility of such damages. 165 | 166 | 9. Accepting Warranty or Additional Liability. While redistributing 167 | the Work or Derivative Works thereof, You may choose to offer, 168 | and charge a fee for, acceptance of support, warranty, indemnity, 169 | or other liability obligations and/or rights consistent with this 170 | License. However, in accepting such obligations, You may act only 171 | on Your own behalf and on Your sole responsibility, not on behalf 172 | of any other Contributor, and only if You agree to indemnify, 173 | defend, and hold each Contributor harmless for any liability 174 | incurred by, or claims asserted against, such Contributor by reason 175 | of your accepting any such warranty or additional liability. 176 | 177 | END OF TERMS AND CONDITIONS 178 | 179 | APPENDIX: How to apply the Apache License to your work. 180 | 181 | To apply the Apache License to your work, attach the following 182 | boilerplate notice, with the fields enclosed by brackets "[]" 183 | replaced with your own identifying information. (Don't include 184 | the brackets!) The text should be enclosed in the appropriate 185 | comment syntax for the file format. We also recommend that a 186 | file or class name and description of purpose be included on the 187 | same "printed page" as the copyright notice for easier 188 | identification within third-party archives. 189 | 190 | Copyright 2013, The ClojureWerkz Team 191 | 192 | Licensed under the Apache License, Version 2.0 (the "License"); 193 | you may not use this file except in compliance with the License. 194 | You may obtain a copy of the License at 195 | 196 | http://www.apache.org/licenses/LICENSE-2.0 197 | 198 | Unless required by applicable law or agreed to in writing, software 199 | distributed under the License is distributed on an "AS IS" BASIS, 200 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 201 | See the License for the specific language governing permissions and 202 | limitations under the License. 203 | -------------------------------------------------------------------------------- /LICENSE-EPL.txt: -------------------------------------------------------------------------------- 1 | Eclipse Public License - v 1.0 2 | 3 | THE ACCOMPANYING PROGRAM IS PROVIDED UNDER THE TERMS OF THIS ECLIPSE PUBLIC LICENSE ("AGREEMENT"). ANY USE, REPRODUCTION OR DISTRIBUTION OF THE PROGRAM CONSTITUTES RECIPIENT'S ACCEPTANCE OF THIS AGREEMENT. 4 | 5 | 1. DEFINITIONS 6 | 7 | "Contribution" means: 8 | 9 | a) in the case of the initial Contributor, the initial code and documentation distributed under this Agreement, and 10 | b) in the case of each subsequent Contributor: 11 | i) changes to the Program, and 12 | ii) additions to the Program; 13 | where such changes and/or additions to the Program originate from and are distributed by that particular Contributor. A Contribution 'originates' from a Contributor if it was added to the Program by such Contributor itself or anyone acting on such Contributor's behalf. Contributions do not include additions to the Program which: (i) are separate modules of software distributed in conjunction with the Program under their own license agreement, and (ii) are not derivative works of the Program. 14 | "Contributor" means any person or entity that distributes the Program. 15 | 16 | "Licensed Patents" mean patent claims licensable by a Contributor which are necessarily infringed by the use or sale of its Contribution alone or when combined with the Program. 17 | 18 | "Program" means the Contributions distributed in accordance with this Agreement. 19 | 20 | "Recipient" means anyone who receives the Program under this Agreement, including all Contributors. 21 | 22 | 2. GRANT OF RIGHTS 23 | 24 | a) Subject to the terms of this Agreement, each Contributor hereby grants Recipient a non-exclusive, worldwide, royalty-free copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, distribute and sublicense the Contribution of such Contributor, if any, and such derivative works, in source code and object code form. 25 | b) Subject to the terms of this Agreement, each Contributor hereby grants Recipient a non-exclusive, worldwide, royalty-free patent license under Licensed Patents to make, use, sell, offer to sell, import and otherwise transfer the Contribution of such Contributor, if any, in source code and object code form. This patent license shall apply to the combination of the Contribution and the Program if, at the time the Contribution is added by the Contributor, such addition of the Contribution causes such combination to be covered by the Licensed Patents. The patent license shall not apply to any other combinations which include the Contribution. No hardware per se is licensed hereunder. 26 | c) Recipient understands that although each Contributor grants the licenses to its Contributions set forth herein, no assurances are provided by any Contributor that the Program does not infringe the patent or other intellectual property rights of any other entity. Each Contributor disclaims any liability to Recipient for claims brought by any other entity based on infringement of intellectual property rights or otherwise. As a condition to exercising the rights and licenses granted hereunder, each Recipient hereby assumes sole responsibility to secure any other intellectual property rights needed, if any. For example, if a third party patent license is required to allow Recipient to distribute the Program, it is Recipient's responsibility to acquire that license before distributing the Program. 27 | d) Each Contributor represents that to its knowledge it has sufficient copyright rights in its Contribution, if any, to grant the copyright license set forth in this Agreement. 28 | 3. REQUIREMENTS 29 | 30 | A Contributor may choose to distribute the Program in object code form under its own license agreement, provided that: 31 | 32 | a) it complies with the terms and conditions of this Agreement; and 33 | b) its license agreement: 34 | i) effectively disclaims on behalf of all Contributors all warranties and conditions, express and implied, including warranties or conditions of title and non-infringement, and implied warranties or conditions of merchantability and fitness for a particular purpose; 35 | ii) effectively excludes on behalf of all Contributors all liability for damages, including direct, indirect, special, incidental and consequential damages, such as lost profits; 36 | iii) states that any provisions which differ from this Agreement are offered by that Contributor alone and not by any other party; and 37 | iv) states that source code for the Program is available from such Contributor, and informs licensees how to obtain it in a reasonable manner on or through a medium customarily used for software exchange. 38 | When the Program is made available in source code form: 39 | 40 | a) it must be made available under this Agreement; and 41 | b) a copy of this Agreement must be included with each copy of the Program. 42 | Contributors may not remove or alter any copyright notices contained within the Program. 43 | 44 | Each Contributor must identify itself as the originator of its Contribution, if any, in a manner that reasonably allows subsequent Recipients to identify the originator of the Contribution. 45 | 46 | 4. COMMERCIAL DISTRIBUTION 47 | 48 | Commercial distributors of software may accept certain responsibilities with respect to end users, business partners and the like. While this license is intended to facilitate the commercial use of the Program, the Contributor who includes the Program in a commercial product offering should do so in a manner which does not create potential liability for other Contributors. Therefore, if a Contributor includes the Program in a commercial product offering, such Contributor ("Commercial Contributor") hereby agrees to defend and indemnify every other Contributor ("Indemnified Contributor") against any losses, damages and costs (collectively "Losses") arising from claims, lawsuits and other legal actions brought by a third party against the Indemnified Contributor to the extent caused by the acts or omissions of such Commercial Contributor in connection with its distribution of the Program in a commercial product offering. The obligations in this section do not apply to any claims or Losses relating to any actual or alleged intellectual property infringement. In order to qualify, an Indemnified Contributor must: a) promptly notify the Commercial Contributor in writing of such claim, and b) allow the Commercial Contributor to control, and cooperate with the Commercial Contributor in, the defense and any related settlement negotiations. The Indemnified Contributor may participate in any such claim at its own expense. 49 | 50 | For example, a Contributor might include the Program in a commercial product offering, Product X. That Contributor is then a Commercial Contributor. If that Commercial Contributor then makes performance claims, or offers warranties related to Product X, those performance claims and warranties are such Commercial Contributor's responsibility alone. Under this section, the Commercial Contributor would have to defend claims against the other Contributors related to those performance claims and warranties, and if a court requires any other Contributor to pay any damages as a result, the Commercial Contributor must pay those damages. 51 | 52 | 5. NO WARRANTY 53 | 54 | EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, THE PROGRAM IS PROVIDED ON AN "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED INCLUDING, WITHOUT LIMITATION, ANY WARRANTIES OR CONDITIONS OF TITLE, NON-INFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Each Recipient is solely responsible for determining the appropriateness of using and distributing the Program and assumes all risks associated with its exercise of rights under this Agreement , including but not limited to the risks and costs of program errors, compliance with applicable laws, damage to or loss of data, programs or equipment, and unavailability or interruption of operations. 55 | 56 | 6. DISCLAIMER OF LIABILITY 57 | 58 | EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, NEITHER RECIPIENT NOR ANY CONTRIBUTORS SHALL HAVE ANY LIABILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING WITHOUT LIMITATION LOST PROFITS), HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OR DISTRIBUTION OF THE PROGRAM OR THE EXERCISE OF ANY RIGHTS GRANTED HEREUNDER, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. 59 | 60 | 7. GENERAL 61 | 62 | If any provision of this Agreement is invalid or unenforceable under applicable law, it shall not affect the validity or enforceability of the remainder of the terms of this Agreement, and without further action by the parties hereto, such provision shall be reformed to the minimum extent necessary to make such provision valid and enforceable. 63 | 64 | If Recipient institutes patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Program itself (excluding combinations of the Program with other software or hardware) infringes such Recipient's patent(s), then such Recipient's rights granted under Section 2(b) shall terminate as of the date such litigation is filed. 65 | 66 | All Recipient's rights under this Agreement shall terminate if it fails to comply with any of the material terms or conditions of this Agreement and does not cure such failure in a reasonable period of time after becoming aware of such noncompliance. If all Recipient's rights under this Agreement terminate, Recipient agrees to cease use and distribution of the Program as soon as reasonably practicable. However, Recipient's obligations under this Agreement and any licenses granted by Recipient relating to the Program shall continue and survive. 67 | 68 | Everyone is permitted to copy and distribute copies of this Agreement, but in order to avoid inconsistency the Agreement is copyrighted and may only be modified in the following manner. The Agreement Steward reserves the right to publish new versions (including revisions) of this Agreement from time to time. No one other than the Agreement Steward has the right to modify this Agreement. The Eclipse Foundation is the initial Agreement Steward. The Eclipse Foundation may assign the responsibility to serve as the Agreement Steward to a suitable separate entity. Each new version of the Agreement will be given a distinguishing version number. The Program (including Contributions) may always be distributed subject to the version of the Agreement under which it was received. In addition, after a new version of the Agreement is published, Contributor may elect to distribute the Program (including its Contributions) under the new version. Except as expressly stated in Sections 2(a) and 2(b) above, Recipient receives no rights or licenses to the intellectual property of any Contributor under this Agreement, whether expressly, by implication, estoppel or otherwise. All rights in the Program not expressly granted under this Agreement are reserved. 69 | 70 | This Agreement is governed by the laws of the State of New York and the intellectual property laws of the United States of America. No party to this Agreement will bring a legal action under this Agreement more than one year after the cause of action arose. Each party waives its rights to a jury trial in any resulting litigation. 71 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Clojure Scrypt Library 2 | 3 | scrypt is a tiny Clojure library for the scrypt key derivation function. 4 | 5 | ## Why Use Scrypt 6 | 7 | Scrypt has a significantly higher cost of carrying out brute force attacks on hashed values: 8 | 9 | ![Key derivation function comparison](https://raw.github.com/pbhogan/scrypt/master/kdf-comparison.png) 10 | 11 | For more details, see the [Scrypt paper](https://www.tarsnap.com/scrypt/scrypt.pdf). 12 | 13 | 14 | ## Community 15 | 16 | To subscribe for announcements of releases, important changes and so on, please follow [@ClojureWerkz](https://twitter.com/#!/clojurewerkz) on Twitter. 17 | 18 | 19 | ## Project Maturity 20 | 21 | ClojureWerkz Scrypt is a fairly young project built on top of a Java 22 | implementation of Scrypt that has been around for a couple of years. 23 | 24 | 25 | ## Artifacts 26 | 27 | Scrypt artifacts are [released to Clojars](https://clojars.org/clojurewerkz/scrypt). If you are using Maven, add the following repository 28 | definition to your `pom.xml`: 29 | 30 | ``` xml 31 | 32 | clojars.org 33 | http://clojars.org/repo 34 | 35 | ``` 36 | 37 | ### The Most Recent Release 38 | 39 | With Leiningen: 40 | 41 | [clojurewerkz/scrypt "1.2.0"] 42 | 43 | 44 | With Maven: 45 | 46 | 47 | clojurewerkz 48 | scrypt 49 | 1.2.0 50 | 51 | 52 | 53 | 54 | ## Documentation 55 | 56 | Scrypt has a single namespace: `clojurewerkz.scrypt.core`, and two functions: 57 | 58 | * `clojurewerkz.scrypt.core/encrypt` encrypts a string using Scrypt 59 | * `clojurewerkz.scrypt.core/verify` verifies a string against a hash produced by `encrypt` 60 | 61 | An example to demonstrate them: 62 | 63 | ``` clojure 64 | (require '[clojurewerkz.scrypt.core :as sc]) 65 | 66 | (let [h (sc/encrypt "secret" 16384 8 1)] 67 | (sc/verify "secret" h)) 68 | ;= true 69 | 70 | (let [h (sc/encrypt "secret" 16384 8 1)] 71 | (sc/verify "another value" h)) 72 | ;= false 73 | ``` 74 | 75 | Arguments that `clojurewerkz.scrypt.core/encrypt` takes control CPU, RAM and parallelization 76 | cost. The values in the example above are optimal starting points for many applications. 77 | 78 | See the [Scrypt paper](https://www.tarsnap.com/scrypt/scrypt.pdf) 79 | for a detailed information. 80 | 81 | ### Native Scrypt Implementation 82 | 83 | It is possible to use a native implementation as of ClojureWerkz Scrypt `1.1.0`. 84 | From [Lambdaworks Scrypt documentation](https://github.com/wg/scrypt/blob/master/README): 85 | 86 | ``` 87 | When the native library can be loaded it will be used instead of the pure 88 | Java implementation. On a J2SE compliant JVM the native library will be 89 | extracted from the jar and loaded, and on other VMs System.loadLibrary will 90 | be called. 91 | 92 | The system property "com.lambdaworks.jni.loader" may be set to override 93 | the default native library loader with one of the following values: 94 | 95 | * nil: refuse to load native libraries and revert to pure Java implementation 96 | * jar: extract native library from jar and load with System.load 97 | * sys: use System.loadLibrary, which may require java.library.path to be set 98 | ``` 99 | 100 | 101 | ## Supported Clojure Versions 102 | 103 | scrypt requires Clojure 1.4+. 104 | 105 | 106 | ## Continuous Integration Status 107 | 108 | [![Continuous Integration status](https://secure.travis-ci.org/clojurewerkz/scrypt.png)](http://travis-ci.org/clojurewerkz/scrypt) 109 | 110 | 111 | 112 | ## Scrypt Is a ClojureWerkz Project 113 | 114 | This library is part of the [group of Clojure libraries known as ClojureWerkz](http://clojurewerkz.org), together with 115 | * [Monger](http://clojuremongodb.info) 116 | * [Langohr](https://github.com/michaelklishin/langohr) 117 | * [Elastisch](https://github.com/clojurewerkz/elastisch) 118 | * [Welle](http://clojureriak.info) 119 | * [Neocons](http://clojureneo4j.info) 120 | * [Quartzite](https://github.com/michaelklishin/quartzite) and several others. 121 | 122 | 123 | ## Development 124 | 125 | scrypt uses [Leiningen 126 | 2](https://github.com/technomancy/leiningen/blob/master/doc/TUTORIAL.md). Make 127 | sure you have it installed and then run tests against supported 128 | Clojure versions using 129 | 130 | lein all test 131 | 132 | Then create a branch and make your changes on it. Once you are done 133 | with your changes and all tests pass, submit a pull request on GitHub. 134 | 135 | 136 | 137 | ## License 138 | 139 | Copyright (C) 2013-2016 Michael S. Klishin, Alex Petrov. 140 | 141 | Double licensed under the [Eclipse Public License](http://www.eclipse.org/legal/epl-v10.html) (the same as Clojure) or 142 | the [Apache Public License 2.0](http://www.apache.org/licenses/LICENSE-2.0.html). 143 | -------------------------------------------------------------------------------- /project.clj: -------------------------------------------------------------------------------- 1 | (defproject clojurewerkz/scrypt "1.3.0-SNAPSHOT" 2 | :description "A Clojure library for scrypt encryption" 3 | :dependencies [[org.clojure/clojure "1.6.0"] 4 | [com.lambdaworks/scrypt "1.4.0"]] 5 | :profiles {:1.4 {:dependencies [[org.clojure/clojure "1.4.0"]]} 6 | :1.5 {:dependencies [[org.clojure/clojure "1.5.1"]]} 7 | :1.7 {:dependencies [[org.clojure/clojure "1.7.0"]]} 8 | :master {:dependencies [[org.clojure/clojure "1.8.0-master-SNAPSHOT"]]} 9 | :dev {:resource-paths ["test/resources"] 10 | :plugins [[codox "0.8.10"]] 11 | :codox {:sources ["src/clojure"] 12 | :output-dir "doc/api"}}} 13 | :aliases {"all" ["with-profile" "dev:dev,1.4:dev,1.5:dev,1.7:dev,master"]} 14 | :repositories {"sonatype" {:url "http://oss.sonatype.org/content/repositories/releases" 15 | :snapshots false 16 | :releases {:checksum :fail}} 17 | "sonatype-snapshots" {:url "http://oss.sonatype.org/content/repositories/snapshots" 18 | :snapshots true 19 | :releases {:checksum :fail :update :always}}} 20 | :javac-options ["-target" "1.6" "-source" "1.6"] 21 | :jvm-opts ["-Dfile.encoding=utf-8"] 22 | :source-paths ["src/clojure"]) 23 | -------------------------------------------------------------------------------- /src/clojure/clojurewerkz/scrypt/core.clj: -------------------------------------------------------------------------------- 1 | ;; Copyright (c) 2013-2014 Michael S. Klishin, Alex Petrov, and the ClojureWerkz Team 2 | ;; 3 | ;; This file is provided to you under the Apache License, Version 2.0 (the 4 | ;; "License"); you may not use this file except in compliance with the License. 5 | ;; You may obtain a copy of the License at 6 | ;; 7 | ;; http://www.apache.org/licenses/LICENSE-2.0 8 | ;; 9 | ;; Unless required by applicable law or agreed to in writing, software 10 | ;; distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 11 | ;; WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the 12 | ;; License for the specific language governing permissions and limitations under 13 | ;; the License. 14 | 15 | (ns clojurewerkz.scrypt.core 16 | "Scrypt encryption function. 17 | 18 | To learn more about scrypt, see https://www.tarsnap.com/scrypt/scrypt.pdf" 19 | (:import com.lambdaworks.crypto.SCryptUtil)) 20 | 21 | 22 | ;; 23 | ;; API 24 | ;; 25 | 26 | (defn ^String encrypt 27 | "Encrypts a string value using scrypt. 28 | 29 | Arguments are: 30 | 31 | s (string): a string to encrypt 32 | n (integer): CPU cost parameter (16384 is a good starting value) 33 | r (integer): RAM cost parameter (8 is a good starting value) 34 | p (integer): parallelism parameter (1 is a good starting value)" 35 | [^String s ^long n ^long r ^long p] 36 | (SCryptUtil/scrypt s n r p)) 37 | 38 | (defn verify 39 | "Verifies a value against a hash produced by scrypt" 40 | [^String candidate ^String hash] 41 | (SCryptUtil/check candidate hash)) 42 | -------------------------------------------------------------------------------- /test/clojurewerkz/scrypt/core_test.clj: -------------------------------------------------------------------------------- 1 | ;; This file is provided to you under the Apache License, Version 2.0 (the 2 | ;; "License"); you may not use this file except in compliance with the License. 3 | ;; You may obtain a copy of the License at 4 | ;; 5 | ;; http://www.apache.org/licenses/LICENSE-2.0 6 | ;; 7 | ;; Unless required by applicable law or agreed to in writing, software 8 | ;; distributed under the License is distributed on an "AS IS" BASIS, WITHOUT 9 | ;; WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the 10 | ;; License for the specific language governing permissions and limitations under 11 | ;; the License. 12 | 13 | (ns clojurewerkz.scrypt.core-test 14 | (:require [clojurewerkz.scrypt.core :as sc] 15 | [clojure.test :refer :all]) 16 | (:import java.util.UUID)) 17 | 18 | 19 | (deftest test-encrypt-and-check 20 | (let [pwd "secret" 21 | hashed (sc/encrypt pwd 16384 8 1)] 22 | (is (sc/verify pwd hashed)) 23 | (dotimes [i 50] 24 | (let [uid (str (UUID/randomUUID))] 25 | (is (not (sc/verify uid hashed))))))) 26 | 27 | --------------------------------------------------------------------------------