The from-scratch Go rewrite had unresolved bugs (missing go.sum, UI 404s, path issues) from being built without a working local Go toolchain to verify against. Switching strategy: use the actual upstream wireguard-ui codebase (proven, battle-tested single-server manager) as the base, and extend it for multi-server support instead of re-deriving everything from zero. Kept our own installers (bootstrap.sh, update.sh, scripts/install.sh, scripts/proxmox-install.sh) - these still apply, just need updating to build/install the upstream module layout instead of the old cmd/wireguard-ui-multi structure. Module path intentionally left as upstream's own (github.com/ngoduykhanh/wireguard-ui) for now to avoid touching every internal import; revisit if this needs to be fully rebranded. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
33 lines
804 B
Go
33 lines
804 B
Go
package util
|
|
|
|
import (
|
|
"encoding/base64"
|
|
"errors"
|
|
"fmt"
|
|
|
|
"golang.org/x/crypto/bcrypt"
|
|
)
|
|
|
|
func HashPassword(plaintext string) (string, error) {
|
|
bytes, err := bcrypt.GenerateFromPassword([]byte(plaintext), 14)
|
|
if err != nil {
|
|
return "", fmt.Errorf("cannot hash password: %w", err)
|
|
}
|
|
return base64.StdEncoding.EncodeToString(bytes), nil
|
|
}
|
|
|
|
func VerifyHash(base64Hash string, plaintext string) (bool, error) {
|
|
hash, err := base64.StdEncoding.DecodeString(base64Hash)
|
|
if err != nil {
|
|
return false, fmt.Errorf("cannot decode base64 hash: %w", err)
|
|
}
|
|
err = bcrypt.CompareHashAndPassword(hash, []byte(plaintext))
|
|
if errors.Is(err, bcrypt.ErrMismatchedHashAndPassword) {
|
|
return false, nil
|
|
}
|
|
if err != nil {
|
|
return false, fmt.Errorf("cannot verify password: %w", err)
|
|
}
|
|
return true, nil
|
|
}
|