|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
HTTP authentication: Basic (RFC 7617) and stateless Digest (RFC 7616, SHA-256, qop=auth). More...
#include "protocore_config.h"Go to the source code of this file.
HTTP authentication: Basic (RFC 7617) and stateless Digest (RFC 7616, SHA-256, qop=auth).
Digest carries no per-nonce server state. A nonce is <issue_ms_hex>.<mac_hex> where the MAC is SHA-256(secret || issue_ms) truncated to 128 bits, so a returned nonce is authenticated by recomputing it and aged by reading the issue time back out of it. That is what makes the scheme safe under the shared-nothing worker model: the keying secret is set once at begin() and is read-only afterwards, and no worker owns a nonce table another worker has to see.
The module exports one symbol, Auth. Everything in auth.c has internal linkage.
Definition in file auth.h.