serverpod_argon2
Zig 표준 라이브러리를 기반으로 한 Argon2 비밀번호 해싱 (argon2id, argon2i, argon2d). Dart 및 Flutter용 사전 빌드된 네이티브 라이브러리와 웹용 WebAssembly 모듈을 제공하여 로컬 툴체인 필요 없음...
Zig로 지원되는 네이티브 Argon2 해싱
>=1.2.1 <3.0.0^2.0.0^2.9.0^4.0.0>=2.7.0^1.25.6아래는 영문 원문 스냅샷입니다. 최신 내용은 GitHub에서 확인하세요.
Argon2 password hashing for Dart and Flutter, backed by the Argon2 implementation in the Zig standard library.
import 'package:serverpod_argon2/serverpod_argon2.dart';
final argon2 = await Argon2.load();
// $argon2id$v=19$m=19456,t=2,p=1$<salt>$<hash>
final encoded = argon2.hash('correct horse battery staple');
final ok = argon2.verify('correct horse battery staple', encoded);
hash defaults to Argon2Parameters.owasp (argon2id, 19 MiB, 2 iterations)
and a random 16 byte salt. verify accepts PHC strings from any Argon2
implementation, as long as they use version 19. deriveKey returns raw bytes
and takes the optional RFC 9106 secret and associatedData inputs.
Hashing runs on the calling thread and is slow by design. On native platforms, move it off the main isolate:
final encoded = await Isolate.run(() => argon2.hash(password));
The library is built single-threaded, so the p lanes are computed one after
another. Hashes with p > 1 are still correct and compatible with other
implementations, but take p times longer than a multithreaded
implementation would. For more throughput, hash on several isolates.
| OS | Architectures |
|---|---|
| macOS | arm64 (11.0+), x64 (10.15+) |
| iOS | arm64 (13.0+), arm64 and x64 simulators |
| Android | arm64, arm, x64 |
| Linux | x64, arm64, arm, riscv64 |
| Windows | x64, arm64 |
| Web | Any browser with WebAssembly |
The libraries are pure Zig and link no libc. On Linux they run on any glibc or musl distribution.
benchmark/argon2_benchmark.dart compares against the pure Dart
implementations in pointycastle and cryptography, after checking all three
produce identical output. The file header shows how to run it in each mode.
Results on an Intel Mac, argon2id with OWASP parameters, in ms per hash:
| Implementation | Dart JIT | Dart AOT | JavaScript (Node) |
|---|---|---|---|
| serverpod_argon2 | 43 | 46 | 40 |
| cryptography | 200 | 183 | 647 |
| pointycastle | 307 | 274 | 5996 |
A git checkout has no prebuilt libraries, so the build hook compiles from
source. That needs the zig version in build.zig.zon (minimum_zig_version), either installed
directly or through anyzig.
zig build test runs the RFC 9106 vectors against the Zig code.dart test -p vm,chrome runs the Dart tests natively and in the browser.See PUBLISH.md.