use Authen::Passphrase::BlowfishCrypt;
use Bytes::Random::Secure qw/random_bytes/;
use DBI;
-use Digest::SHA qw/hmac_sha1_base64/;
+use Digest::SHA qw/hmac_sha1_base64 sha256/;
use Email::Simple;
use Email::Sender::Simple qw/sendmail/;
use MIME::Base64 qw/decode_base64/;
use Plack::Request;
+use Tie::Hash::Expire;
sub default_opts {(
dbi_connect => ['dbi:Pg:', '', ''],
insert_user => 'INSERT INTO users (id, passphrase, email) VALUES (?,?,?)',
mail_subject => 'Password reset token',
realm => 'restricted area',
+ cache_fail => 0,
+ cache_max_age => 5 * 60,
token_max_age => 60 * 60 * 24,
username_regex => qr/^\w{2,20}$/a,
register_url => '/action/register',
sub check_passphrase {
my ($self, $username, $passphrase) = @_;
+ unless ($self->{cache}) {
+ tie my %cache, 'Tie::Hash::Expire', {expire_seconds => $self->{cache_max_age}};
+ $self->{cache} = \%cache;
+ }
+ my $cachekey = sha256 "$username:$passphrase";
+ return $self->{cache}{$cachekey} if exists $self->{cache}{$cachekey};
my $user = $self->get_user($username);
return 0 unless $user;
- Authen::Passphrase->from_rfc2307($user->{passphrase})->match($passphrase)
+ my $ret = Authen::Passphrase->from_rfc2307($user->{passphrase})->match($passphrase);
+ $self->{cache}{$cachekey} = $ret if $ret || $self->{cache_fail};
+ $ret
}
sub hash_passphrase {
Authentication realm. Defaults to C<'restricted area'>.
+=item cache_fail
+
+If true, all authentication results are cached. If false, only
+successful logins are cached. Defaults to false.
+
+=item cache_max_age
+
+Authentication cache timeout, in seconds. Authentication results are
+cached for this number of seconds to avoid expensive hashing. Defaults
+to 5 minutes.
+
=item token_max_age
Password reset token validity, in seconds. Defaults to 24 hours.
my $create_table = 'CREATE TABLE users (id TEXT PRIMARY KEY, passphrase TEXT, email TEXT)';
my $ac = Plack::Middleware::Auth::Complex->new({
- dbi_connect => ['dbi:SQLite:dbname=:memory:'],
- post_connect_cb => sub { shift->{dbh}->do($create_table) },
+ dbi_connect => ['dbi:SQLite:dbname=:memory:'],
+ post_connect_cb => sub { shift->{dbh}->do($create_table) },
+ register_url => '/register',
+ passwd_url => '/passwd',
+ request_reset_url => '/request-reset',
+ reset_url => '/reset',
+ cache_max_age => 0,
});
my $app = $ac->wrap(\&app);