Repository navigation
Add SHA-256/SHA-512 TOTP variants (#43) - #96
Merged
Merged
Conversation
RFC 6238 allows HMAC-SHA256/SHA512 alongside the near-universal SHA-1. Adds portable SHA-256/SHA-512 (src/core/sha256.*, sha512.*) and their HMAC variants, generalises otp.c around an otp_alg dispatch (hotp()/totp() plus an otp_render() every front-end now shares for code formatting), parses otpauth://'s algorithm= parameter (rejecting anything unimplemented rather than silently falling back to SHA-1), and activates the vault format's already-reserved algorithm ids 1/2. Covered by RFC 6238 App. B vectors and an OpenSSL differential fuzz pass for every new primitive. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
7 tasks done
This was referenced Jul 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/VAULT_FORMAT.md), so this activates them rather than changing the format.src/core/sha256.*,sha512.*) and their HMAC variants, and generalisesotp.caround anotp_algdispatch (hotp()/totp()plus a sharedotp_render()every front-end now uses for code formatting).otpauth://'salgorithm=parameter is parsed and validated — an algorithm AmiAuth doesn't implement is rejected outright, rather than silently generating (wrong) SHA-1 codes.otp_render().Test plan
make test— 256 host unit tests pass, including RFC 6238 App. B SHA-256/SHA-512 vectorsmake diff— OpenSSL differential fuzz pass for SHA-256, SHA-512, HMAC-SHA256, HMAC-SHA512 (0 mismatches)make m68k-docker/make gui-docker— plain 68000 baseline cross-builds succeedmake gui-smoke— headless Copperline GUI smoke test passesmake smoke— CLI smoke test passesotpauth://URIs, confirmed correct codes and that an unsupportedalgorithm=is rejecteduserdocs/updated in this PR (Managing-Accounts.md, Security-Model.md, Troubleshooting-and-FAQ.md);docs/VAULT_FORMAT.mdupdated for the activated algorithm ids🤖 Generated with Claude Code