package sihl

  1. Overview
  2. Docs
The modular functional web framework

Install

Dune Dependency

Authors

Maintainers

Sources

sihl-queue-0.1.9.tbz
sha256=77f0813d75a88edd14b3396e8b848d94c31c28803299b4b1bd4b78b1de4a2e80
sha512=a8907bc35ea14b7c3a7d638979a2a274860202b2de58b84b5621a4908db001ace493d8aa2e5383f4c8b1847efd256938592f63ef75a41521284b3640d3a7442a

doc/sihl.http/Sihl_http/Cookie/Signer/index.html

Module Cookie.SignerSource

Sign an unsign cookies with secret.

Beware that signing a cookie is not the same as encrypting it! The value of a signed cookie is still visible to anyone, so don't store any sensitive information in it.

When signing a cookie, a hash of its value is generated using the Signer's secret. The generated string is appended to the Cookie's value. So, for instance, if you have a Cookie key=value, the signed cookie will look like key=value.xRt15vh.

When reading the cookie value, the hash will be regenerated again and compared with the sent value. If the values are not the same, the cookie has been tempered with, and we discard it.

Sourcetype t

Constructors

make

Sourceval make : ?salt:string -> string -> t

make ?salt secret returns a new signer that will sign values with secret

Signing functions

sign

Sourceval sign : t -> string -> string

sign signer value signs the string value with signer

unsign

Sourceval unsign : t -> string -> string option

unsign signer value unsigns a signed string value with signer.Httpaf

To avoid time attacks, this function is constant time, it will iterate through all the characters of value, even if it is not the same.

OCaml

Innovation. Community. Security.