mirror of
https://github.com/securego/gosec.git
synced 2024-12-26 12:35:52 +00:00
68 lines
1.5 KiB
Go
68 lines
1.5 KiB
Go
package matching
|
|
|
|
import (
|
|
"github.com/nbutton23/zxcvbn-go/entropy"
|
|
"github.com/nbutton23/zxcvbn-go/match"
|
|
"strings"
|
|
)
|
|
|
|
func sequenceMatch(password string) []match.Match {
|
|
var matches []match.Match
|
|
for i := 0; i < len(password); {
|
|
j := i + 1
|
|
var seq string
|
|
var seqName string
|
|
seqDirection := 0
|
|
for seqCandidateName, seqCandidate := range SEQUENCES {
|
|
iN := strings.Index(seqCandidate, string(password[i]))
|
|
var jN int
|
|
if j < len(password) {
|
|
jN = strings.Index(seqCandidate, string(password[j]))
|
|
} else {
|
|
jN = -1
|
|
}
|
|
|
|
if iN > -1 && jN > -1 {
|
|
direction := jN - iN
|
|
if direction == 1 || direction == -1 {
|
|
seq = seqCandidate
|
|
seqName = seqCandidateName
|
|
seqDirection = direction
|
|
break
|
|
}
|
|
}
|
|
|
|
}
|
|
|
|
if seq != "" {
|
|
for {
|
|
var prevN, curN int
|
|
if j < len(password) {
|
|
prevChar, curChar := password[j-1], password[j]
|
|
prevN, curN = strings.Index(seq, string(prevChar)), strings.Index(seq, string(curChar))
|
|
}
|
|
|
|
if j == len(password) || curN-prevN != seqDirection {
|
|
if j-i > 2 {
|
|
matchSequence := match.Match{
|
|
Pattern: "sequence",
|
|
I: i,
|
|
J: j - 1,
|
|
Token: password[i:j],
|
|
DictionaryName: seqName,
|
|
}
|
|
|
|
matchSequence.Entropy = entropy.SequenceEntropy(matchSequence, len(seq), (seqDirection == 1))
|
|
matches = append(matches, matchSequence)
|
|
}
|
|
break
|
|
} else {
|
|
j += 1
|
|
}
|
|
|
|
}
|
|
}
|
|
i = j
|
|
}
|
|
return matches
|
|
}
|