OpaquePolicy
in package
implements
JsonSerializable
Secure Remote Password policy. `suite` and `ksf` are the parameters a *new* registration record is enrolled with. They deliberately do not apply retroactively: an existing record is only valid under the suite and KSF it was created with, so tightening these takes effect as users next set a password rather than invalidating everybody at once.
Table of Contents
Interfaces
- JsonSerializable
Properties
- $opaqueKsf : string
- $opaqueMode : string
- $opaqueSuite : string
Methods
- __construct() : mixed
- Constructs a OpaquePolicy.
- fromArray() : self
- Rebuilds a OpaquePolicy from one decoded JSON object.
- jsonSerialize() : array<string, mixed>
- Renders this object for `json_encode()`.
- toArray() : array<string, mixed>
- Renders this object back to its wire form.
Properties
$opaqueKsf read-only
public
string
$opaqueKsf
$opaqueMode read-only
public
string
$opaqueMode
$opaqueSuite read-only
public
string
$opaqueSuite
Methods
__construct()
Constructs a OpaquePolicy.
public
__construct(string $opaqueKsf, string $opaqueMode, string $opaqueSuite) : mixed
Parameters
- $opaqueKsf : string
-
Key-stretching function new records are enrolled under. Both variants are memory-hard; see [
opaque_ksf_is_at_least] for the tighten-only ordering. - $opaqueMode : string
-
Whether OPAQUE is offered, and whether password login is still accepted.
- $opaqueSuite : string
-
RFC 9807 ciphersuite new records are enrolled under.
fromArray()
Rebuilds a OpaquePolicy from one decoded JSON object.
public
static fromArray(array<string, mixed> $data) : self
Parameters
- $data : array<string, mixed>
-
The raw wire object.
Return values
selfjsonSerialize()
Renders this object for `json_encode()`.
public
jsonSerialize() : array<string, mixed>
Any Sensitive it carries stays WRAPPED here, so a log line or a
json_encode($model) in application code prints [SENSITIVE]. The one place a secret
is revealed is ManagementTransport, on the way to the wire
and nowhere else (§27.5).
Return values
array<string, mixed>toArray()
Renders this object back to its wire form.
public
toArray() : array<string, mixed>
§27.4 rule 5: a null property is OMITTED, not emitted as null. On a sparse update those two say opposite things — "leave this alone" versus "set this to nothing" — and only omission means the first.