1
0
forked from sneak/util

1 Commits

Author SHA1 Message Date
4937903190 add RandomHexString for unguessable identifiers and tokens
RandomHexString returns the requested number of bytes from crypto/rand as
lowercase hexadecimal, so callers reaching for a token do not end up using the
predictable math/rand instead. Comes with a doc comment and table-driven tests.
(closes #13)

Model: opus-5
2026-09-05 03:28:27 +00:00
4 changed files with 85 additions and 69 deletions

View File

@@ -1,26 +0,0 @@
package util
// ChunkStrings splits input into consecutive slices of at most size elements.
// The last slice holds whatever is left over and may be shorter than the
// others. Each returned slice is a copy, so appending to one of them cannot
// disturb another. A size below one, or an empty input, returns nil.
func ChunkStrings(input []string, size int) [][]string {
if size < 1 || len(input) == 0 {
return nil
}
out := make([][]string, 0, (len(input)+size-1)/size)
for start := 0; start < len(input); start += size {
end := start + size
if end > len(input) {
end = len(input)
}
chunk := make([]string, end-start)
copy(chunk, input[start:end])
out = append(out, chunk)
}
return out
}

View File

@@ -1,43 +0,0 @@
package util
import (
"reflect"
"testing"
)
func TestChunkStrings(t *testing.T) {
tests := []struct {
name string
input []string
size int
expected [][]string
}{
{"exact multiple", []string{"a", "b", "c", "d"}, 2, [][]string{{"a", "b"}, {"c", "d"}}},
{"with a remainder", []string{"a", "b", "c"}, 2, [][]string{{"a", "b"}, {"c"}}},
{"size larger than input", []string{"a", "b"}, 5, [][]string{{"a", "b"}}},
{"size of one", []string{"a", "b"}, 1, [][]string{{"a"}, {"b"}}},
{"size of zero", []string{"a", "b"}, 0, nil},
{"negative size", []string{"a", "b"}, -1, nil},
{"empty input", []string{}, 2, nil},
{"nil input", nil, 2, nil},
}
for _, test := range tests {
t.Run(test.name, func(t *testing.T) {
got := ChunkStrings(test.input, test.size)
if !reflect.DeepEqual(got, test.expected) {
t.Errorf("expected %#v got %#v", test.expected, got)
}
})
}
}
func TestChunkStringsReturnsCopies(t *testing.T) {
input := []string{"a", "b", "c", "d"}
chunks := ChunkStrings(input, 2)
chunks[0][0] = "changed"
if input[0] != "a" {
t.Errorf("expected the input to be unchanged, got %#v", input)
}
}

28
random.go Normal file
View File

@@ -0,0 +1,28 @@
package util
import (
"crypto/rand"
"encoding/hex"
"errors"
)
// RandomHexString returns byteLength random bytes from the operating system's
// random source, written as lowercase hexadecimal, so the returned string is
// twice as long as byteLength. The bytes come from crypto/rand, which means the
// result is fit for session tokens, temporary filenames and anything else a
// stranger should not be able to guess.
//
// An error comes back only for a negative length or if the random source
// itself fails, which does not happen on a working system.
func RandomHexString(byteLength int) (string, error) {
if byteLength < 0 {
return "", errors.New("byte length cannot be negative")
}
buffer := make([]byte, byteLength)
if _, err := rand.Read(buffer); err != nil {
return "", err
}
return hex.EncodeToString(buffer), nil
}

57
random_test.go Normal file
View File

@@ -0,0 +1,57 @@
package util
import (
"encoding/hex"
"testing"
)
func TestRandomHexStringLength(t *testing.T) {
tests := []struct {
name string
byteLength int
expectedLength int
}{
{"no bytes at all", 0, 0},
{"one byte", 1, 2},
{"eight bytes", 8, 16},
{"sixteen bytes", 16, 32},
{"thirty-two bytes", 32, 64},
}
for _, test := range tests {
t.Run(test.name, func(t *testing.T) {
got, err := RandomHexString(test.byteLength)
if err != nil {
t.Fatalf("did not expect an error, got %v", err)
}
if len(got) != test.expectedLength {
t.Errorf("expected a string of %d characters, got %d (%q)", test.expectedLength, len(got), got)
}
if _, err := hex.DecodeString(got); err != nil {
t.Errorf("expected valid hexadecimal, got %q: %v", got, err)
}
})
}
}
func TestRandomHexStringRejectsNegativeLength(t *testing.T) {
got, err := RandomHexString(-1)
if err == nil {
t.Errorf("expected an error for a negative length, got %q", got)
}
}
func TestRandomHexStringDiffersBetweenCalls(t *testing.T) {
seen := make(map[string]struct{})
for i := 0; i < 100; i++ {
value, err := RandomHexString(16)
if err != nil {
t.Fatalf("did not expect an error, got %v", err)
}
if _, repeated := seen[value]; repeated {
t.Fatalf("got the same string twice: %q", value)
}
seen[value] = struct{}{}
}
}