# mcf

> Modular Crypt Format

Latest version **2.0.4** (published 2016-11-18) · MIT license · 0 weekly downloads

## Install

```sh
npm install mcf
pnpm add mcf
yarn add mcf
bun add mcf
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 2.0.4 |
| Published | 2016-11-18 |
| First published | 2015-01-04 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=4 |
| Dependencies | 1 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 6 |
| Author | Marc-Aurèle DARCHE |
| Maintainers | madarche |
| Keywords | modular, crypt, format, crypto, database, db |

## Links

- npm: https://www.npmjs.com/package/mcf
- Repository: https://github.com/madarche/mcf-js
- Issues: https://github.com/madarche/mcf-js/issues
- npm.io page: https://npm.io/package/mcf

## Dependencies (1)

- [create-error](https://npm.io/package/create-error.md) 0.3.1

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 2.0.4 (latest) — 2016-11-18
- 2.0.3 — 2016-10-16
- 2.0.2 — 2016-03-02
- 2.0.1 — 2016-01-31
- 2.0.0 — 2016-01-16
- 1.0.5 — 2015-06-06
- 1.0.4 — 2015-04-08
- 1.0.3 — 2015-04-04
- 1.0.2 — 2015-04-04
- 1.0.1 — 2015-01-14
- 1.0.0 — 2015-01-04

## README

Modular Crypt Format
====================

[![NPM version](http://img.shields.io/npm/v/mcf.svg)](https://www.npmjs.org/package/mcf)
[![Dependency Status](https://david-dm.org/madarche/mcf-js.svg)](https://david-dm.org/madarche/mcf-js)
[![devDependency Status](https://david-dm.org/madarche/mcf-js/dev-status.svg)](https://david-dm.org/madarche/mcf-js#info=devDependencies)
[![Build Status](https://travis-ci.org/madarche/mcf-js.svg?branch=master)](https://travis-ci.org/madarche/mcf-js)
[![Coverage Status](https://coveralls.io/repos/github/madarche/mcf-js/badge.svg?branch=master)](https://coveralls.io/github/madarche/mcf-js?branch=master)

This modules reads (deserialize) and writes (serialize) password fields in
databases following the Modular Crypt Format (MCF).

The modular crypt format (MCF) is a standard for encoding password hash strings
in order to defend a database against attacks (dictionary attacks, pre-computed
rainbow table attacks, etc.).

The Modular Crypt Format is described in detail in
http://pythonhosted.org/passlib/modular_crypt_format.html


Format
------

A password field in the Modular Crypt Format is of the following form:

    $identifier$cost$salt$derived_key


Install
-------

```bash
npm install mcf
```


API
---

```js
deserialize(mcf_field)
```

```js
serialize(identifier, cost, salt, derived_key)
```


Usage
-----

Reading the format from the database:

```js
const mcf = require('mcf')

let mcf_field = user.get('password')
try {
    let obj = mcf.deserialize(mcf_field)
    let identifier = obj.identifier
    let cost = obj.cost
    let salt = obj.salt
    let derived_key = obj.derived_key
} catch(err) {
    if (err instanceof mcf.McfError) {
        console.log("Format error in the database", err)
    } else {
        console.log("Unexpected fail")
    }
}
```

Creating the format to write in the database:

```js
const mcf = require('mcf')

let mcf_field = mcf.serialize('pbkdf2', cost, salt, derived_key)
```

Development
-----------

To run the tests:
```bash
npm test
```

To compute test coverage:
```bash
npm run test:coverage
```

Contributions
-------------

Pull Requests and contributions in general are welcome as long as they follow
the [Node aesthetic].

[Node aesthetic]: http://substack.net/node_aesthetic

---
_Source: https://npm.io/package/mcf · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
