// Copyright 2026 Leo Cheng
// SPDX-License-Identifier: Apache-2.0
///|
/// The 64 per-round additive constants `K[i] = floor(abs(sin(i+1)) * 2^32)`
/// (RFC 1321). Hand-tabulated so MD5 stays a self-contained pure-MoonBit
/// primitive with no dependency on a `sin` at build time.
let md5_k : FixedArray[UInt] = [
0xd76aa478, 0xe8c7b756, 0x242070db, 0xc1bdceee, 0xf57c0faf, 0x4787c62a, 0xa8304613,
0xfd469501, 0x698098d8, 0x8b44f7af, 0xffff5bb1, 0x895cd7be, 0x6b901122, 0xfd987193,
0xa679438e, 0x49b40821, 0xf61e2562, 0xc040b340, 0x265e5a51, 0xe9b6c7aa, 0xd62f105d,
0x02441453, 0xd8a1e681, 0xe7d3fbc8, 0x21e1cde6, 0xc33707d6, 0xf4d50d87, 0x455a14ed,
0xa9e3e905, 0xfcefa3f8, 0x676f02d9, 0x8d2a4c8a, 0xfffa3942, 0x8771f681, 0x6d9d6122,
0xfde5380c, 0xa4beea44, 0x4bdecfa9, 0xf6bb4b60, 0xbebfbc70, 0x289b7ec6, 0xeaa127fa,
0xd4ef3085, 0x04881d05, 0xd9d4d039, 0xe6db99e5, 0x1fa27cf8, 0xc4ac5665, 0xf4292244,
0x432aff97, 0xab9423a7, 0xfc93a039, 0x655b59c3, 0x8f0ccc92, 0xffeff47d, 0x85845dd1,
0x6fa87e4f, 0xfe2ce6e0, 0xa3014314, 0x4e0811a1, 0xf7537e82, 0xbd3af235, 0x2ad7d2bb,
0xeb86d391,
]
///|
/// Per-round left-rotation amounts (RFC 1321): four values cycled within each
/// of the four 16-operation rounds.
let md5_s : FixedArray[Int] = [
7, 12, 17, 22, 7, 12, 17, 22, 7, 12, 17, 22, 7, 12, 17, 22, 5, 9, 14, 20, 5, 9,
14, 20, 5, 9, 14, 20, 5, 9, 14, 20, 4, 11, 16, 23, 4, 11, 16, 23, 4, 11, 16, 23,
4, 11, 16, 23, 6, 10, 15, 21, 6, 10, 15, 21, 6, 10, 15, 21, 6, 10, 15, 21,
]
///|
fn rotl32(x : UInt, s : Int) -> UInt {
(x << s) | (x >> (32 - s))
}
///|
/// The MD5 digest of `msg` as 16 raw bytes (RFC 1321). Used only for
/// PostgreSQL's `AuthenticationMD5Password` handshake; not a general-purpose
/// hashing API. Runs the standard little-endian padding + four-round
/// compression over 64-byte blocks.
pub fn md5(msg : Bytes) -> Bytes {
let msg_len = msg.length()
// Padded length: message + 0x80 + zeros until ≡ 56 (mod 64) + 8-byte length.
let total = ((msg_len + 8) / 64 + 1) * 64
let buf = FixedArray::make(total, (0 : Byte))
for i in 0..> (i * 8)).to_byte()
}
let mut a0 : UInt = 0x67452301
let mut b0 : UInt = 0xefcdab89
let mut c0 : UInt = 0x98badcfe
let mut d0 : UInt = 0x10325476
let m = FixedArray::make(16, (0 : UInt))
let mut off = 0
while off < total {
for j in 0..<16 {
let p = off + j * 4
m[j] = buf[p].to_uint() |
(buf[p + 1].to_uint() << 8) |
(buf[p + 2].to_uint() << 16) |
(buf[p + 3].to_uint() << 24)
}
let mut a = a0
let mut b = b0
let mut c = c0
let mut d = d0
for i in 0..<64 {
let mut f : UInt = 0
let mut g = 0
if i < 16 {
f = (b & c) | (b.lnot() & d)
g = i
} else if i < 32 {
f = (d & b) | (d.lnot() & c)
g = (5 * i + 1) % 16
} else if i < 48 {
f = b ^ c ^ d
g = (3 * i + 5) % 16
} else {
f = c ^ (b | d.lnot())
g = 7 * i % 16
}
f = f + a + md5_k[i] + m[g]
a = d
d = c
c = b
b = b + rotl32(f, md5_s[i])
}
a0 = a0 + a
b0 = b0 + b
c0 = c0 + c
d0 = d0 + d
off = off + 64
}
let ob = Buffer()
let words : FixedArray[UInt] = [a0, b0, c0, d0]
for w in 0..<4 {
for i in 0..<4 {
ob.write_byte((words[w] >> (i * 8)).to_byte())
}
}
ob.to_bytes()
}
///|
/// Lowercase hex of `data`, e.g. the 16-byte MD5 digest rendered as its 32-char
/// hex string — the form PostgreSQL's MD5 auth concatenates and re-hashes.
pub fn hex_lower(data : Bytes) -> String {
let digits = "0123456789abcdef"
let buf = StringBuilder::new()
for i in 0..> 4].unsafe_to_char())
buf.write_char(digits[b & 0xf].unsafe_to_char())
}
buf.to_string()
}
///|
/// The `AuthenticationMD5Password` response token: `"md5" ++
/// hex(md5(hex(md5(password ++ user)) ++ salt))`, exactly per the PostgreSQL
/// frontend/backend protocol. `salt` is the four bytes the server sent.
pub fn pg_md5_password(
user : String,
password : String,
salt : Bytes,
) -> String {
let inner = md5(concat_bytes(@utf8.encode(password), @utf8.encode(user)))
let inner_hex = hex_lower(inner)
let outer = md5(concat_bytes(@utf8.encode(inner_hex), salt))
"md5" + hex_lower(outer)
}