key function
Derives a key from the password, salt and cost parameters using Argon2id,
returning length bytes that can be used as a cryptographic key.
RFC 9106 Section 4 recommends time 1, memory 2 GiB (2 * 1024 * 1024 KiB) and threads 4. Its second recommendation, the defaults here, uses time 3, memory 64 MiB (64 * 1024 KiB) and threads 4. Both use a random 16-byte salt and a 32-byte output.
time is the number of passes and memory is the total working memory in
KiB. threads is Argon2's lane count, an algorithm parameter that changes
the derived key; it does not select how many threads run. Store the salt
and all cost parameters so the same key can be derived on other devices.
The derivation blocks the calling isolate until it finishes.
Throws if any of these input limits are violated:
timemust be 1 to 2^32 - 1.threadsmust be 1 to 16777215.memorymust be 8 *threadsto 2^32 - 1 KiB.saltmust be 8 to 2^32 - 1 bytes.passwordmust be at most 2^32 - 1 bytes.lengthmust be 4 to 2^32 - 1 bytes.
Also throws if the working memory cannot be allocated.
Implementation
Uint8List key({
required Uint8List password,
required Uint8List salt,
int time = 3,
int memory = 65536,
int threads = 4,
int length = 32,
}) {
_checkUint32(time, 'time');
_checkUint32(memory, 'memory');
_checkUint32(threads, 'threads');
_checkUint32(length, 'length');
return ffi.argon2Key(
password: password,
salt: salt,
time: time,
memory: memory,
threads: threads,
keyLength: BigInt.from(length),
);
}