This is a custom GLAuth backend plugin that provides full PostgreSQL support with Argon2id password verification.
It is a drop-in replacement for the official postgres plugin, but overrides the Bind method to use the modern, memory-hard Argon2id algorithm (via github.com/alexedwards/argon2id) instead of the default bcrypt/sha256.
All other features remain 100% identical:
- Automatic schema creation & migration
- User/group search
includegroups,othergroups, capabilities, etc.- Same database schema (uses the
passbcryptcolumn for hashes)
# Build for your current platform
make plugin
# Build for specific platforms
make plugin_linux_amd64
make plugin_linux_arm64
make plugin_darwin_amd64
make plugin_darwin_arm64
# or
PLUGIN_OS=darwin PLUGIN_ARCH=arm64 make plugin
# Build with build variables
BUILD_VARS="-X main.BuildVersion=1.2.3" make plugin
# Build for all platforms at once
make releaseThe resulting plugin will be placed in:
bin/<OS>_<ARCH>/argon2-postgres.so
[backend]
datastore = "plugin"
plugin = "/path/to/bin/<OS>_<ARCH>/argon2-postgres.so"
pluginhandler = "NewPostgresHandler"
database = "host=localhost user=glauth password=secret dbname=glauth sslmode=disable"Note: The
pluginhandlerline is required and must point toNewPostgresHandler.
This plugin expects Argon2id hashes in the passbcrypt column of the users table.
$argon2id$v=19$m=65536,t=3,p=4$abc123...$def456...
You can generate hashes with any library that implements the same parameters (memory=64 MiB, iterations=3, parallelism=4 is the default used by this plugin).
Example one-liner in Go:
hash, _ := argon2id.CreateHash("mysecretpassword", argon2id.DefaultParams)
fmt.Println(hash)The plugin uses exactly the same schema as the official Postgres backend.
- Tables:
users,ldapgroups,includegroups,capabilities - Full schema creation and migration is handled automatically on startup.
For details on seeding the database and the table structure, see the official documentation:
→ https://glauth.github.io/docs/databases.html
- Modern, secure password hashing (Argon2id is the current winner of the Password Hashing Competition)
- Full compatibility with existing GLAuth Postgres setups
- Zero changes to your database schema
- Easy to maintain (single-file plugin after internalizing
basesqlhandler.go)
Just build, drop the .so file in place, update your config, and you’re done.
Made with ❤️ for the GLAuth community
Feel free to open issues or PRs at your fork.