A lightweight C library for interacting with the Have I Been Pwned Pwned Password API using k-Anonymity.
To build this library, you will need to install the development packages for cURL and OpenSSL.
sudo apt update
sudo apt install build-essential pkg-config libcurl4-openssl-dev libssl-devsudo dnf groupinstall 'Development Tools'
sudo dnf install libcurl-develmake
sudo make installTo try the interactive password checker:
cd examples
make
LD_LIBRARY_PATH=.. ./pwnedpasswordCurrently, the library implements one function:
#include <hibp.h>
long long is_pwned_password(char *password, char *proxy_server_url, char *api_url);The value of proxy_server_url is passed to libcurl as CURLOPT_PROXY.
Set this to NULL if you aren't using a proxy.
The value of api_url can also be NULL, in which case it will use the default base URL https://api.pwnedpasswords.com/range/.
The URL at api_url is expected to behave like the default base URL. Do not forget the trailing slash.
See the documentation for the Pwned Password API.
The function returns the number of occurences where password is breached, or a -1 if there was an error.
Link against the library in your own projects using pkg-config:
gcc main.c $(pkg-config --cflags --libs libhibp) -o my_appSee examples directory for example code and Makefile.
While not a professional developer, the author wrote this as part of a "larger" personal project for an "ecosystem" of Linux system modules to interface with the Pwned Password API. Thanks to examples from the cURL team and all the body of knowledge that Google AI currated from StackOverlow providing the author with a good refresher after 25 years away from C programming.