SHA-256 and HMAC from scratch
Stage 6 of 7v2 · 2a04c32f

HMAC-SHA256

Combine normalized keys with HMAC inner and outer pads.

HMAC-SHA256

Combine normalized keys with HMAC inner and outer pads. This stage adds one observable capability to the project; keep every operation from earlier stages working.

Model and contract

The harness reads one JSON request from stdin. Bytes are represented as UTF-8 text or hexadecimal, and all binary output uses lowercase hexadecimal.

Representative input:

{
  "op": "hmac-sha256",
  "keyHex": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
  "text": "Hi There"
}

Exact output:

{ "hex": "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7" }

The output ends with a newline. For an invalid request, leave stdout empty, write a diagnostic containing error to stderr, and exit with a non-zero status.

How to approach it

Keep input parsing, core logic, and output serialization separate. First write down the invariants behind “hmac-sha256”, walk through the example by hand, and exercise boundaries before optimizing. Do not replace the mechanism taught by this stage with a library function that solves it completely.

Pay particular attention to empty inputs, index or length boundaries, and malformed data. The result must be deterministic: preserve the ordering required by the request and emit compact JSON.

Acceptance criteria

  • The representative input produces exactly the output shown.
  • Invalid input follows the stderr and exit-status contract.
  • Capabilities from earlier stages keep working.