Show HN: SpringZKAuth – Spring application with zero knowledge password proof
github.com
github.com
It also looks like you do normal String equals to compare secrets, which could be vulnerable to a timing attack.
Are you sure you are qualified to implement crypto?