Class BCryptPasswordEncoder

java.lang.Object
com.codename1.backend.security.crypto.BCryptPasswordEncoder
All Implemented Interfaces:
PasswordEncoder

public final class BCryptPasswordEncoder extends Object implements PasswordEncoder

bcrypt, as OpenBSD defined it and Spring's BCryptPasswordEncoder writes it: $2a$, $2b$ or $2y$, a cost, a 16 byte salt and a 23 byte hash.

$2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy

Registered as {bcrypt}, so passwords hashed by a Spring application verify unchanged. It is written in Java -- this runtime has no native Blowfish -- and at cost 10 one check is tens of milliseconds of a host thread, which is why new passwords are encoded with {pbkdf2-sha256} instead. Only the first 72 bytes of a password take part, as in every bcrypt.

  • Field Details

    • DEFAULT_STRENGTH

      public static final int DEFAULT_STRENGTH
      The cost Spring uses unless told otherwise.
      See Also:
  • Constructor Details

    • BCryptPasswordEncoder

      public BCryptPasswordEncoder()
      An encoder of cost DEFAULT_STRENGTH writing $2a$.
    • BCryptPasswordEncoder

      public BCryptPasswordEncoder(int strength)
      Parameters:
      strength - the cost, 4 to 31: the work doubles with every step
    • BCryptPasswordEncoder

      public BCryptPasswordEncoder(char version, int strength)
      Parameters:
      version - the letter after $2: 'a', 'b' or 'y'
      strength - the cost, 4 to 31
  • Method Details

    • encode

      public String encode(CharSequence rawPassword)
      Description copied from interface: PasswordEncoder
      The password as it should be stored: salted and hashed, so encoding one password twice gives two different results.
      Specified by:
      encode in interface PasswordEncoder
    • matches

      public boolean matches(CharSequence rawPassword, String encodedPassword)
      Description copied from interface: PasswordEncoder
      Whether rawPassword is the password encodedPassword was made from.
      Specified by:
      matches in interface PasswordEncoder
    • upgradeEncoding

      public boolean upgradeEncoding(String encodedPassword)
      True when the stored password was made with a lower cost than this encoder's.
      Specified by:
      upgradeEncoding in interface PasswordEncoder