Skip to main content

hash

Function hash 

Source
pub async fn hash(password: &str) -> Result<String>
Expand description

Hashes password with a new random 16-byte salt into a self-describing digest.

The result looks like pbkdf2_sha256$100000$<salt>$<hash>; store it (e.g. in a password_digest column) and check passwords with verify. Two calls with the same password give different digests (new salt).

Cost: one PBKDF2 run with ITERATIONS, measured at 5.5 ms of CPU on Workers (see the cost model): about half of the free plan’s 10 ms per request.

§Errors

On Workers, Error::Internal (500) when WebCrypto fails (the message names the step, never the password). Native builds never fail.

§Panics

If the platform’s secure random generator is unavailable, which does not happen on supported targets.

§Examples

let digest = ocre::password::hash("correct horse").await?;
assert!(digest.starts_with("pbkdf2_sha256$100000$"));
assert!(ocre::password::verify("correct horse", &digest).await?);