pub async fn verify(password: &str, digest: &str) -> Result<bool>Expand description
Whether password matches digest (made by hash), compared in constant time.
The password is hashed with the digest’s own salt and iteration count, so
digests made with an older ITERATIONS still verify. A wrong password
is Ok(false), not an error.
Cost: one PBKDF2 run with the stored iteration count (5.5 ms of CPU on Workers at 100,000). To keep timing from revealing which emails have accounts, verify against some digest even when the user is unknown.
§Errors
Error::Internal(500) whendigestis not in thepbkdf2_sha256$<iterations>$<salt>$<hash>format (corrupted data, not a failed login).- On Workers,
Error::Internalwhen WebCrypto fails.
§Examples
let digest = ocre::password::hash("correct horse").await?;
assert!(ocre::password::verify("correct horse", &digest).await?);
assert!(!ocre::password::verify("wrong horse", &digest).await?);
assert!(ocre::password::verify("correct horse", "plaintext").await.is_err());