DVPasswordHasher class

PBKDF2-HMAC-SHA256 password hashing.

Providers store the string returned by hash and check candidates with verify. Salts are random per password, so identical passwords never produce identical hashes, and verification compares in constant time.

Constructors

DVPasswordHasher({int iterations = defaultIterations, Random? random})

Properties

hashCode → int
The hash code for this object.
no setterinherited
iterations → int
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

hash(String password) → String
Encodes as pbkdf2-sha256$<iterations>$<salt>$<derived key>, with salt and key base64-encoded. Self-describing, so the parameters used for an old hash travel with it.
override
needsRehash(String encoded) → bool
True when encoded was produced with weaker parameters than this hasher currently uses, so a provider can re-hash on the next successful sign-in.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited
verify(String password, String encoded) → bool
True when password produced encoded. A malformed or unknown-algorithm hash returns false rather than throwing, so a corrupt record cannot be used to bypass a check.

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

defaultIterations → const int
Iteration count for new hashes. Existing hashes carry their own count, so raising this does not invalidate them.