DVPasswordHasher class
PBKDF2-HMAC-SHA256 password hashing.
Providers store the string returned by hash and check candidates with verify. Salts are random per password, so identical passwords never produce identical hashes, and verification compares in constant time.
Constructors
- DVPasswordHasher({int iterations = defaultIterations, Random? random})
Properties
- hashCode → int
-
The hash code for this object.
no setterinherited
- iterations → int
-
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
Methods
-
hash(
String password) → String -
Encodes as
pbkdf2-sha256$<iterations>$<salt>$<derived key>, with salt and key base64-encoded. Self-describing, so the parameters used for an old hash travel with it.override -
needsRehash(
String encoded) → bool -
True when
encodedwas produced with weaker parameters than this hasher currently uses, so a provider can re-hash on the next successful sign-in. -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
-
verify(
String password, String encoded) → bool -
True when
passwordproducedencoded. A malformed or unknown-algorithm hash returns false rather than throwing, so a corrupt record cannot be used to bypass a check.
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Constants
- defaultIterations → const int
- Iteration count for new hashes. Existing hashes carry their own count, so raising this does not invalidate them.