basalt / auth/src / ScryptPasswordHasher
Class: ScryptPasswordHasher
Defined in: auth/src/hashing.ts:54
Default hasher: scrypt from node:crypto — memory-hard, zero dependencies. An argon2id driver can be swapped in via the same contract (native module, left out of the core install).
The default cost is N=2^16 (r=8, p=1) — ~64 MiB per hash. The parameters are embedded in every hash, so raising them here never breaks verification of older, cheaper hashes; those simply verify at their stored cost. A stored hash declaring more than N=2^20, r=32, p=16 (or more than 512 MiB) never verifies, so a tampered row cannot pin the CPU.
Implements
Constructors
Constructor
> new ScryptPasswordHasher(params?): ScryptPasswordHasher
Defined in: auth/src/hashing.ts:55
Parameters
params?
N
number
p
number
r
number
Returns
ScryptPasswordHasher
Methods
hash()
> hash(plain): Promise<string>
Defined in: auth/src/hashing.ts:65
Parameters
plain
string
Returns
Promise<string>
Implementation of
verify()
> verify(plain, hashed): Promise<boolean>
Defined in: auth/src/hashing.ts:72
Parameters
plain
string
hashed
string
Returns
Promise<boolean>