Skip to content

basalt / auth/src / ScryptPasswordHasher

Class: ScryptPasswordHasher ​

Defined in: auth/src/hashing.ts:54

Default hasher: scrypt from node:crypto — memory-hard, zero dependencies. An argon2id driver can be swapped in via the same contract (native module, left out of the core install).

The default cost is N=2^16 (r=8, p=1) — ~64 MiB per hash. The parameters are embedded in every hash, so raising them here never breaks verification of older, cheaper hashes; those simply verify at their stored cost. A stored hash declaring more than N=2^20, r=32, p=16 (or more than 512 MiB) never verifies, so a tampered row cannot pin the CPU.

Implements ​

Constructors ​

Constructor ​

> new ScryptPasswordHasher(params?): ScryptPasswordHasher

Defined in: auth/src/hashing.ts:55

Parameters ​

params? ​
N ​

number

p ​

number

r ​

number

Returns ​

ScryptPasswordHasher

Methods ​

hash() ​

> hash(plain): Promise<string>

Defined in: auth/src/hashing.ts:65

Parameters ​

plain ​

string

Returns ​

Promise<string>

Implementation of ​

PasswordHasher.hash


verify() ​

> verify(plain, hashed): Promise<boolean>

Defined in: auth/src/hashing.ts:72

Parameters ​

plain ​

string

hashed ​

string

Returns ​

Promise<boolean>

Implementation of ​

PasswordHasher.verify

Released under the MIT License.