bcrypthash

Generates a salted bcrypt hash of a string. Each call produces a different hash (a random salt is embedded), and the cost factor is encoded in the result. Returns the $2a$ variant so hashes are interchangeable with the org.mindrot.jbcrypt.BCrypt shim and reference engines. This is the Lucee crypto-extension name; the modern RustCFML name is bcryptHash() and the deprecated form is generateBCryptHash(). Available when the security cargo feature is enabled.

bcrypthash(input [, cost]) → returns string

This function requires RustCFML.  Not supported on Lucee, Adobe ColdFusion, etc.

Argument Reference

input string
Required

The string to hash.

cost numeric
Default: 10

The bcrypt work factor, between 4 and 31 (default 10).

Examples
Sample code invoking the bcrypthash function

Hash with the default cost of 10.

hash = bcrypthash("secret");
writeDump(bcrypthash("secret") == hash); // false - random salt each call

Expected Result: false

Check a password against a stored bcrypt hash.

hash = bcrypthash("secret", 8);
writeDump(bcryptverify("secret", hash));

Expected Result: true

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub