bcryptverify

Verifies a string against a bcrypt hash. The cost factor is read from the hash itself. Returns false for a mismatch, and also false when the hash is malformed unless throwOnError is true, in which case an error is thrown instead. This is the Lucee crypto-extension name; the modern RustCFML name is bcryptVerify() and the deprecated form is verifyBCryptHash(). Available when the security cargo feature is enabled.

bcryptverify(input, hash [, throwOnError]) → returns boolean

This function requires RustCFML.  Not supported on Lucee, Adobe ColdFusion, etc.

Argument Reference

input string
Required

The plain string to check.

hash string
Required

The bcrypt hash to verify against.

throwOnError boolean
Default: false

True to throw on a malformed hash instead of returning false (default false).
Values:
  • true
  • false

Examples
Sample code invoking the bcryptverify function

Check that a password matches its stored hash.

hash = bcrypthash("secret");
writeDump(bcryptverify("secret", hash));
writeDump(bcryptverify("wrong", hash));

Expected Result: true false

Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.

Fork me on GitHub