Verifies a plaintext password against a hash created by passwordHashGenerate(). The algorithm, cost parameters and salt are read from the hash itself. It also verifies hashes created by the deprecated generateBCryptHash() and generateSCryptHash().
passwordHashVerify(password, hash [, algorithm])
→ returns boolean
Argon2BCryptSCryptHashes a password, then checks a correct and a wrong password against the hash.
storedHash = passwordHashGenerate("mySecurePassword");
writeOutput(passwordHashVerify("mySecurePassword", storedHash, "Argon2"));
writeOutput(passwordHashVerify("wrongPassword", storedHash, "Argon2"));
Expected Result: YESNO
Hashes created with generateBCryptHash() can be checked with the new function.
oldHash = generateBCryptHash("myPassword");
writeOutput(passwordHashVerify("myPassword", oldHash, "BCrypt"));
Expected Result: YES
Signup for cfbreak to stay updated on the latest news from the ColdFusion / CFML community. One email, every friday.