Comparing BCrypt hash between PHP and NodeJS

后端 未结 3 1707
梦毁少年i
梦毁少年i 2020-12-04 15:04

For an app I\'m working on, nodejs needs to verify hashes created by PHP and vice-versa.

The problem is, the hashes generated in PHP (via Laravel\'s Hash

3条回答
  •  误落风尘
    2020-12-04 15:41

    This fails because the types of bcrypt hashes being generated from php and node are different. Laravel generates the $2y$ while node generates the $2a$. But the good news is the only difference between 2a and 2y are their prefixes.

    So what you can do is make one of the prefix similar to the other. Like:

    $phpGeneratedHash  = '$2y$10$jOTwkwLVn6OeA/843CyIHu67ib4RixMa/N/pTJVhOjTddvrG8ge5.';
    $nodeGeneratedHash = '$2a$10$ZiBH5JtTDtXqDajO6f4EbeBIXGwtcGg2MGwr90xTH9ki34SV6rZhO';
    

    To something like:

    $phpGeneratedHash  = '$2y$10$jOTwkwLVn6OeA/843CyIHu67ib4RixMa/N/pTJVhOjTddvrG8ge5.';
    $nodeGeneratedHash = '$2y$10$ZiBH5JtTDtXqDajO6f4EbeBIXGwtcGg2MGwr90xTH9ki34SV6rZhO';
    

    Notice that I replaced the $2a$ of the node hash to $2y$. You can simply do this with:

    PHP

    $finalNodeGeneratedHash = str_replace("$2a$", "$2y$", $nodeGeneratedHash);
    

    Node

    finalNodeGeneratedHash = nodeGeneratedHash.replace('$2a$', '$2y$');
    

    Then compare phpGeneratedHash to finalNodeGeneratedHash.

    Note: It is recommended that if you're comparing in PHP, change the prefix of the NodeJS generated hash to $2y$ and if you're comparing in NodeJS; change the prefix of the PHP generated hash to $2a$.

提交回复
热议问题