Files
spa-api/laravel/hash.php

62 lines
1.4 KiB
PHP
Raw Normal View History

<?php namespace Laravel;
2011-10-08 22:41:52 -05:00
class Hash {
2011-10-08 22:41:52 -05:00
/**
* Hash a password using the Bcrypt hashing scheme.
*
* <code>
* // Create a Bcrypt hash of a value
* $hash = Hash::make('secret');
2011-10-08 22:41:52 -05:00
*
* // Use a specified number of iterations when creating the hash
* $hash = Hash::make('secret', 12);
2011-10-08 22:41:52 -05:00
* </code>
*
* @param string $value
* @param int $rounds
* @return string
*/
public static function make($value, $rounds = 8)
2011-10-08 22:41:52 -05:00
{
2012-01-16 13:59:24 -06:00
$work = str_pad($rounds, 2, '0', STR_PAD_LEFT);
return crypt($value, '$2a$'.$work.'$'.static::salt());
2011-10-08 22:41:52 -05:00
}
/**
* Determine if an unhashed value matches a given Bcrypt hash.
*
* @param string $value
* @param string $hash
* @return bool
*/
public static function check($value, $hash)
{
return crypt($value, $hash) === $hash;
}
/**
* Get a salt for use during Bcrypt hashing.
*
* @return string
*/
protected static function salt()
{
2012-01-16 13:59:24 -06:00
// Bcrypt expects the salt to be 22 base64 encoded characters including
// dots and slashes. We will get rid of the plus signs included in the
// base64 data and replace them with dots. OpenSSL will be used if it
// is available, otherwise we will use the Str::random method.
2011-10-08 22:41:52 -05:00
if (function_exists('openssl_random_pseudo_bytes'))
{
2011-11-02 21:27:43 -05:00
$bytes = openssl_random_pseudo_bytes(16);
return substr(strtr(base64_encode($bytes), '+', '.'), 0 , 22);
2011-10-08 22:41:52 -05:00
}
2012-01-16 13:59:24 -06:00
$salt = str_replace('+', '.', base64_encode(Str::random(40)));
return substr($salt, 0, 22);
2011-10-08 22:41:52 -05:00
}
}