package bouncer import "golang.org/x/crypto/bcrypt" // HashPassword returns a bcrypt hash of plain at the given cost. func HashPassword(cost int, plain string) (string, error) { b, err := bcrypt.GenerateFromPassword([]byte(plain), cost) if err != nil { return "", err } return string(b), nil } // CheckPassword reports whether plain matches hash. A malformed hash returns false. func CheckPassword(hash, plain string) bool { return bcrypt.CompareHashAndPassword([]byte(hash), []byte(plain)) == nil } // NeedsRehash reports whether hash was produced below configuredCost. // A hash bcrypt cannot parse needs a rehash. func NeedsRehash(hash string, configuredCost int) bool { cost, err := bcrypt.Cost([]byte(hash)) if err != nil { return true } return cost < configuredCost }