如何在 Laravel 中比较两个加密(bcrypt)密码?

laravelphpserver side programming更新于 2025/4/29 20:07:17

在 Laravel 中,您可以使用 Hash Facade 模块来处理密码。它具有 bcrypt 功能,可帮助您安全地存储密码。

Hash Facade bcrypt() 方法是一种强大的密码哈希处理方法。它可以防止恶意用户破解使用 bcrypt() 生成的密码。

哈希处理详细信息可在 config/hashing.php 中找到。默认驱动程序使用 bcrypt() 作为要使用的哈希值。

哈希密码

要使用 Hash Facade,您需要包含类:

Illuminate\Support\Facades\Hash

示例

要哈希密码,您可以使用 make() 方法。以下是哈希密码的示例

<?php namespace App\Http\Controllers; use Illuminate\Http\Request; use App\Models\Student; use Illuminate\Support\Facades\Hash; class StudentController extends Controller { public function index() { echo $hashed = Hash::make('password', [ 'rounds' => 15, ]); } }

输出

上述代码的输出为

$2y$15$QKYQhdKcDSsMmIXZmwyF/.sihzQDhxtgF5WNiy4fdocNm6LiVihZi

验证密码是否与散列密码匹配

要验证纯文本,即 Hash::make 中使用的文本是否与散列文本匹配,可以使用 check() 方法。

如果纯文本与散列密码匹配,则 check() 方法返回 true,如果不匹配,则返回 false。

<?php namespace App\Http\Controllers; use Illuminate\Http\Request; use App\Models\Student; use Illuminate\Support\Facades\Hash; class StudentController extends Controller { public function index() { $hashed = Hash::make('password', [ 'rounds' => 15, ]); if (Hash::check('password', $hashed)) { echo "Password matching"; } else { echo "Password is not matching"; } } }

输出

上述代码的输出为

Password matching

使用 check() 方法

现在让我们通过提供错误的纯文本进行测试,并查看 check() 方法的响应。

<?php namespace App\Http\Controllers; use Illuminate\Http\Request; use App\Models\Student; use Illuminate\Support\Facades\Hash; class StudentController extends Controller { public function index() { $hashed = Hash::make('password', [ 'rounds' => 15, ]); if (Hash::check('password123', $hashed)) { echo "Password matching"; } else { echo "Password is not matching"; } } }

我们在散列中使用的纯文本是"密码"。在 check 方法中,我们使用了"password123",由于文本与散列文本不匹配,因此输出"密码不匹配"。

输出

在浏览器中执行时,输出将是 –

Password is not matching

对密码进行两次散列

现在让我们对相同的文本进行两次散列,并在 check() 方法中进行比较 −

$testhash1 = Hash::make('mypassword'); $testhash2 = Hash::make('mypassword'); if (Hash::check('mypassword', $testhash1) && Hash::check('mypassword', $testhash2)) { echo "Password matching"; } else { echo "Password not matching"; }

您可以在浏览器中测试完整的代码,如下所示 -

<?php namespace App\Http\Controllers; use Illuminate\Http\Request; use App\Models\Student; use Illuminate\Support\Facades\Hash; class StudentController extends Controller { public function index() { $testhash1 = Hash::make('mypassword'); $testhash2 = Hash::make('mypassword'); if (Hash::check('mypassword', $testhash1) && Hash::check('mypassword', $testhash2)) { echo "Password matching"; } else { echo "Password not matching"; } } }

输出

上述代码的输出为 −

Password matching

使用 bcrypt() 方法

您还可以尝试使用 bcrypt() 方法,并使用 Hash::check() 对经过哈希处理的纯文本进行测试。

<?php namespace App\Http\Controllers; use Illuminate\Http\Request; use App\Models\Student; use Illuminate\Support\Facades\Hash; class StudentController extends Controller { public function index() { $hashedtext = bcrypt('mypassword'); if (Hash::check('mypassword', $hashedtext)) { echo 'Password matches'; } else{ echo 'Password not matching'; } } }

输出

上述代码的输出是 –

Password matches

相关文章