BCrypt hash function from Password::hash HashBuilder always throws a throws BadParameter exception with a random salt

#156 · closed · 1 comments

View on GitHub ↗

linm-at

**Describe the bug** When using the HashBuilder with BCrypt and a random salt it always throws a BadParametersException with either "Invalid salt version" or "Invalid salt" as the cause, this does not happen with SCrypt ```log com.password4j.BadParametersException: Invalid salt version at [email protected]/com.password4j.BcryptFunction.internalChecks(BcryptFunction.java:450) at [email protected]/com.password4j.BcryptFunction.internalHash(BcryptFunction.java:550) at [email protected]/com.password4j.BcryptFunction.hash(BcryptFunction.java:520) at [email protected]/com.password4j.AbstractHashingFunction.hash(AbstractHashingFunction.java:92) at [email protected]/com.password4j.HashBuilder.with(HashBuilder.java:162) at [email protected]/com.password4j.HashBuilder.withBcrypt(HashBuilder.java:219) at at.htlhl.calendar.calendar/at.htlhl.calendar.PW4J.main(PW4J.java:8) com.password4j.BadParametersException: Invalid salt at [email protected]/com.password4j.BcryptFunction.internalChecks(BcryptFunction.java:446) at [email protected]/com.password4j.BcryptFunction.internalHash(BcryptFunction.java:550) at [email protected]/com.password4j.BcryptFunction.hash(BcryptFunction.java:520) at [email protected]/com.password4j.AbstractHashingFunction.hash(AbstractHashingFunction.java:92) at [email protected]/com.password4j.HashBuilder.with(HashBuilder.java:162) at [email protected]/com.password4j.HashBuilder.withBcrypt(HashBuilder.java:219) at at.htlhl.calendar.calendar/at.htlhl.calendar.PW4J.main(PW4J.java:14) ``` **To Reproduce** ```java import com.password4j.Password; public class PW4J { public static void main(String[] args) { try { Password.hash("password1234").addRandomSalt().withBcrypt().getResult(); } catch(Exception e) { e.printStackTrace(); } try { Password.hash("password1234").addRandomSalt(16).withBcrypt().getResult(); } catch(Exception e) { e.printStackTrace(); } } } ``` **Expected behavior** An exception not to be thrown **Environment:** - OS: Windows 10 22H2 Build 19045 - JDK Azul JDK 17 - Version 1.8.2

Comments

firaja

Hello @Markus-included bcrypt has salts built into the generated hashes to prevent rainbow table attacks. The [documentation](https://github.com/Password4j/password4j/wiki/BCrypt#add-salt) states that is not possible to specify the salt manually. The only way to "control" the salt generation is though the cost factor parameter (aka `logRounds`) So you just invoke ```java Password.hash("password1234").withBcrypt() ``` and the salt will be automatically added.