SQL Server
SQL Server
BCrypt Verify a Password (Check if Password is Correct)
See more Encryption Examples
A system that uses BCrypt for storing passwords would not store the actual password, but would instead store the bcrypt hash of the password. When a user presents the password, such as for login, call BCryptVerify to verify the password against the stored bcrypt hash.Note: This example requires Chilkat v9.5.0.65 or greater.
Chilkat SQL Server Downloads
-- Important: See this note about string length limitations for strings returned by sp_OAMethod calls.
--
CREATE PROCEDURE ChilkatSample
AS
BEGIN
DECLARE @hr int
-- This example assumes the Chilkat API to have been previously unlocked.
-- See Global Unlock Sample for sample code.
DECLARE @crypt int
EXEC @hr = sp_OACreate 'Chilkat.Crypt2', @crypt OUT
IF @hr <> 0
BEGIN
PRINT 'Failed to create ActiveX component'
RETURN
END
DECLARE @storedHash nvarchar(4000)
SELECT @storedHash = '$2a$10$H5kIVktMGzAPKGKNAe9DVu0iwEqfhv/o4MMJ/Dzw/MPy1leOE9NOK'
DECLARE @password nvarchar(4000)
SELECT @password = 'mySecretPassword'
DECLARE @passwordValid int
EXEC sp_OAMethod @crypt, 'BCryptVerify', @passwordValid OUT, @password, @storedHash
IF @passwordValid = 1
BEGIN
PRINT @password + ' is valid.'
END
ELSE
BEGIN
PRINT @password + ' is NOT valid.'
END
SELECT @password = 'notAValidPassword'
EXEC sp_OAMethod @crypt, 'BCryptVerify', @passwordValid OUT, @password, @storedHash
IF @passwordValid = 1
BEGIN
PRINT @password + ' is valid.'
END
ELSE
BEGIN
PRINT @password + ' is NOT valid.'
END
-- Output should be:
-- mySecretPassword is valid.
-- notAValidPassword is NOT valid.
EXEC @hr = sp_OADestroy @crypt
END
GO