Class Pbkdf2PasswordEncoder

java.lang.Object
com.codename1.backend.security.crypto.Pbkdf2PasswordEncoder
All Implemented Interfaces:
PasswordEncoder

public final class Pbkdf2PasswordEncoder extends Object implements PasswordEncoder

Reads the PBKDF2 passwords Spring Security's Pbkdf2PasswordEncoder wrote, so a user table brought over from a Spring application signs its users in as it is.

A stored value is the salt followed by the derived key, as hexadecimal -- or base64, where the application had set that. How many rounds, which digest and how long the salt is are not in it: they are whatever the encoder that wrote it was configured with, and this one has to be configured the same.

Stored as Written by Made with
{pbkdf2} defaultsForSpringSecurity_v5_5() SHA-1, 185000 rounds, 8 byte salt
{pbkdf2@SpringSecurity_v5_8} defaultsForSpringSecurity_v5_8() SHA-256, 310000 rounds, 16 byte salt

Both are registered in the encoder PasswordEncoderFactories makes, for verifying. New passwords get {pbkdf2-sha256}, whose stored form says how it was made; a sign-in with an older one re-encodes it.

  • Constructor Details

    • Pbkdf2PasswordEncoder

      public Pbkdf2PasswordEncoder(CharSequence secret, int saltLength, int iterations, String digest)
      Parameters:
      secret - a value mixed into every salt -- Spring's "pepper"; empty for none
      saltLength - the bytes of salt in front of every stored value
      iterations - the rounds
      digest - Crypto.SHA1, Crypto.SHA256 or Crypto.SHA512
  • Method Details

    • defaultsForSpringSecurity_v5_5

      public static Pbkdf2PasswordEncoder defaultsForSpringSecurity_v5_5()
      What Spring Security wrote as {pbkdf2} up to its version 5.7, and still reads under that id: SHA-1, 185000 rounds, an 8 byte salt and a 32 byte key.
    • defaultsForSpringSecurity_v5_8

      public static Pbkdf2PasswordEncoder defaultsForSpringSecurity_v5_8()
      What Spring Security writes as {pbkdf2@SpringSecurity_v5_8}: SHA-256, 310000 rounds, a 16 byte salt and a 32 byte key.
    • setEncodeHashAsBase64

      public void setEncodeHashAsBase64(boolean encodeHashAsBase64)
      Whether stored values are base64 rather than hexadecimal; hexadecimal unless set.
    • encode

      public String encode(CharSequence rawPassword)
      Description copied from interface: PasswordEncoder
      The password as it should be stored: salted and hashed, so encoding one password twice gives two different results.
      Specified by:
      encode in interface PasswordEncoder
    • matches

      public boolean matches(CharSequence rawPassword, String encodedPassword)
      Description copied from interface: PasswordEncoder
      Whether rawPassword is the password encodedPassword was made from.
      Specified by:
      matches in interface PasswordEncoder