{"_id":"upash","_rev":"3-caf34e736f1adb0825f4977b5f82b7bb","name":"upash","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"upash","version":"1.0.0","description":"Painless Unified API for any password hashing algorithm","license":"MIT","homepage":"https://github.com/simonepri/upash#readme","repository":{"type":"git","url":"git+https://github.com/simonepri/upash.git"},"bugs":{"url":"https://github.com/simonepri/upash/issues","email":"simonepri@outlook.com"},"author":{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"},"contributors":[{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"}],"keywords":["account","accounts","algorithm","algorithms","API","APIs","application","argon2","attack","attacks","auth","authentication","authorization","bcrypt","brute","cli","command","credential","credentials","cryptographically","derivation","easy","force","form","function","hash","hashing","interface","irreversible","kdf","key","line","login","one","one-way","password","passwords","PBKDF","PBKDF1","PBKDF2","pbkdf2-crypt","plus","programming","protected","rainbow","resistance","salt","scrypt","secure","security","sign in","simple","store","stretching","strong","table","time","timining","transform","unified","universal","upash","user","users","verification","verify","way"],"main":"index.js","files":["index.js"],"engines":{"node":">=4"},"scripts":{"test":"xo &&nyc ava","release":"np","update":"npm-check -u"},"dependencies":{},"devDependencies":{"ava":"*","np":"*","npm-check":"*","nyc":"*","xo":"*"},"ava":{"verbose":true},"nyc":{"reporter":["lcovonly","text"]},"xo":{"prettier":true,"space":true,"rules":{"prefer-destructuring":"off"}},"gitHead":"0f217796c66766af82ff0d302a85a384cbc71837","_id":"upash@1.0.0","_npmVersion":"5.6.0","_nodeVersion":"10.2.1","_npmUser":{"name":"simonepri","email":"simonepri@outlook.com"},"dist":{"integrity":"sha512-8WR3dBbyAlJQNbspV48MZKKcvDdcGVeO5bPtvYXmcoYLciqAosD5TW2KeMHF5tNHo+tVSz0cy8svFUeSpRUb8w==","shasum":"160503254d02387cdea209ba2c6e1b7afc28455a","tarball":"https://registry.npmjs.org/upash/-/upash-1.0.0.tgz","fileCount":4,"unpackedSize":25509,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbX3wwCRA9TVsSAnZWagAAkw0P/AhBB82zyLDv0RkVaZBx\nrnKhT1YihHbBZXxZmS5AcsPnIt+ZqU/+oHijCOyezEIwS3AP447Im+S5UHQt\nw3ATLd8GmfBFF8kvFxYQHAll+0p40muZaMIuOqc/oC63JvXWmtMGmP3lg442\nzftnvgaWlO3ffHfpJ1ozT+Sh8QftPSR8qwLJPvKdS0ApDyqLcGlgWiKPTlHZ\n+UIG+xZ5DbQHkGUJzO78i39TrlGDoGAYOz4cA2ehgPL7tREWZBMEotZM2hoh\n7RdM5h7h5mE9PVPrsPai6chEcanMvl8DHc2Rokx2+2ZPSh2OyQp+pp3yVPpk\nCZurLfZfXoZM+DQdit5tXHbEWpUZUn/va5su7ivsxz6GI9jbNPtoy9JLCufe\nqlETuNcU5zOd7oE9yZctxBmkF/yKq9OY+DfpoOVATQ3HHfUFmaFP+r2Ddt4o\nIbCW8+/vsI+dOniPByTxQE32ZsPafo2wYoG0r68l5VB1iqboORBKfkVazwhh\nbRSRC36LiNFk7ExG+LqEAQBEZEVFkOYtuTUbyG4iD4iBcmngU+zdocGrrIF/\n9F5aj4Qlg1FpATXrEpANBMkG1wPZ1sM972jGZDWpmTaYmdpiI53sbRaJIL2V\nDdg+Gx+xGGNm8/f9uOCESXrkf9NHFIeH976rFe/2OpGwrWrvDdAiS7qU4zKk\n+NbR\r\n=1Qbf\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBNP6Q24IaHLAgtohRPeGQnsQthNvhHB+bEb33/rgFKIAiBK9YBy75JccQC/uZn4ZXuvSxs/f3+EUZ4jhjU664Xhsg=="}]},"maintainers":[{"name":"simonepri","email":"simonepri@outlook.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/upash_1.0.0_1532984367921_0.49775607073570316"},"_hasShrinkwrap":false},"1.0.1":{"name":"upash","version":"1.0.1","description":"Unified API for password hashing algorithms","license":"MIT","homepage":"https://github.com/simonepri/upash#readme","repository":{"type":"git","url":"git+https://github.com/simonepri/upash.git"},"bugs":{"url":"https://github.com/simonepri/upash/issues","email":"simonepri@outlook.com"},"author":{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"},"contributors":[{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"}],"keywords":["account","accounts","algorithm","algorithms","API","APIs","application","argon2","attack","attacks","auth","authentication","authorization","bcrypt","brute","cli","command","credential","credentials","cryptographically","derivation","easy","force","form","function","hash","hashing","interface","irreversible","kdf","key","line","login","one","one-way","password","passwords","PBKDF","PBKDF1","PBKDF2","pbkdf2-crypt","plus","programming","protected","rainbow","resistance","salt","scrypt","secure","security","sign in","simple","store","stretching","strong","table","time","timining","transform","unified","universal","upash","user","users","verification","verify","way"],"main":"index.js","files":["index.js"],"engines":{"node":">=4"},"scripts":{"test":"xo &&nyc ava","release":"np","update":"npm-check -u"},"dependencies":{},"devDependencies":{"ava":"*","np":"*","npm-check":"*","nyc":"*","xo":"*"},"ava":{"verbose":true},"nyc":{"reporter":["lcovonly","text"]},"xo":{"prettier":true,"space":true,"rules":{"prefer-destructuring":"off"}},"gitHead":"04a0754f3e2e4b5f1deceb45cef79e131a925f13","_id":"upash@1.0.1","_npmVersion":"5.6.0","_nodeVersion":"10.2.1","_npmUser":{"name":"simonepri","email":"simonepri@outlook.com"},"dist":{"integrity":"sha512-9ATrP9SUjcyUEuktiFo88n83MovAR8fsdXPdxnUHCGL41pDGAME+gw54pQua7gYkOQg3VxWOo3PYzGuuDxe2DQ==","shasum":"35c8e376cca7977e09f14a7742efbfee40f0def8","tarball":"https://registry.npmjs.org/upash/-/upash-1.0.1.tgz","fileCount":4,"unpackedSize":25509,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbX379CRA9TVsSAnZWagAAWNQP/R8McDO77Az4rT75FoAy\n6HJLhvj5dFY56ssbUG+GTh+dfz9q50hLHzMgEf07DxFAMsxCZnYxiLJ/sp7v\nB0tIGqzbocikdA3mv9SM976zsI7bZLUfJDCLmNIZwg2tfZHW7HX/Mxhycma1\nlqB5aVHJoS/2As1fLD24M8UMkW8n5O/s4bCwbFTml570GFypHuau+gJGEmYW\n8sjLb8b8Q/53F2lrH3kVlr7JkBRnqsu5xglRjflfO2JdPXlnSa8s10OChDy/\n4CaoNr1d8qJ06kxVx+2aI1kHU/F3lR5Z7IOUBI/9Ah9vhlK14xMzLcN1tHbe\na0Xvsg1r0kW11flpFv6AHcONYHjW0dsAIwo3lXYC+VHxOL/0lIXjgHlXNMBJ\nP4TpbbhIaKUGat12HDiSfJ8eMLu9RY5QpwPW7YrFaeUFcLI4dDeAatQ1DzPy\n4j/ZOuUiZ9s8JE1zB73rAzsus9HVkaedN6gamobEzd8Q4HxWUu+889E/A8Dg\nEEMtm4gZaNGPDd6Bmfy4ktx5DBAiedIbbXuhemIexbHkqhPVI6W2z36f1bEG\noebyZo/V0dwjlXiUMjvPvsyD1akd1nYQRfIF5CIWHNFR39lShQPiXuGC2xkC\nKzlnsYWS7jgQd858zj0gCRdfGo/6X7SfdNdXjiCmuWwgzsLtYOQp1R9Dv6NI\nXPAY\r\n=h+gA\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGSXqqdFkwYoJRK+CnVa9SEAERTMoh2wz56tug/JdZOeAiEA/7Q2xAKCym+26fc9x/qYLrVnalZRt8D9mJvspnj4zTQ="}]},"maintainers":[{"name":"simonepri","email":"simonepri@outlook.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/upash_1.0.1_1532985085125_0.7888848056712985"},"_hasShrinkwrap":false},"1.0.2":{"name":"upash","version":"1.0.2","description":"Unified API for password hashing algorithms","license":"MIT","homepage":"https://github.com/simonepri/upash#readme","repository":{"type":"git","url":"git+https://github.com/simonepri/upash.git"},"bugs":{"url":"https://github.com/simonepri/upash/issues","email":"simonepri@outlook.com"},"author":{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"},"contributors":[{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"}],"keywords":["account","accounts","algorithm","algorithms","API","APIs","application","argon2","attack","attacks","auth","authentication","authorization","bcrypt","brute","cli","command","credential","credentials","cryptographically","derivation","easy","force","form","function","hash","hashing","interface","irreversible","kdf","key","line","login","one","one-way","password","passwords","PBKDF","PBKDF1","PBKDF2","pbkdf2-crypt","plus","programming","protected","rainbow","resistance","salt","scrypt","secure","security","sign in","simple","store","stretching","strong","table","time","timining","transform","unified","universal","upash","user","users","verification","verify","way"],"main":"index.js","files":["index.js"],"engines":{"node":">=4"},"scripts":{"test":"xo &&nyc ava","release":"np","update":"npm-check -u"},"dependencies":{},"devDependencies":{"ava":"*","np":"*","npm-check":"*","nyc":"*","xo":"*"},"ava":{"verbose":true},"nyc":{"reporter":["lcovonly","text"]},"xo":{"prettier":true,"space":true,"rules":{"prefer-destructuring":"off"}},"gitHead":"d2d9cd61294d4f24ee7d676a41dc4a9aca672401","_id":"upash@1.0.2","_npmVersion":"6.2.0","_nodeVersion":"8.11.1","_npmUser":{"name":"simonepri","email":"simonepri@outlook.com"},"dist":{"integrity":"sha512-fs6y+iUp4vMyRzD7VvHe0x7E9ElK2TrIj/nZICJ92NrF09pb+55mYjIEJckPO5WR41ICBiSPZbg9lPcJeundZA==","shasum":"bea34c94f1d4ffbd8258a2affa7a8873362c66ec","tarball":"https://registry.npmjs.org/upash/-/upash-1.0.2.tgz","fileCount":4,"unpackedSize":25650,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.4\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJbY3KqCRA9TVsSAnZWagAApA8P/iIA9FA/6WSlaolBPsA/\n3HOcu6il/3znF+NAvazzXzK3Lj6Btp0rDHx3aRJESoSRRTJu8dr9F+/4Q1K7\nyrGyk2IaDPkqQQ3LxGDl1QIOxv3HscKS6L7TtmlUInXtTNyv6oz00UerIgyo\nsB5fI60me6jKEA18X42BaO6doHDI47tg0LCCyQW2bIwRmuNoEEneLDx/epS+\n+eJMAhOOA638ui1qNvnfOEj+tFOVczJSKy1osp5OePHYkPvwv4cHj6CjDyAd\nfmqNZN3c03ZMQ2U0eZRl37Q3w1oAnirRJ06WW496ho0Oemeh2olFZQOhXDYB\nucKr9aydSOiQ+nrrvvuPmxLjANnt+Awwd7Pfyw60DTYW/fTDYq7TrYtI36oq\nGonxmvUibiDSAarkjjvcBJMvl3+O2RqzEZxbnfTyCDryXGAran/6Gdn2/1TM\nh47gYPn7fs4606pIgQRfNUa1h0gL9nXjTQhNGQjorP9e0VRnCiFA3/JvLBZh\nUhDI/VEttmbGtkbinfyOO/xMeaj75B4pIik6ARw8oJburdKnTXMH9MWcHLDY\npPeETYaVJg5gp7RG+g38yy3dM2n2TUg89Tr0zvl4O1NGsYs7Ryk4u+QBJ7Xd\nChBCEJDww4Jvdqr/k8Iwz3Kgz59WprLiQw5/7bNi7Fdd7yceNO7XuAIIgp1S\nt8wo\r\n=yVbk\r\n-----END PGP SIGNATURE-----\r\n","signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC18FcxuIP36dnawk9cjI/evQHI7b5hNFLDIkTgcK+sAQIhANyJF6NcXSeKEFGIySE1WUFtgNhJg3u81nXrjsoBMfUy"}]},"maintainers":[{"name":"simonepri","email":"simonepri@outlook.com"}],"directories":{},"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/upash_1.0.2_1533244073737_0.32299763159097616"},"_hasShrinkwrap":false}},"time":{"created":"2018-07-30T20:59:27.921Z","1.0.0":"2018-07-30T20:59:28.028Z","modified":"2022-05-22T20:20:17.030Z","1.0.1":"2018-07-30T21:11:25.737Z","1.0.2":"2018-08-02T21:07:53.834Z"},"maintainers":[{"name":"simonepri","email":"simonepri@outlook.com"}],"description":"Unified API for password hashing algorithms","homepage":"https://github.com/simonepri/upash#readme","keywords":["account","accounts","algorithm","algorithms","API","APIs","application","argon2","attack","attacks","auth","authentication","authorization","bcrypt","brute","cli","command","credential","credentials","cryptographically","derivation","easy","force","form","function","hash","hashing","interface","irreversible","kdf","key","line","login","one","one-way","password","passwords","PBKDF","PBKDF1","PBKDF2","pbkdf2-crypt","plus","programming","protected","rainbow","resistance","salt","scrypt","secure","security","sign in","simple","store","stretching","strong","table","time","timining","transform","unified","universal","upash","user","users","verification","verify","way"],"repository":{"type":"git","url":"git+https://github.com/simonepri/upash.git"},"contributors":[{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"}],"author":{"name":"Simone Primarosa","email":"simonepri@outlook.com","url":"https://simoneprimarosa.com"},"bugs":{"url":"https://github.com/simonepri/upash/issues","email":"simonepri@outlook.com"},"license":"MIT","readme":"<p align=\"center\">\n  <a href=\"https://github.com/simonepri/upash\">\n    <img src=\"https://github.com/simonepri/upash/raw/master/media/upash.png\" alt=\"upash\" width=\"300\"/>\n  </a>\n</p>\n<p align=\"center\">\n  <!-- CI - TravisCI -->\n  <a href=\"https://travis-ci.com/simonepri/upash\">\n    <img src=\"https://img.shields.io/travis/com/simonepri/upash/master.svg?label=MacOS%20%26%20Linux\" alt=\"Mac/Linux Build Status\" />\n  </a>\n  <!-- CI - AppVeyor -->\n  <a href=\"https://ci.appveyor.com/project/simonepri/upash\">\n    <img src=\"https://img.shields.io/appveyor/ci/simonepri/upash/master.svg?label=Windows\" alt=\"Windows Build status\" />\n  </a>\n  <!-- Coverage - Codecov -->\n  <a href=\"https://codecov.io/gh/simonepri/upash\">\n    <img src=\"https://img.shields.io/codecov/c/github/simonepri/upash/master.svg\" alt=\"Codecov Coverage report\" />\n  </a>\n  <!-- DM - Snyk -->\n  <a href=\"https://snyk.io/test/github/simonepri/upash?targetFile=package.json\">\n    <img src=\"https://snyk.io/test/github/simonepri/upash/badge.svg?targetFile=package.json\" alt=\"Known Vulnerabilities\" />\n  </a>\n  <!-- DM - David -->\n  <a href=\"https://david-dm.org/simonepri/upash\">\n    <img src=\"https://david-dm.org/simonepri/upash/status.svg\" alt=\"Dependency Status\" />\n  </a>\n\n  <br/>\n\n  <!-- Code Style - XO-Prettier -->\n  <a href=\"https://github.com/xojs/xo\">\n    <img src=\"https://img.shields.io/badge/code_style-XO+Prettier-5ed9c7.svg\" alt=\"XO Code Style used\" />\n  </a>\n  <!-- Test Runner - AVA -->\n  <a href=\"https://github.com/avajs/ava\">\n    <img src=\"https://img.shields.io/badge/test_runner-AVA-fb3170.svg\" alt=\"AVA Test Runner used\" />\n  </a>\n  <!-- Test Coverage - Istanbul -->\n  <a href=\"https://github.com/istanbuljs/nyc\">\n    <img src=\"https://img.shields.io/badge/test_coverage-NYC-fec606.svg\" alt=\"Istanbul Test Coverage used\" />\n  </a>\n  <!-- Init - ni -->\n  <a href=\"https://github.com/simonepri/ni\">\n    <img src=\"https://img.shields.io/badge/initialized_with-ni-e74c3c.svg\" alt=\"NI Scaffolding System used\" />\n  </a>\n  <!-- Release - np -->\n  <a href=\"https://github.com/sindresorhus/np\">\n    <img src=\"https://img.shields.io/badge/released_with-np-6c8784.svg\" alt=\"NP Release System used\" />\n  </a>\n\n  <br/>\n\n  <!-- Mentioned - Awesome NodeJS -->\n  <a href=\"https://github.com/sindresorhus/awesome-nodejs#security\">\n    <img src=\"https://awesome.re/mentioned-badge.svg\" alt=\"Mentioned in Awesome NodeJS\" />\n  </a>\n  <!-- Version - npm -->\n  <a href=\"https://www.npmjs.com/package/upash\">\n    <img src=\"https://img.shields.io/npm/v/upash.svg\" alt=\"Latest version on npm\" />\n  </a>\n  <!-- License - MIT -->\n  <a href=\"https://github.com/simonepri/upash/tree/master/license\">\n    <img src=\"https://img.shields.io/github/license/simonepri/upash.svg\" alt=\"Project license\" />\n  </a>\n</p>\n<p align=\"center\">\n  🔒 <b>U</b>nified API for <b>PAS</b>sword <b>H</b>ashing algorithms\n\n  <br/>\n\n  <sub>\n    Coded with ❤️ by <a href=\"#authors\">Simone Primarosa</a>.\n  </sub>\n</p>\n\n## Synopsis\nPassword breaches have become more and more frequent.  \nSee: [Yahoo][breach:yahoo] ([twice][breach:yahoo2]), [LinkedIn][breach:linkedin], [Adobe][breach:adobe],\n[Ashley Madison][breach:ashley-madison], and [a whole lot more][breach:hibp-breaches].\n\nIndeed, the above examples doubles as a list of \"how NOT to do password\nstorage\": simple hashing, unsalted values, misuse of encryption, and failed\npassword migration. (For more information on why these are bad, see our [introduction to password hashing theory][docs:password-hashing-theory])\n\nThere are two possible interpretations here: first, companies do not put adequate resources in securing passwords; and secondly, getting password hashing right is hard. Furthermore, even if you have followed previous best practice, keeping it right is another technical challenge: algorithm choices, security levels, parameter selection change regularly.\n\n## Make passwords painless\n<img src=\"https://github.com/simonepri/upash/raw/master/media/api.png\" alt=\"upash api\" width=\"400\" align=\"right\"/>\n\nThe upash ([pronounced u-pash][upash:pronounce]) project aims is to allow you to\nhave a clean and easy-to-use API to use any password hashing algorithm\nseamlessly in your application.\n***\n\n#### Highlights\n- Simple API for all password hashing algorithms\n- Easy to maintain and [upgradable](#upgrading-your-password-hashing-algorithm) logic\n- Easy to test configurations through the [CLI](#test-configurations-through-the-cli)\n- Step by step [migration guide](#migrating-your-existing-password-hashing-solution)\n- Comprehensive list of supported [hashing algorithms](#recommended-algorithms-implementations)\n\nDo you believe that this is useful? Has it saved you time? Or maybe you simply like it?  \nIf so, [support my work with a Star ⭐️][start].\n\n## Usage\nThe upash solution is straight-forward but it is important to follow all the\nsteps carefully.\n\nFirstly, you need to install this package.\n\n```bash\nnpm install --save upash\n```\nThen, you need to choose from the\n[list of supported password hashing algorithms](#recommended-algorithms-implementations)\nthe one that best suits your needs and install that too.  \nIn the following, we will assume that you choose `@phc/argon2`, that is also a\nsuitable solution in case you don't know which one fits better for you.\n\n```bash\nnpm install --save @phc/argon2\n```\n\nFinally, you can enjoy the easy APIs.\n\n```js\nconst upash = require('upash');\n\n// Install the algorithm of your choice.\nupash.install('argon2', require('@phc/argon2'));\n\n// Hash API\nconst hashstr = await upash.hash('password');\n// => \"$argon2id$v=19$m=4096,t=3,p=1$PcEZHj1maR/+ZQynyJHWZg$2jEN4xcww7CYp1jakZB1rxbYsZ55XH2HgjYRtdZtubI\"\n\n// Verify API\nconst match = await upash.verify(hashstr, 'password');\n// => true\n```\n\nYou can store the hash returned by the `hash` function directly into your database.\n\nYou can also install more than one algorithm at once.  \nThis is really handy when you want to update your current password hashing\nalgorithm.\n\n```js\nconst upash = require('upash');\n\n// Install the algorithms of your choice.\nupash.install('pbkdf2', require('@phc/pbkdf2'));\nupash.install('argon2', require('@phc/argon2'));\n\n// You can explicitly tell upash which algorithm to use.\nconst hashstr_pbkdf2 = await upash.use('pbkdf2').hash('password');\n// => \"$pbkdf2-sha512$i=10000$O484sW7giRw+nt5WVnp15w$jEUMVZ9adB+63ko/8Dr9oB1jWdndpVVQ65xRlT+tA1GTKcJ7BWlTjdaiILzZAhIPEtgTImKvbgnu8TS/ZrjKgA\"\n\n// If you don't do so it will automatically use the last one installed.\nconst hashstr_argon2 = await upash.hash('password');\n// => \"$argon2i$v=19$m=4096,t=3,p=1$mTFYKhlcxmjS/v6Y8aEd5g$IKGY+vj0MdezVEKHQ9bvjpROoR5HPun5/AUCjQrHSIs\"\n\n// When you verify upash will automatically choose the algorithm to use based\n// on the identifier contained in the hash string.\nconst match_pbkdf2 = await upash.verify(hashstr_pbkdf2, 'password');\n// => true\n\n// This will allow you to easily migrate from an algorithm to another.\nconst match_argon2 = await upash.verify(hashstr_argon2, 'password');\n// => true\n```\n\n## Recommended algorithms implementations\nThe following is a curated list of algorithms that adhere to the upash APIs\nguidelines and are ready to work at a production level straight out of the box.  \nAll the functions come pre-configured but fine-tuning is always a good practice.  \nThe defaults are maintained by the community and the aim of this project is also\nto bring together experts to be able to provide you reasonably secure default\nconfigurations.\n\n#### Packages that adhere to the PHC string format\n- [@phc/argon2][alg:@phc/argon2]\n- [@phc/pbkdf2][alg:@phc/pbkdf2]\n- [@phc/scrypt][alg:@phc/scrypt]\n- [@phc/bcrypt][alg:@phc/bcrypt]\n\n#### Other packages\n- N/A\n\nWant your package listed here? [Open an issue][new issue] and we will review it.\n\n## Test configurations through the CLI\n<img src=\"https://github.com/simonepri/upash/raw/master/media/cli.gif\" alt=\"upash cli\" width=\"400\" align=\"right\"/>\n\nGenerally, each function allows configuration of 'work factors’.\nUnderlying mechanisms used to achieve irreversibility and govern work factors\n(such as time, space, and parallelism) vary between functions.  \n\nYou want to adjust the work factor to keep pace with threats' increasing hardware\ncapabilities so as to impede attackers while providing acceptable user experience\nand scale.\n\nA common rule of thumb for tuning the work factor (or cost) is to make the\nfunction run as slow as possible without affecting the users' experience and\nwithout increasing the need for extra hardware over budget.\n\nThe CLI lets you hash and verify password directly from your terminal.  \nYou can use it to test work, memory and parallelism parameters on different\nmachines.\n\nFor installation and usage information about the CLI, see the\n[upash-cli][gh:upash-cli] page.\n\n## Migrating your existing password hashing solution\nIf you are not building a new application, chances are high that you have\nalready implemented some hash/verify logic for your passwords.  \nThe [migration guide][docs:migration-guide] provides some good guidance on how\nto accomplish an upgrade in place without adversely affecting existing user\naccounts and future proofing your upgrade so you can seamlessly upgrade again\n(which you eventually will need to do).\n\nPlease if you do not find a migration documentation that fits your case,\n[open an issue][new issue].\n\n## Upgrading your password hashing algorithm\nUpgrading the hashing algorithm used to hash passwords inside your application\ncan be a really painful operation if not done well.\nYou should take a lot of attention in order to not adversely affect existing\nuser accounts.  \n\n[This article][docs:ext:upgrade-algorithm] is a nice start that should give you\nsome ideas on what are the problems related to that process.  \n\nExample of implementations can be found in the\n[upgrade algorithm guide][docs:upgrade-algorithm].\n\n## API\n<dl>\n<dt><a href=\"#install\">install(name, algorithm)</a></dt>\n<dd><p>Installs a compatible password hashing function.</p>\n</dd>\n<dt><a href=\"#uninstall\">uninstall(name)</a></dt>\n<dd><p>Uninstalls a password hashing function previously installed.</p>\n</dd>\n<dt><a href=\"#list\">list()</a> ⇒ <code>Array.&lt;string&gt;</code></dt>\n<dd><p>Gets the list of the installed password hashing functions.</p>\n</dd>\n<dt><a href=\"#use\">use(name)</a> ⇒ <code>Object</code></dt>\n<dd><p>Selects manually which password hashing function to use.\nYou can call hash and verify on the object returned.</p>\n</dd>\n<dt><a href=\"#which\">which(hashstr)</a> ⇒ <code>string</code> | <code>null</code></dt>\n<dd><p>Returns the name of the algorithm that has generated the hash string.</p>\n</dd>\n<dt><a href=\"#verify\">verify(hashstr, password)</a> ⇒ <code>Promise.&lt;boolean&gt;</code></dt>\n<dd><p>Determines whether or not the hash provided matches the hash generated for\nthe given password choosing the right algorithm based on the identifier\ncontained in the hash.</p>\n</dd>\n<dt><a href=\"#hash\">hash(password, [options])</a> ⇒ <code>Promise.&lt;string&gt;</code></dt>\n<dd><p>Computes the hash string of the given password using the &#39;last&#39; algorithm\ninstalled.</p>\n</dd>\n</dl>\n\n<a name=\"install\"></a>\n\n### install(name, algorithm)\nInstalls a compatible password hashing function.\n\n**Kind**: global function  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| name | <code>string</code> | The name of the password hashing function. |\n| algorithm | <code>Object</code> | The password hashing function object. |\n| algorithm.hash | <code>function</code> | A function that takes a password and returns a cryptographically secure password hash string. |\n| algorithm.verify | <code>function</code> | A function that takes a secure password hash string and a password and returns whether or not the password is valid for the given hash string. |\n| algorithm.identifiers | <code>function</code> | A function that returns the list of identifiers that this password hashing algorithm is able to generate / verify. |\n\n<a name=\"uninstall\"></a>\n\n### uninstall(name)\nUninstalls a password hashing function previously installed.\n\n**Kind**: global function  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| name | <code>string</code> | The name of the algorithm to uninstall or 'last' to uninstall the last one installed. |\n\n<a name=\"list\"></a>\n\n### list() ⇒ <code>Array.&lt;string&gt;</code>\nGets the list of the installed password hashing functions.\n\n**Kind**: global function  \n**Returns**: <code>Array.&lt;string&gt;</code> - The array of the available password hashing\nfunctions.  \n**Access**: public  \n<a name=\"use\"></a>\n\n### use(name) ⇒ <code>Object</code>\nSelects manually which password hashing function to use.\nYou can call hash and verify on the object returned.\n\n**Kind**: global function  \n**Returns**: <code>Object</code> - The password hashing function object.  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| name | <code>string</code> \\| <code>undefined</code> | The name of the algorithm to use. |\n\n<a name=\"which\"></a>\n\n### which(hashstr) ⇒ <code>string</code> \\| <code>null</code>\nReturns the name of the algorithm that has generated the hash string.\n\n**Kind**: global function  \n**Returns**: <code>string</code> \\| <code>null</code> - The name of password hashing algorithm.  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| hashstr | <code>string</code> | Secure hash string generated from this package. |\n\n<a name=\"verify\"></a>\n\n### verify(hashstr, password) ⇒ <code>Promise.&lt;boolean&gt;</code>\nDetermines whether or not the hash provided matches the hash generated for\nthe given password choosing the right algorithm based on the identifier\ncontained in the hash.\n\n**Kind**: global function  \n**Returns**: <code>Promise.&lt;boolean&gt;</code> - A boolean that is true if the hash computed\nfor the password matches.  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| hashstr | <code>string</code> | Secure hash string generated from this package. |\n| password | <code>string</code> | User's password input. |\n\n<a name=\"hash\"></a>\n\n### hash(password, [options]) ⇒ <code>Promise.&lt;string&gt;</code>\nComputes the hash string of the given password using the 'last' algorithm\ninstalled.\n\n**Kind**: global function  \n**Returns**: <code>Promise.&lt;string&gt;</code> - The generated secure hash string.  \n**Access**: public  \n\n| Param | Type | Description |\n| --- | --- | --- |\n| password | <code>string</code> | The password to hash. |\n| [options] | <code>Object</code> | Optional configurations related to the hashing function. See the algorithm specific documentation for the options supported. |\n\n## Contributing\nContributions are REALLY welcome and if you find a security flaw in this code,\nPLEASE [report it][new issue].  \n\n## Authors\n- **Simone Primarosa** - *Github* ([@simonepri][github:simonepri]) • *Twitter* ([@simoneprimarosa][twitter:simoneprimarosa])\n\nSee also the list of [contributors][contributors] who participated in this project.\n\n## License\nThis project is licensed under the MIT License - see the [license][license] file for details.\n\n<!-- Links -->\n[start]: https://github.com/simonepri/upash#start-of-content\n[new issue]: https://github.com/simonepri/upash/issues/new\n[contributors]: https://github.com/simonepri/upash/contributors\n\n[license]: https://github.com/simonepri/upash/tree/master/license\n\n[gh:upash-cli]: https://github.com/simonepri/upash-cli\n\n[alg:@phc/argon2]: https://github.com/simonepri/upash-argon2\n[alg:@phc/scrypt]: https://github.com/simonepri/upash-scrypt\n[alg:@phc/bcrypt]: https://github.com/simonepri/upash-bcrypt\n[alg:@phc/pbkdf2]: https://github.com/simonepri/upash-pbkdf2\n\n[github:simonepri]: https://github.com/simonepri\n[twitter:simoneprimarosa]: http://twitter.com/intent/user?screen_name=simoneprimarosa\n\n[argon2:password-competition]: https://password-hashing.net/\n[upash:pronounce]: https://translate.google.com/translate_tts?ie=UTF-8&client=tw-ob&tl=en&q=u-pash\n\n[docs:migration-guide]: https://github.com/simonepri/upash/tree/master/docs/migrate-your-solution.md\n[docs:upgrade-algorithm]: https://github.com/simonepri/upash/tree/master/docs/upgrade-algorithm.md\n[docs:password-hashing-theory]: https://github.com/simonepri/upash/tree/master/docs/password-hashing-theory.md\n[docs:ext:upgrade-algorithm]: https://veggiespam.com/painless-password-hash-upgrades/\n\n[breach:yahoo]: https://help.yahoo.com/kb/account/SLN27925.html\n[breach:yahoo2]: https://help.yahoo.com/kb/account/sln28092.html\n[breach:linkedin]: https://motherboard.vice.com/en_us/article/78kk4z/another-day-another-hack-117-million-linkedin-emails-and-password\n[breach:adobe]: https://www.troyhunt.com/adobe-credentials-and-serious/\n[breach:ashley-madison]: https://krebsonsecurity.com/2015/07/online-cheating-site-ashleymadison-hacked/\n[breach:hibp-breaches]: https://haveibeenpwned.com/PwnedWebsites\n","readmeFilename":"readme.md"}