Skip to content

BCrypt.Net-Next: .NET 10, 4.2.0, rehash and compatibility tests - #2259

Open
vladimir-pecanac-main wants to merge 1 commit into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/78377-dotnet-secure-passwords-bcrypt
Open

vladimir-pecanac-main wants to merge 1 commit into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/78377-dotnet-secure-passwords-bcrypt

Conversation

@vladimir-pecanac-main

Copy link
Copy Markdown
Collaborator

Updates the sample for "How to Secure Passwords with BCrypt.NET" (https://code-maze.com/dotnet-secure-passwords-bcrypt/).

Changes, all inside authorization-dotnet/HowToSecurePasswordsWithBCryptNET:

  • Both projects retargeted from net7.0 to net10.0.
  • BCrypt.Net-Next 4.0.3 to 4.2.0 (latest listed stable; 4.2.1 is unlisted on NuGet).
  • Test stack: Microsoft.NET.Test.Sdk 18.10.1, xunit 2.9.3, xunit.runner.visualstudio 4.0.0, coverlet.collector 10.1.0.
  • New PasswordLoginService with the LoginAndUpgrade method the article shows; the test project references the console project.
  • Program.cs now hashes, verifies and upgrades a password instead of printing a placeholder.
  • New tests: PasswordNeedsRehash true/false, InterrogateHash, the PHP manual password_verify $2y$ vector, the four accepted revisions, an unsupported revision, enhanced hash vs plain Verify and the wrong HashType, the 72-byte truncation (plain and enhanced), the 4 to 31 work factor range (upper bound checked through GenerateSalt(31), never hashed at 31), and LoginAndUpgrade.

Package versions re-queried on NuGet on 2026-10-04: BCrypt.Net-Next 4.2.0, Microsoft.NET.Test.Sdk 18.10.1, xunit 2.9.3, xunit.runner.visualstudio 4.0.0, coverlet.collector 10.1.0.

Local run: SDK 10.0.302, runtime 10.0.10. dotnet build -c Release 0 warnings 0 errors; dotnet test Passed 24, Failed 0. dotnet list package --vulnerable --include-transitive: no vulnerable packages.

…ompatibility tests

Both projects move from net7.0 to net10.0. BCrypt.Net-Next goes from 4.0.3 to 4.2.0
and the test stack is bumped. New tests cover PasswordNeedsRehash, InterrogateHash,
a PHP-generated $2y$ hash, the accepted revisions, enhanced entropy against plain
Verify, the 72-byte truncation, the work factor range, and the LoginAndUpgrade
method that now lives in PasswordLoginService. Program.cs hashes, verifies and
upgrades a password instead of printing a placeholder.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant