same salt, same password, different results (bcrypt)

Viewed 42

I'm using bcrypt with Node.js and the hash comes out different each time, even using the same salt. This is my code:

const bcrypt = require('bcrypt');

let saltRounds = 1;
let salt = bcrypt.genSaltSync(saltRounds);
let hash = bcrypt.hashSync('senha', salt);

console.log(hash);

What am I doing wrong? How to solve this?

1 Answers

You are re-generating the salt each time. You must generate the salt only once, and store it along with the hashed password. When it comes time to validate, pull the salt and the hashed password from storage, hash the input password using the stored salt, and compare to the stored hashed password.

Related