Skip to content

HashPassword

Hashes a password for the mode’s own accounts - one text to store as it is.

PBKDF2-SHA256 with a random salt and 20 000 rounds, everything in one text (pbkdf2$...) that VerifyPassword checks later. Store that text in the mode’s database; never the password. The hash costs a few milliseconds on the server’s thread - a registration’s worth, not something to run every tick.

HashPassword(password)
Parameter Type
password string the password as the player typed it

string - the hash text

db:Execute("INSERT INTO players (name, password) VALUES (@n, @p)", { n = name, p = HashPassword(password) })

VerifyPassword · SetSecretCommand · GetDatabase · the Accounts, admins, bans and the audit group of the index