PASSWORD HASHING (bcrypt)
PASSWORD HASHING (bcrypt) is a SQL function in the Administration category. Password hashing best practices in SQL: store hashes, not plaintext. Use bcrypt, SHA-256, or database-specific hash functions. The syntax is -- PostgreSQL: crypt() from pgcrypto. MySQL: PASSWORD() is deprecated, use application-level hashing.. It accepts see syntax. It returns password hash. A typical example: -- PostgreSQL (pgcrypto): CREATE EXTENSION pgcrypto; INSERT INTO users (username, pass) VALUES ('alice', crypt('mypassword', gen_salt('bf'))); -- Verify: SELECT * FROM users WHERE username = 'alice' AND pass = crypt('input_password', pass); -- crypt() extracts salt from stored hash, re-hashes input, compares -- SQL Server: -- Use HASHBYTES('SHA2_512', 'password' + CAST(salt AS VARCHAR(32))) -- NEVER use plain MD5 or SHA1 for passwords -- bcrypt (bf) or SHA2_256/512 with salt are recommended A close relative is CREATE USER, which creates a new database user account. A close relative is GRANT, which grants specific privileges (SELECT, INSERT, UPDATE, DELETE, ALL) to a user on a database/table.