/*
* JBoss, Home of Professional Open Source.
* Copyright 2012, Red Hat, Inc., and individual contributors
* as indicated by the @author tags. See the copyright.txt file in the
* distribution for a full listing of individual contributors.
*
* This is free software; you can redistribute it and/or modify it
* under the terms of the GNU Lesser General Public License as
* published by the Free Software Foundation; either version 2.1 of
* the License, or (at your option) any later version.
*
* This software is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
*
* You should have received a copy of the GNU Lesser General Public
* License along with this software; if not, write to the Free
* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
*/
package org.exoplatform.web.security.hash;
/**
* Interface for creating salted hashes from plaintext passwords and for validating passwords against stored salted hashes.
*
* @author <a href="mailto:ppalaga@redhat.com">Peter Palaga</a>
*
*/
public interface SaltedHashService {
/**
* Computes a salted hash of given plaintext password suitable for storing in a database.
*
* @throws SaltedHashException
*/
String getSaltedHash(String password) throws SaltedHashException;
/**
* Checks whether given plaintext {@code password} corresponds to the given {@code saltedHash}.
*
* @param password
* @param saltedHash
* @return {@code true} if the given {@code password} matches the given {@code saltedHash}; {@code false} otherwise.
* @throws SaltedHashException if the {@code saltedHash} cannot be parsed or if the hashing algorithm is not available.
*/
boolean validate(String password, String saltedHash) throws SaltedHashException;
}