Jump to main content Jump to doc navigation

modUser::passwordMatches

Hashes the candidate with the class named by hash_class through the hashing service and compares the result with the stored password field. changePassword() uses it to validate the old password.

$options are merged with the User's own salt as the base, so a salt key passed here wins. The hash implementation defines how the rest of the options are used. modPBKDF2 reads salt, iterations, derived_key_length, algorithm and raw_output; the default modNative runs password_verify() and ignores them. If the hashing service does not load, the method returns false.

Syntax

boolean passwordMatches (string $password [, array $options = array()])
  • $password (string) Plain password to check against the stored hash.
  • $options (array) Implementation-specific hashing options, by default array().

Example

$user = $modx->getObject('modUser', array('username' => 'foobar'));

if ($user->passwordMatches('s3cur3d')) {
    echo 'ok';
}

See Also

Support the team building MODX with a monthly donation.

The budget raised through OpenCollective is transparent, including payouts, and any contributor can apply to be paid for their work on MODX.

Backers

  • modmore
  • STERC
  • Digital Penguin
  • Jens Wittmann – Gestaltung & Entwicklung
  • CrewMark
  • Fabian Christen
  • Sepia River Studios
  • Dannevang Digital
  • Alex
  • A. Moreno
  • Chris Fickling
  • Stéphane Jäggi
  • Murray Wood
  • Anton Tarasov
  • JT Skaggs
  • deJaya
  • Lefthandmedia
  • eydolan
  • Following Sea
  • Guido Gallenkamp
  • YJ
  • Raffy
  • Snow Creative
  • Nick Clark
  • Guest
  • Helen
  • krisznet
  • Yanni
  • Richard

Budget

$194 per month—let's make that $500!

Learn more