sodium_crypto_pwhash_str_verify
(PHP 7 >= 7.2.0, PHP 8)
Verifies that a password matches a hash
Description
Checks that a password hash created using sodium_crypto_pwhash_str() matches a given plain-text password. Note that the parameters are in the opposite order to the same parameters in the similar password_verify() function.
Parameters
hashHash
passwordPassword
Return Values
Returns true if the password and hash match, or false otherwise.
Notes
Hashes are calculated using the Argon2ID algorithm, providing resistance to both GPU and side-channel attacks.