3. Password Encoding

Never store plain-text passwords. When you boot the application, internal/autoconfig automatically registers a highly secure, upgradeable default PasswordEncoder.

The Delegating Password Encoder

To support seamless algorithm migrations over time (a best practice from Spring Security), the default encoder is a DelegatingPasswordEncoder.

It automatically wraps a BCryptPasswordEncoder (with a cost of 10) mapped to the “bcrypt” prefix. This means your hashed passwords will automatically be formatted with a prefix, looking something like this: {bcrypt}$2a$10$wN1FzZ2...

Overriding the Default Encoder

If you need to override this default (for example, to increase the hashing cost to 12 or to add support for legacy passwords), you can simply define your own PasswordEncoder Beam:

package security

import (
    . "github.com/BeamFoundry/rays-web-security/pkg/core"
    . "github.com/BeamFoundry/rays-web-security/pkg/password"
    . "github.com/BeamFoundry/rays/pkg/core"
)

type PasswordConfig struct {
    Configuration
}

// Overrides the auto-configured DelegatingPasswordEncoder
func (this *PasswordConfig) PasswordEncoder() PasswordEncoder {
    return DelegatingPasswordEncoder{}.New(
        "bcrypt",
        map[string]PasswordEncoder{
            "bcrypt": BCryptPasswordEncoder{}.New(12), // Increased cost!
            "noop":   NoOpPasswordEncoder{}.New(),     // Support legacy plaintext (Not Recommended!)
        },
    )
}