Encryption and Hashing
Hashing passwords
Section titled “Hashing passwords”Naluz\Security\Hasher uses Argon2id (bcrypt if Argon2 is unavailable).
use Naluz\Security\Hasher;
$hash = $hasher->make('secret');$hasher->check('secret', $hash); // true$hasher->needsRehash($hash); // true when the parameters changedThe hashed model cast hashes on assignment, and Auth::attempt() rehashes when needed.
Encrypting data
Section titled “Encrypting data”Naluz\Security\Encrypter uses XChaCha20-Poly1305 with APP_KEY:
use Naluz\Security\Encrypter;
$token = $encrypter->encryptString('secret');$encrypter->decryptString($token); // 'secret'
$payload = $encrypter->encrypt(['id' => 5]); // any JSON-serializable value$encrypter->decrypt($payload);A wrong key or tampered payload throws Naluz\Security\DecryptException; data is never returned unauthenticated.
For sensitive database columns use the encrypted cast:
protected array $casts = ['api_key' => 'encrypted'];Encrypted columns cannot be searched in SQL.
php naluz key:generate # APP_KEYphp naluz key:generate --jwt # also JWT_SECRETphp naluz key:generate --show # print instead of writing .envAPP_KEY must be 32 bytes (base64: prefixed). Rotate it without losing data by listing old keys in
config/app.php:
'key' => env('APP_KEY'),'previous_keys' => ['base64:the-old-key'],Decryption tries the current key first, then each previous key. New encryption always uses the current key.
What uses APP_KEY
Section titled “What uses APP_KEY”- the
encryptedcast - queue payloads
- optional model-cache encryption (
MODEL_CACHE_ENCRYPT=true)