HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulepassword-types-1.0.0.0Haskell2010

Data.Password.Types

This library provides datatypes for interacting with passwords. It provides the types Password and PasswordHash, which correspond to plain-text and hashed passwords.

Special instances

There is an accompanying password-instances package that provides canonical typeclass instances for Password and PasswordHash for many common typeclasses, like FromJSON from aeson, PersistField from persistent, etc.

See the password-instances package for more information.

Phantom types

The PasswordHash and Salt data types have a phantom type parameter to be able to make sure salts and hashes can carry information about the algorithm they should be used with.

For example, the bcrypt algorithm requires its salt to be exactly 16 bytes (128 bits) long, so this way you won't accidentally use a Salt PBKDF2 when the hashing function requires a Salt Bcrypt. And checking a password using bcrypt would obviously fail if checked against a PasswordHash PBKDF2.

  • 3 types
  • 2 values

Plain-text Password

2 declarations
newtypenewtype Password
#

A plain-text password.

This represents a plain-text password that has NOT been hashed.

You should be careful with Password. Make sure not to write it to logs or store it in a database.

You can construct a Password by using the mkPassword function or as literal strings together with the OverloadedStrings pragma (or manually, by using fromString on a String). Alternatively, you could also use some of the instances in the password-instances library.

Instances2Show, IsString
  • Show PasswordDefined in password-types-1.0.0.0 · Data.Password.Types

    CAREFUL: Show-ing a Password will always print "**PASSWORD**"

    Example1 expression
    show ("hello" :: Password)"**PASSWORD**"
  • IsString PasswordDefined in password-types-1.0.0.0 · Data.Password.Types

Password Hashing

1 declaration
newtypenewtype PasswordHash a
#

A hashed password.

This represents a password that has been put through a hashing function. The hashed password can be stored in a database.

Instances4Eq, Ord, Read, Show
  • Eq (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Ord (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Read (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Show (PasswordHash a)Defined in password-types-1.0.0.0 · Data.Password.Types

Unsafe debugging function to show a Password

This is an unsafe function that shows a password in plain-text.

Example1 expression
unsafeShowPassword ("foobar" :: Password)"foobar"

You should generally not use this function in production settings, as you don't want to accidentally print a password anywhere, like logs, network responses, database entries, etc.

This will mostly be used by other libraries to handle the actual password internally, though it is conceivable that, even in a production setting, a password might have to be handled in an unsafe manner at some point.

Hashing salts

1 declaration
newtypenewtype Salt a
#

A salt used by a hashing algorithm.

Constructors

Instances2Eq, Show
  • Eq (Salt a)Defined in password-types-1.0.0.0 · Data.Password.Types
  • Show (Salt a)Defined in password-types-1.0.0.0 · Data.Password.Types