0Pricing
Flask Academy · درس

تجزئة كلمات المرور وعدم تخزينها كنص صريح

استخدم Werkzeug لتجزئة كلمات المرور والتحقق منها.

تجزئة كلمات المرور وعدم تخزينها كنص صريح درس مجاني في Flask Academy على CoddyKit. هذا هو الدرس 1 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Flask Academy، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Flask Academy 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Plaintext Is a Disaster

If you store passwords as plaintext, one database leak hands attackers every account at once. The first rule of auth is simple: never save the raw password. 🔒

Hashing, Not Encrypting

You protect passwords with hashing, a one-way transform. Unlike encryption, a hash cannot be reversed back into the original password, even by you.

Werkzeug Has It Built In

Flask ships with Werkzeug, which gives you two helpers for password security. You import them straight from its security module, no extra install needed.

from werkzeug.security import generate_password_hash, check_password_hash

Hash on Sign-Up

When a user registers, run generate_password_hash on their password and store only the result. The plaintext never touches your database.

hashed = generate_password_hash("hunter2")
user.password_hash = hashed

Salt Comes Free

generate_password_hash adds a random salt for you. That is why two users with the same password get totally different stored hashes.

Verify on Login

At login you cannot un-hash anything. Instead you call check_password_hash with the stored hash and the typed password to get a True or False.

ok = check_password_hash(user.password_hash, "hunter2")

Argument Order Matters

Remember the order: the stored hash comes first, the user-supplied password second. Swapping them silently breaks every login attempt.

check_password_hash(stored_hash, typed_password)

Pick a Strong Method

By default Werkzeug uses a strong, slow algorithm on purpose. Slowness is a feature here, because it makes brute-force guessing far more expensive.

generate_password_hash(pw, method="pbkdf2:sha256")

Store the Hash, Not More

Your user table needs a single password_hash column. You never need a separate salt column, since the salt is baked into the hash string itself.

password_hash = db.Column(db.String(255))

Helper Methods on User

A clean trick is to put a set_password method on your User model so hashing lives in one place and your routes stay tidy.

def set_password(self, pw):
    self.password_hash = generate_password_hash(pw)

Never Log the Password

Even during debugging, do not print or log the raw password. A stray log line can leak credentials just as badly as a database breach can.

Quick Check

You need to confirm a login. Which call should you use?

Recap

You learned to hash with generate_password_hash, store only the result, and verify with check_password_hash. Plaintext passwords are gone for good. 🎉

الأسئلة الشائعة

هل درس «تجزئة كلمات المرور وعدم تخزينها كنص صريح» مجاني؟

نعم — نص درس «تجزئة كلمات المرور وعدم تخزينها كنص صريح» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Flask Academy، انتقل إلى CoddyKit PRO. تتضمن دورة Flask Academy 4 دروس في المجموع.

ماذا ستتعلم في «تجزئة كلمات المرور وعدم تخزينها كنص صريح»؟

استخدم Werkzeug لتجزئة كلمات المرور والتحقق منها. تتمرن على Flask Academy مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Flask Academy؟

لا تُشترط خبرة سابقة. Flask Academy على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 1 من أصل 4.

كم من الوقت يستغرق درس «تجزئة كلمات المرور وعدم تخزينها كنص صريح»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Flask Academy هذا؟

نعم. كل درس في Flask Academy يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. تجزئة كلمات المرور وعدم تخزينها كنص صريح
  2. محمّل المستخدم وUserMixin
  3. login_user وlogout_user والجلسات
  4. حماية العروض باستخدام login_required
← العودة إلى Flask Academy