diff --git a/flask_bcrypt.py b/flask_bcrypt.py index 994985a..78812c9 100644 --- a/flask_bcrypt.py +++ b/flask_bcrypt.py @@ -221,5 +221,5 @@ def check_password_hash(self, pw_hash, password): if self._handle_long_passwords: password = hashlib.sha256(password).hexdigest() password = self._unicode_to_bytes(password) - - return hmac.compare_digest(bcrypt.hashpw(password, pw_hash), pw_hash) + + return bcrypt.checkpw(password, pw_hash)