Checksum Verifier — Java source
Drag and drop a file to compute its MD5, SHA-1, SHA-256, and SHA-512 checksums. Paste an expected hash to verify integrity - detect tampered or corrupted downloads instantly. Runs entirely in your browser.
This is the Java implementation — the same logic the interactive tool runs, in a shareable, citable form.
// Checksum Verifier — MD5 / SHA-1 / SHA-256 / SHA-512 digests + verification.
//
// Language: Java (17+, standard library only)
// Ported from src/lib/checksum-verifier.ts
// display source — part of CosmoDev's polyglot tool pages.
//
// The TS reference implements MD5 from scratch because the Web Crypto API
// dropped MD5; the JDK's java.security.MessageDigest still ships it, so all
// four algorithms use the platform digest here. The verification helpers
// (length-based algorithm detection, normalization, comparison) are ported
// as-is.
import java.security.MessageDigest;
import java.util.Locale;
import java.util.Map;
public final class ChecksumVerifier {
/** The four checksums of one buffer, as lowercase hex. */
public record ChecksumResult(String md5, String sha1, String sha256, String sha512) {
}
public enum HashAlgorithm { MD5, SHA1, SHA256, SHA512 }
private static final Map<Integer, HashAlgorithm> LENGTH_TO_ALGO = Map.of(
32, HashAlgorithm.MD5,
40, HashAlgorithm.SHA1,
64, HashAlgorithm.SHA256,
128, HashAlgorithm.SHA512);
private ChecksumVerifier() {
}
private static String toHex(byte[] bytes) {
StringBuilder sb = new StringBuilder(bytes.length * 2);
for (byte b : bytes) {
sb.append(Character.forDigit((b >> 4) & 0xf, 16));
sb.append(Character.forDigit(b & 0xf, 16));
}
return sb.toString();
}
/** Digest a buffer and return lowercase hex. */
public static String hex(HashAlgorithm algorithm, byte[] data) throws Exception {
String name = switch (algorithm) {
case MD5 -> "MD5";
case SHA1 -> "SHA-1";
case SHA256 -> "SHA-256";
case SHA512 -> "SHA-512";
};
return toHex(MessageDigest.getInstance(name).digest(data));
}
/** Compute all four checksums of a buffer. */
public static ChecksumResult computeChecksums(byte[] data) throws Exception {
return new ChecksumResult(
hex(HashAlgorithm.MD5, data),
hex(HashAlgorithm.SHA1, data),
hex(HashAlgorithm.SHA256, data),
hex(HashAlgorithm.SHA512, data));
}
// --- Verification helpers ---------------------------------------------------
/** Normalize a pasted hash: drop whitespace and `:` grouping, lowercase. */
private static String normalizeHash(String hash) {
return hash.trim().replaceAll("[\\s:]", "").toLowerCase(Locale.ROOT);
}
/** Detect the algorithm from the hex length: 32=MD5, 40=SHA-1, 64=SHA-256, 128=SHA-512. */
public static HashAlgorithm detectHashAlgorithm(String hash) {
String h = normalizeHash(hash);
if (!h.matches("[0-9a-f]+")) {
return null;
}
return LENGTH_TO_ALGO.get(h.length());
}
/** The verdict of comparing an expected hash against a computed result. */
public record Verification(HashAlgorithm algorithm, boolean match) {
}
/**
* Compare an expected hash against a computed result. Returns null when the
* expected string is not a recognizable hex hash of a supported length.
*/
public static Verification verifyChecksum(String expected, ChecksumResult result) {
HashAlgorithm algorithm = detectHashAlgorithm(expected);
if (algorithm == null) {
return null;
}
String actual = switch (algorithm) {
case MD5 -> result.md5();
case SHA1 -> result.sha1();
case SHA256 -> result.sha256();
case SHA512 -> result.sha512();
};
return new Verification(algorithm, normalizeHash(expected).equals(actual));
}
}
Also available in 8 other languages
Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →