

I wouldn’t send the salt to the client. Have it hash the password, then the server hashes that with the salt for comparison and storage.
But that would mean you can’t verify the password complexity server side, which can be bad for certain accounts.




The client salt would need to be consistent and “public” since the client needs it before login. It’s basically useless.