Quote:
is Bcrypt one way-hash ?
Yes. All hashes are effectively one-way: they throw away information to produce a "unique" value for the input.
Quote:
how about admin forget password ?
When you forget a password, you reset it to a new value (and store the hash of that in the DB) and send the new password to the user, encouraging them to change it to one they can remember. (In order to make them do this, I use GUIDs as the new password - nobody wants to try and remember them, so they do reset the value pretty quickly)
Quote:
how to know admin plain password from password encryption?
You can't: all passwords are stored as hashes, so that nobody at all (except the user) has any idea what password they used.