Bug #66835 [Nab]: password_verifiy

From: Date: Thu, 06 Mar 2014 14:29:37 +0000
Subject: Bug #66835 [Nab]: password_verifiy
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184580@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66835&edit=1 ID: 66835 User updated by: pl dot lamballais at flashover dot fr Reported by: pl dot lamballais at flashover dot fr Summary: password_verifiy Status: Not a bug Type: Bug Package: *General Issues Operating System: Linux PHP Version: 5.5.10 Block user comment: N Private report: N New Comment: Agree with nikic, not really a bug. Maybe a good thing will be to add a note about that on the doc. Because I notice that, depending on the hash, some are working with ' or "" and others not... :/ This means you can do your dev, test and if, unfortunatly the hash used for test are good even with ' or " you'll have some problems... later. Previous Comments: ------------------------------------------------------------------------ [2014-03-06 13:44:17] nikic@php.net "...$BCryptRequires22Chrcte..." will interpolate the value of the variable $BCryptRequires22Chrcte into the string. I would recommend to enable notices during development. ------------------------------------------------------------------------ [2014-03-06 13:39:21] pl dot lamballais at flashover dot fr Description: ------------ --- From manual page: http://www.php.net/function.password-verify --- System is:Linux webd497.20gp.ha.ovh.net 3.10.23-grsec-mutu-grs-ipv6-64+ #42 SMP Wed Feb 26 12:45:33 CET 2014 x86_64 PHP version is 5.5.7 Notice a strange comportemnt of password_verify() depending on the fact the hash variable is using ' or ". I start to think this affect also the hash builder as I've some user records in my database which are seen as "correct" using password_verify and others which are seen as "bad password" when in fact they are all build the same way. Test script: --------------- // First exemple will give "Password is valid!" $hash = '$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq'; if (password_verify('rasmuslerdorf', $hash)) { echo 'Password is valid!';} else { echo 'Invalid password.';} // But this one will will give "Invalid password!" $hash = "$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq"; if (password_verify('rasmuslerdorf', $hash)) { echo 'Password is valid!';} else { echo 'Invalid password.';} ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66835&edit=1

« previous php.bugs (#184580) next »