Req #71992 [Wfx]: The $iv parameter should be required since E_WARNING is thrown without it
| From: | bukka@php.net | Date: | Mon, 02 May 2016 14:29:10 +0000 |
| Subject: | Req #71992 [Wfx]: The $iv parameter should be required since E_WARNING is thrown without it | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200862@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71992&edit=1
ID: 71992
Updated by: bukka@php.net
Reported by: markreodica at gmail dot com
Summary: The $iv parameter should be required since E_WARNING
is thrown without it
Status: Wont fix
Type: Feature/Change Request
Package: OpenSSL related
PHP Version: Irrelevant
-Assigned To: bukk
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
This is just an incorrect documentation. The IV parameter depends on cipher mode. It means that
it's not required for ECB mode or some weak ciphers like RC4. The function is marked as not
documented but we will hopefully improve it at some point.
Previous Comments:
------------------------------------------------------------------------
[2016-04-08 16:44:13] markreodica at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.openssl-encrypt
---
The manual says: "Emits an E_WARNING level error if an empty value is passed in via the iv
parameter."
Because of this behavior, the $iv parameter should be required. The parameter should not be labeled
as optional if it's throwing an E_WARNING if not used.
Test script:
---------------
Test script is not really needed.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71992&edit=1