Bug #77225 [NEW]: Object class does not function

From: Date: Fri, 30 Nov 2018 14:31:12 +0000
Subject: Bug #77225 [NEW]: Object class does not function
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218225@lists.php.net to get a copy of this message
From: magnus at feitocubo dot com dot br Operating system: LINUX/UNIX PHP version: 7.2.12 Package: hash related Bug Type: Bug Bug description:Object class does not function Description: ------------ PASSWORD_HASH does not function into object class. When we declare one kind of class and these object works with a function that return a string HASHed using, inside this function, the PASSWORD_HASH function, become a wrong functionality when we check hash string with PASSWORD_VERIFY function. So, using PASSWORD_VERIFY to validate a HASH string, using a object class, returns always FALSE. Only using PASSWORD_HASH directly in the line to generate a HASH works ok, in the objetct class doesn't work. some type of microtime in the object's instantiation of memory is affecting the HASH generation with the PASSWORD_HASH function inside the LINUX / UNIX OS. This proceeds? class HashController{ /** * Definição de variáveis privadas - uso interno na classe * */ private $AlgoType = PASSWORD_DEFAULT; private $CostOfProcess = ['cost'=>10]; private $InputString = null; private $TargetTimeToGo = 0.1; /** * fncGetHashString - Gera chave HASH * * @since 0.1 * @access public * @return string - Criptografia de string do sistema */ public function fncGetHashString ($InputString) : String { if (empty($InputString)){ return null; } else{ return password_hash($this->InputString, (int)$this->AlgoType, $this->CostOfProcess); } } /** * fncSetCostOfProcess - Configura a variável privada VCost - custo de processamento da chave HASH * * @since 0.1 * @access public * @ */ public function fncSetCostOfProcess ($Cost) { if ((isset($Cost)) && ($Cost > 0)){ $this->CostOfProcess = ['cost'=>(int)$Cost]; } } /** * fncSetAlgoType - Configura a variável privada AlgoType - tipo algoritmo para hash * * @since 0.1 * @access public * @ */ public function fncSetAlgoType ($inAlgoType) { if (isset($inAlgoType)) { $this->AlgoType = $inAlgoType; } } /** * fncBestCostProcess - Gera valor de melhor custo de processamento * da chave HASH * * @since 0.1 * @access public * @return int - Valor do melhor custo encontrado */ public function fncBestCostProcess ($InputUserPassword, $inTargetTimeToGo) : int { $VCost = 8; if ((!isset($inTargetTimeToGo)) || (is_null($inTargetTimeToGo))) { $inTargetTimeToGo = $this->TargetTimeToGo; } do{ $VCost++; $StartTime = microtime(true); password_hash($InputUserPassword, (int)$this->AlgoType, ['cost' => $VCost]); $EndTime = microtime(true); } while (($EndTime - $StartTime) < $inTargetTimeToGo); return $VCost; } } Test script: --------------- class HashController{ /** * Definição de variáveis privadas - uso interno na classe * */ private $AlgoType = PASSWORD_DEFAULT; private $CostOfProcess = ['cost'=>10]; private $InputString = null; private $TargetTimeToGo = 0.1; /** * fncGetHashString - Gera chave HASH * * @since 0.1 * @access public * @return string - Criptografia de string do sistema */ public function fncGetHashString ($InputString) : String { if (empty($InputString)){ return null; } else{ return password_hash($this->InputString, (int)$this->AlgoType, $this->CostOfProcess); } } /** * fncSetCostOfProcess - Configura a variável privada VCost - custo de processamento da chave HASH * * @since 0.1 * @access public * @ */ public function fncSetCostOfProcess ($Cost) { if ((isset($Cost)) && ($Cost > 0)){ $this->CostOfProcess = ['cost'=>(int)$Cost]; } } /** * fncSetAlgoType - Configura a variável privada AlgoType - tipo algoritmo para hash * * @since 0.1 * @access public * @ */ public function fncSetAlgoType ($inAlgoType) { if (isset($inAlgoType)) { $this->AlgoType = $inAlgoType; } } /** * fncBestCostProcess - Gera valor de melhor custo de processamento * da chave HASH * * @since 0.1 * @access public * @return int - Valor do melhor custo encontrado */ public function fncBestCostProcess ($InputUserPassword, $inTargetTimeToGo) : int { $VCost = 8; if ((!isset($inTargetTimeToGo)) || (is_null($inTargetTimeToGo))) { $inTargetTimeToGo = $this->TargetTimeToGo; } do{ $VCost++; $StartTime = microtime(true); password_hash($InputUserPassword, (int)$this->AlgoType, ['cost' => $VCost]); $EndTime = microtime(true); } while (($EndTime - $StartTime) < $inTargetTimeToGo); return $VCost; } } -- Edit bug report at https://bugs.php.net/bug.php?id=77225&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77225&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77225&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77225&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77225&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77225&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77225&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77225&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77225&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77225&r=support Expected behavior: https://bugs.php.net/fix.php?id=77225&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77225&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77225&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77225&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77225&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77225&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77225&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77225&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77225&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77225&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77225&r=mysqlcfg

« previous php.bugs (#218225) next »