Bug #77225 [Opn->Fbk]: Object class does not function

From: Date: Fri, 30 Nov 2018 15:42:45 +0000
Subject: Bug #77225 [Opn->Fbk]: Object class does not function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218228@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77225&edit=1 ID: 77225 Updated by: cmb@php.net Reported by: magnus at feitocubo dot com dot br Summary: Object class does not function -Status: Open +Status: Feedback Type: Bug Package: hash related Operating System: LINUX/UNIX PHP Version: 7.2.12 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Thank you for this bug report. To properly diagnose the problem, we need a short but complete example script to be able to reproduce this bug ourselves. A proper reproducing script starts with , is max. 10-20 lines long and does not require any external resources such as databases, etc. If the script requires a database to demonstrate the issue, please make sure it creates all necessary tables, stored procedures etc. Please avoid embedding huge scripts into the report. Previous Comments: ------------------------------------------------------------------------ [2018-11-30 14:31:12] magnus at feitocubo dot com dot br Description: ------------ PASSWORD_HASH does not function into object class. When we declare one kind of class and these object works with a function that return a string HASHed using, inside this function, the PASSWORD_HASH function, become a wrong functionality when we check hash string with PASSWORD_VERIFY function. So, using PASSWORD_VERIFY to validate a HASH string, using a object class, returns always FALSE. Only using PASSWORD_HASH directly in the line to generate a HASH works ok, in the objetct class doesn't work. some type of microtime in the object's instantiation of memory is affecting the HASH generation with the PASSWORD_HASH function inside the LINUX / UNIX OS. This proceeds? class HashController{ /** * Definição de variáveis privadas - uso interno na classe * */ private $AlgoType = PASSWORD_DEFAULT; private $CostOfProcess = ['cost'=>10]; private $InputString = null; private $TargetTimeToGo = 0.1; /** * fncGetHashString - Gera chave HASH * * @since 0.1 * @access public * @return string - Criptografia de string do sistema */ public function fncGetHashString ($InputString) : String { if (empty($InputString)){ return null; } else{ return password_hash($this->InputString, (int)$this->AlgoType, $this->CostOfProcess); } } /** * fncSetCostOfProcess - Configura a variável privada VCost - custo de processamento da chave HASH * * @since 0.1 * @access public * @ */ public function fncSetCostOfProcess ($Cost) { if ((isset($Cost)) && ($Cost > 0)){ $this->CostOfProcess = ['cost'=>(int)$Cost]; } } /** * fncSetAlgoType - Configura a variável privada AlgoType - tipo algoritmo para hash * * @since 0.1 * @access public * @ */ public function fncSetAlgoType ($inAlgoType) { if (isset($inAlgoType)) { $this->AlgoType = $inAlgoType; } } /** * fncBestCostProcess - Gera valor de melhor custo de processamento * da chave HASH * * @since 0.1 * @access public * @return int - Valor do melhor custo encontrado */ public function fncBestCostProcess ($InputUserPassword, $inTargetTimeToGo) : int { $VCost = 8; if ((!isset($inTargetTimeToGo)) || (is_null($inTargetTimeToGo))) { $inTargetTimeToGo = $this->TargetTimeToGo; } do{ $VCost++; $StartTime = microtime(true); password_hash($InputUserPassword, (int)$this->AlgoType, ['cost' => $VCost]); $EndTime = microtime(true); } while (($EndTime - $StartTime) < $inTargetTimeToGo); return $VCost; } } Test script: --------------- class HashController{ /** * Definição de variáveis privadas - uso interno na classe * */ private $AlgoType = PASSWORD_DEFAULT; private $CostOfProcess = ['cost'=>10]; private $InputString = null; private $TargetTimeToGo = 0.1; /** * fncGetHashString - Gera chave HASH * * @since 0.1 * @access public * @return string - Criptografia de string do sistema */ public function fncGetHashString ($InputString) : String { if (empty($InputString)){ return null; } else{ return password_hash($this->InputString, (int)$this->AlgoType, $this->CostOfProcess); } } /** * fncSetCostOfProcess - Configura a variável privada VCost - custo de processamento da chave HASH * * @since 0.1 * @access public * @ */ public function fncSetCostOfProcess ($Cost) { if ((isset($Cost)) && ($Cost > 0)){ $this->CostOfProcess = ['cost'=>(int)$Cost]; } } /** * fncSetAlgoType - Configura a variável privada AlgoType - tipo algoritmo para hash * * @since 0.1 * @access public * @ */ public function fncSetAlgoType ($inAlgoType) { if (isset($inAlgoType)) { $this->AlgoType = $inAlgoType; } } /** * fncBestCostProcess - Gera valor de melhor custo de processamento * da chave HASH * * @since 0.1 * @access public * @return int - Valor do melhor custo encontrado */ public function fncBestCostProcess ($InputUserPassword, $inTargetTimeToGo) : int { $VCost = 8; if ((!isset($inTargetTimeToGo)) || (is_null($inTargetTimeToGo))) { $inTargetTimeToGo = $this->TargetTimeToGo; } do{ $VCost++; $StartTime = microtime(true); password_hash($InputUserPassword, (int)$this->AlgoType, ['cost' => $VCost]); $EndTime = microtime(true); } while (($EndTime - $StartTime) < $inTargetTimeToGo); return $VCost; } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77225&edit=1

« previous php.bugs (#218228) next »