[php-src] Issue #8397: crypt() accepts invalid characters in salt
| From: | cmb69 | Date: | Tue, 19 Apr 2022 10:58:17 +0000 |
| Subject: | [php-src] Issue #8397: crypt() accepts invalid characters in salt | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-241070@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8397
Comment Author: cmb69
Well, PHP's implementation follows the [informal
specification](https://akkadia.org/drepper/SHA-crypt.txt); actually, the PHP implementation is
closely based on the given implementation (it might be identical). And that specification does not
apply base64-like encoding to the salt when producing the result string.
I think not base64-like encoding the salt is somewhat strange, but I don't think we can change
that for BC reasons. Not sure what to do; maybe documenting the behavior explicitly is the best
solution for now. That might require users to pass in a properly encoded salt, what obviously would
reduce the entropy, but that may not be a problem in practice.