[php-src] Issue #8397: crypt() accepts invalid characters in salt
| From: | martenlehmann | Date: | Tue, 19 Apr 2022 13:28:10 +0000 |
| Subject: | [php-src] Issue #8397: crypt() accepts invalid characters in salt | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-241073@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8397
Comment Author: martenlehmann
There is surely a benefit of PHP's cross-platform implementation of
crypt(),
because otherwise this function wouldn't be available on non-UNIX platforms. In Python you
would use the [passlib](https://pypi.org/project/passlib/) password hashing library, which is not
part of the standard library and the standard
[crypt](https://docs.python.org/3/library/crypt.html#module-crypt) module simply wouldn't work
on eg. Windows.
What I'm missing in PHP, however, is a way to explicitly make use of and test against the
OS's crypt() function.