Doc #70615 [Opn]: 72-character password limit
| From: | dave at qccareerschool dot com | Date: | Tue, 06 Oct 2015 13:14:39 +0000 |
| Subject: | Doc #70615 [Opn]: 72-character password limit | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12806@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70615&edit=1
ID: 70615
User updated by: dave at qccareerschool dot com
Reported by: dave at qccareerschool dot com
Summary: 72-character password limit
Status: Open
Type: Documentation Problem
Package: *General Issues
PHP Version: 5.6.13
Block user comment: N
Private report: N
New Comment:
>Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being
>truncated to a maximum length of 72 characters.
Oh yes this addresses the issue as I saw it.
Previous Comments:
------------------------------------------------------------------------
[2015-10-06 08:13:05] sobak@php.net
I would say that docs are clear. Current form is good, because we won't have to change the
documentation once PASSWORD_DEFAULT value will change. Maybe:
> Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being
> truncated to a maximum length of 72 characters.
is better? Does removing explitic corelation with function parameter make it more readable in any
way?
------------------------------------------------------------------------
[2015-10-01 17:52:14] dave at qccareerschool dot com
Description:
------------
---
From manual page: http://www.php.net/function.password-hash
---
>Caution
>Using the PASSWORD_BCRYPT for the algo parameter, will result in the password parameter being
>truncated to a maximum length of 72 characters.
Since PASSWORD_DEFAULT is currently set to PASSWORD_BCRYPT, does using PASSWORD_DEFAULT for the algo
paramater _also_ result in a truncated password? It's not entirely clear. Maybe the section
should be reworded to
>Caution
>Using bcrypt will result in the password parameter being truncated to a maximum length of 72
>characters.
or perhaps
>Caution
>Using PASSWORD_BCRYPT (and, by extension, PASSWORD_DEFAULT) for the algo parameter will result
>in the password parameter being truncated to a maximum length of 72 characters.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70615&edit=1