Doc #70615 [Opn->Csd]: 72-character password limit

From: Date: Wed, 07 Oct 2015 06:50:13 +0000
Subject: Doc #70615 [Opn->Csd]: 72-character password limit
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12809@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70615&edit=1 ID: 70615 Updated by: sobak@php.net Reported by: dave at qccareerschool dot com Summary: 72-character password limit -Status: Open +Status: Closed Type: Documentation Problem Package: *General Issues PHP Version: 5.6.13 -Assigned To: +Assigned To: sobak Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-10-07 06:49:29] sobak@php.net Automatic comment from SVN on behalf of sobak Revision: http://svn.php.net/viewvc/?view=revision&revision=337962 Log: Make the caution more clear (closes bug #70615) ------------------------------------------------------------------------ [2015-10-06 13:14:38] dave at qccareerschool dot com >Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being >truncated to a maximum length of 72 characters. Oh yes this addresses the issue as I saw it. ------------------------------------------------------------------------ [2015-10-06 08:13:05] sobak@php.net I would say that docs are clear. Current form is good, because we won't have to change the documentation once PASSWORD_DEFAULT value will change. Maybe: > Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being > truncated to a maximum length of 72 characters. is better? Does removing explitic corelation with function parameter make it more readable in any way? ------------------------------------------------------------------------ [2015-10-01 17:52:14] dave at qccareerschool dot com Description: ------------ --- From manual page: http://www.php.net/function.password-hash --- >Caution >Using the PASSWORD_BCRYPT for the algo parameter, will result in the password parameter being >truncated to a maximum length of 72 characters. Since PASSWORD_DEFAULT is currently set to PASSWORD_BCRYPT, does using PASSWORD_DEFAULT for the algo paramater _also_ result in a truncated password? It's not entirely clear. Maybe the section should be reworded to >Caution >Using bcrypt will result in the password parameter being truncated to a maximum length of 72 >characters. or perhaps >Caution >Using PASSWORD_BCRYPT (and, by extension, PASSWORD_DEFAULT) for the algo parameter will result >in the password parameter being truncated to a maximum length of 72 characters. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70615&edit=1

« previous php.doc.bugs (#12809) next »