Doc #70615 [Opn->Csd]: 72-character password limit
| From: | sobak@php.net | Date: | Wed, 07 Oct 2015 06:50:13 +0000 |
| Subject: | Doc #70615 [Opn->Csd]: 72-character password limit | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12809@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70615&edit=1
ID: 70615
Updated by: sobak@php.net
Reported by: dave at qccareerschool dot com
Summary: 72-character password limit
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: *General Issues
PHP Version: 5.6.13
-Assigned To:
+Assigned To: sobak
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2015-10-07 06:49:29] sobak@php.net
Automatic comment from SVN on behalf of sobak
Revision: http://svn.php.net/viewvc/?view=revision&revision=337962
Log: Make the caution more clear (closes bug #70615)
------------------------------------------------------------------------
[2015-10-06 13:14:38] dave at qccareerschool dot com
>Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being
>truncated to a maximum length of 72 characters.
Oh yes this addresses the issue as I saw it.
------------------------------------------------------------------------
[2015-10-06 08:13:05] sobak@php.net
I would say that docs are clear. Current form is good, because we won't have to change the
documentation once PASSWORD_DEFAULT value will change. Maybe:
> Using the PASSWORD_BCRYPT as the algorithm, will result in the password parameter being
> truncated to a maximum length of 72 characters.
is better? Does removing explitic corelation with function parameter make it more readable in any
way?
------------------------------------------------------------------------
[2015-10-01 17:52:14] dave at qccareerschool dot com
Description:
------------
---
From manual page: http://www.php.net/function.password-hash
---
>Caution
>Using the PASSWORD_BCRYPT for the algo parameter, will result in the password parameter being
>truncated to a maximum length of 72 characters.
Since PASSWORD_DEFAULT is currently set to PASSWORD_BCRYPT, does using PASSWORD_DEFAULT for the algo
paramater _also_ result in a truncated password? It's not entirely clear. Maybe the section
should be reworded to
>Caution
>Using bcrypt will result in the password parameter being truncated to a maximum length of 72
>characters.
or perhaps
>Caution
>Using PASSWORD_BCRYPT (and, by extension, PASSWORD_DEFAULT) for the algo parameter will result
>in the password parameter being truncated to a maximum length of 72 characters.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70615&edit=1