Doc #76716 [Opn->Csd]: PASSWORD_ARGON2I not always being available not documented.
| From: | cmb@php.net | Date: | Tue, 07 Aug 2018 21:36:59 +0000 |
| Subject: | Doc #76716 [Opn->Csd]: PASSWORD_ARGON2I not always being available not documented. | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15950@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76716&edit=1
ID: 76716
Updated by: cmb@php.net
Reported by: phpdoc at mail dot my1 dot info
Summary: PASSWORD_ARGON2I not always being available not
documented.
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
Operating System: -
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2018-08-07 21:36:08] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=345440
Log: Fix #76716: PASSWORD_ARGON2I not always being available not documented
------------------------------------------------------------------------
[2018-08-07 12:58:54] phpdoc at mail dot my1 dot info
Description:
------------
---
From manual page: http://www.php.net/function.password-hash
---
According to the relevant RFC at [1] Argon2i via password_hash() is not only optional but needs
extra work for inclusion into the respective PHP installation unless one uses a precompiled build
with everything inside (e.g. PHP's official Windows builds), this leads to it being unavailable
at some webhosters which, while not being really great, leads to a whole different problem.
one cannot expect Argon2i to be available just because PHP is 7.2 (and Argon2id on 7.3
respectively), meaning users need to know that the PHP Version is NOT the correct way to judge
Argon2 availability, and that they will need to check for it even if the PHP is new enough, and
either fail gracefully or at least fall back to default.
[1]
https://wiki.php.net/rfc/argon2_password_hash
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76716&edit=1