Bug->Doc #77218 [Opn]: password_hash returns null
| From: | nikic@php.net | Date: | Wed, 02 Jan 2019 13:55:02 +0000 |
| Subject: | Bug->Doc #77218 [Opn]: password_hash returns null | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-16280@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77218&edit=1
ID: 77218
Updated by: nikic@php.net
Reported by: magnar at myrtveit dot com
Summary: password_hash returns null
Status: Open
-Type: Bug
+Type: Documentation Problem
Package: *Encryption and hash functions
Operating System: Any
PHP Version: 7.3.0RC6
Block user comment: N
Private report: N
New Comment:
password_hash() does indeed consistently use null for errors, so this should be adjusted in the
docs, not implementation.
Previous Comments:
------------------------------------------------------------------------
[2018-12-08 06:47:43] yohgaki@php.net
Briefly checked how RETURN_NULL() is used.
Most of them, but password_hash(), return NULL when "empty" result is appropriate, not for
errors.
RETURN_NULL() for invalid algo seems actually a bug.
------------------------------------------------------------------------
[2018-12-01 13:15:59] petk@php.net
Hello, I'm just confirming this issue for now. Yes, the documentation should be probably fixed
from false to null in case of failure such as non existing algorithm. Returning string or null is
more logical in these more recently added functions. Returning mixed value of boolean is much less
logical to expect and understand in such case I think.
------------------------------------------------------------------------
[2018-11-29 08:33:25] magnar at myrtveit dot com
It seems that password_hash returns null on all failures. Here is my test: https://3v4l.org/DMv87
------------------------------------------------------------------------
[2018-11-29 08:26:53] magnar at myrtveit dot com
Description:
------------
From manual page: http://php.net/manual/en/function.password-hash.php
The return value is documented as "Returns the hashed password, or FALSE on failure."
However, password_hash returns null on failure, as is evident from this test: https://3v4l.org/siaNi I am not sure whether password_hash returns
false on other failures.
I don't know whether the issue is with the documentation or with the function.
Test script:
---------------
var_dump(password_hash('foo', -1));
Expected result:
----------------
false (based on the documentation)
Actual result:
--------------
null
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77218&edit=1