Bug->Doc #77218 [Opn]: password_hash returns null

From: Date: Wed, 02 Jan 2019 13:55:02 +0000
Subject: Bug->Doc #77218 [Opn]: password_hash returns null
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-16280@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77218&edit=1 ID: 77218 Updated by: nikic@php.net Reported by: magnar at myrtveit dot com Summary: password_hash returns null Status: Open -Type: Bug +Type: Documentation Problem Package: *Encryption and hash functions Operating System: Any PHP Version: 7.3.0RC6 Block user comment: N Private report: N New Comment: password_hash() does indeed consistently use null for errors, so this should be adjusted in the docs, not implementation. Previous Comments: ------------------------------------------------------------------------ [2018-12-08 06:47:43] yohgaki@php.net Briefly checked how RETURN_NULL() is used. Most of them, but password_hash(), return NULL when "empty" result is appropriate, not for errors. RETURN_NULL() for invalid algo seems actually a bug. ------------------------------------------------------------------------ [2018-12-01 13:15:59] petk@php.net Hello, I'm just confirming this issue for now. Yes, the documentation should be probably fixed from false to null in case of failure such as non existing algorithm. Returning string or null is more logical in these more recently added functions. Returning mixed value of boolean is much less logical to expect and understand in such case I think. ------------------------------------------------------------------------ [2018-11-29 08:33:25] magnar at myrtveit dot com It seems that password_hash returns null on all failures. Here is my test: https://3v4l.org/DMv87 ------------------------------------------------------------------------ [2018-11-29 08:26:53] magnar at myrtveit dot com Description: ------------ From manual page: http://php.net/manual/en/function.password-hash.php The return value is documented as "Returns the hashed password, or FALSE on failure." However, password_hash returns null on failure, as is evident from this test: https://3v4l.org/siaNi I am not sure whether password_hash returns false on other failures. I don't know whether the issue is with the documentation or with the function. Test script: --------------- var_dump(password_hash('foo', -1)); Expected result: ---------------- false (based on the documentation) Actual result: -------------- null ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77218&edit=1

« previous php.doc.bugs (#16280) next »