Doc #77218 [Opn]: password_hash returns null
Edit report at https://bugs.php.net/bug.php?id=77218&edit=1
ID: 77218
Updated by: cmb@php.net
Reported by: magnar at myrtveit dot com
Summary: password_hash returns null
Status: Open
Type: Documentation Problem
Package: *Encryption and hash functions
Operating System: Any
PHP Version: 7.3.0RC6
Block user comment: N
Private report: N
New Comment:
@nikic This is true for master, but the code has recently been
changed[1], and apparently older versions would have returned
FALSE if the underlying hash function failed[2][3]][4]]. So
basically, for PHP ⤠7.3, the function returned FALSE for a
failing implementation, and NULL for invalid parameters in
combination with a warning (the latter likely according to the
general convention to return NULL on ZPP failures).
This behavioral change looks rather dangerous to me, since
formerly developers who had carefully made sure that they pass
valid arguments might have checked for a FALSE return to signal
failure. Now they'd get a NULL, which might pass their check.
[1] <https://github.com/php/php-src/commit/534df87c9e3c28001986e70844e0ad04e5708d3d>
[2] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L492>
[3] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L497>
[4] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L585>
Previous Comments:
------------------------------------------------------------------------
[2019-01-02 13:55:02] nikic@php.net
password_hash() does indeed consistently use null for errors, so this should be adjusted in the
docs, not implementation.
------------------------------------------------------------------------
[2018-12-08 06:47:43] yohgaki@php.net
Briefly checked how RETURN_NULL() is used.
Most of them, but password_hash(), return NULL when "empty" result is appropriate, not for
errors.
RETURN_NULL() for invalid algo seems actually a bug.
------------------------------------------------------------------------
[2018-12-01 13:15:59] petk@php.net
Hello, I'm just confirming this issue for now. Yes, the documentation should be probably fixed
from false to null in case of failure such as non existing algorithm. Returning string or null is
more logical in these more recently added functions. Returning mixed value of boolean is much less
logical to expect and understand in such case I think.
------------------------------------------------------------------------
[2018-11-29 08:33:25] magnar at myrtveit dot com
It seems that password_hash returns null on all failures. Here is my test: https://3v4l.org/DMv87
------------------------------------------------------------------------
[2018-11-29 08:26:53] magnar at myrtveit dot com
Description:
------------
From manual page: http://php.net/manual/en/function.password-hash.php
The return value is documented as "Returns the hashed password, or FALSE on failure."
However, password_hash returns null on failure, as is evident from this test: https://3v4l.org/siaNi I am not sure whether password_hash returns
false on other failures.
I don't know whether the issue is with the documentation or with the function.
Test script:
---------------
var_dump(password_hash('foo', -1));
Expected result:
----------------
false (based on the documentation)
Actual result:
--------------
null
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77218&edit=1
Thread (10 messages)