Doc #78390 [Ver]: PHP 7.4 now supports string password hash algorithms
| From: | salathe@php.net | Date: | Sun, 11 Aug 2019 22:54:22 +0000 |
| Subject: | Doc #78390 [Ver]: PHP 7.4 now supports string password hash algorithms | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-16878@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78390&edit=1
ID: 78390
Updated by: salathe@php.net
Reported by: beebware at gmail dot com
Summary: PHP 7.4 now supports string password hash algorithms
Status: Verified
Type: Documentation Problem
Package: *Encryption and hash functions
PHP Version: 7.4.0
Assigned To: salathe
Block user comment: N
Private report: N
New Comment:
PHP 7.4 is coming soon (we're at 7.4.0beta2 at the time of writing). It is fine having the new
features/changes for 7.4 documented now. Just remember the changelog sections when documenting
changes.
What we don't want to do is document something bleeding-edge only to have the feature/change
changed in some way and have the documentation be incorrect. This is what can and does happen if we
document changes as soon as they're committed to php-src.
A sensible line in the sand where that is much less likely to happen is feature freeze, which
happens at beta1. Once we've crossed that point we can, with high confidence, say that the
change will be in the GA release. Consequently, it is fine to start documenting the changes fully
expecting them to be in the GA release.
Previous Comments:
------------------------------------------------------------------------
[2019-08-11 22:25:09] girgias@php.net
Honestly no idea, I just know that some were documented while I was updating the French translation
and I followed suit with some of them (e.g. the array_merge ones).
So maybe @salathe what is the official stance on this?
------------------------------------------------------------------------
[2019-08-09 14:02:05] requinix@php.net
So are all 7.4 changes supposed to get documented as they're merged? Because there are all
sorts of changes in the queue that should/would be documented but currently are not...
------------------------------------------------------------------------
[2019-08-09 13:06:00] girgias@php.net
@requinix this is not entirely true, we did already document changes which will happen in PHP 7.4
(see array_merge for example) as these changes may get forgotten when it releases.
Assigning to myself and will have a look next week.
------------------------------------------------------------------------
[2019-08-09 12:43:47] requinix@php.net
7.4 hasn't been released yet. The documentation covers stable releases, not the latest betas.
------------------------------------------------------------------------
[2019-08-09 12:24:23] beebware at gmail dot com
Description:
------------
---
From manual page: https://php.net/function.password-needs-rehash
And https://www.php.net/password_hash
---
Currently reads:
password_hash ( string $password , int $algo [, array $options ] ) : string
password_needs_rehash ( string $hash , int $algo [, array $options ] ) : bool
however, PHP 7.4 has changed the password algorithms to strings so it should be:
password_hash ( string $password , int|string $algo [, array $options ] ) : string
password_needs_rehash ( string $hash , int|string $algo [, array $options ] ) : bool
(or mixed)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78390&edit=1