Doc #77218 [Com]: password_hash returns null on failure instead of false as of PHP 7.4

From: Date: Mon, 02 Dec 2019 21:27:54 +0000
Subject: Doc #77218 [Com]: password_hash returns null on failure instead of false as of PHP 7.4
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-17077@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77218&edit=1 ID: 77218 Comment by: weirdan at gmail dot com Reported by: magnar at myrtveit dot com Summary: password_hash returns null on failure instead of false as of PHP 7.4 Status: Open Type: Documentation Problem Package: *Encryption and hash functions PHP Version: 7.3.0 Block user comment: N Private report: N New Comment: > the behavioral change does not affect PHP 7.3, but master only. Ping. Master is 7.4 now and it's still needs to be documented. Previous Comments: ------------------------------------------------------------------------ [2019-02-17 04:08:44] weirdan at gmail dot com > the behavioral change does not affect PHP 7.3, but master only. If there's a behavioral change, it should be mentioned in UPGRADING. 7.4 branch seems to be missing such a note. ------------------------------------------------------------------------ [2019-01-24 19:09:04] cmb@php.net Correction: the behavioral change does not affect PHP 7.3, but master only. The cases which return NULL in PHP 7.3 and before, are according to the general note regarding return values for invalid/unsuitable parameters[1]. In my opinion, password_hash() should *throw* on failure for the same reasons random_bytes() does. [1] <http://php.net/manual/en/functions.internal.php> ------------------------------------------------------------------------ [2019-01-24 18:45:48] cmb@php.net I think that might need discussion on internals@. Anyhow, the status “feedback” is for requesting feedback from the reporter – if no feedback is given after a week, the ticket will automatically be closed with status “no feedback”. ------------------------------------------------------------------------ [2019-01-24 18:10:59] girgias@php.net Is this going to be reverted or should I write a documentation patch? ------------------------------------------------------------------------ [2019-01-02 14:32:38] cmb@php.net @nikic This is true for master, but the code has recently been changed[1], and apparently older versions would have returned FALSE if the underlying hash function failed[2][3]][4]]. So basically, for PHP ≤ 7.3, the function returned FALSE for a failing implementation, and NULL for invalid parameters in combination with a warning (the latter likely according to the general convention to return NULL on ZPP failures). This behavioral change looks rather dangerous to me, since formerly developers who had carefully made sure that they pass valid arguments might have checked for a FALSE return to signal failure. Now they'd get a NULL, which might pass their check. [1] <https://github.com/php/php-src/commit/534df87c9e3c28001986e70844e0ad04e5708d3d> [2] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L492> [3] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L497> [4] <https://github.com/php/php-src/blob/php-7.3.0/ext/standard/password.c#L585> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77218 -- Edit this bug report at https://bugs.php.net/bug.php?id=77218&edit=1

« previous php.doc.bugs (#17077) next »