Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt

From: Date: Thu, 01 Oct 2026 17:36:54 +0000
Subject: Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
References: 1 2 3 4 5 6 7 8 9 10 11 12 13  Groups: php.internals 
Request: Send a blank email to internals+get-132762@lists.php.net to get a copy of this message
On Thu, 1 Oct 2026 at 18:15, Matthew Weier O'Phinney <mweierophinney@gmail.com> wrote: > > If a hash already exists from a truncated password, it will continue to validate. The only time > this would raise the exception or error is when hashing, which will typically be done once, when a > user registers, or chooses to change their password. Having an error condition here forces the > application developer to address the truncation issue when storing new hashes only, and won't > invalidate existing user hashes and login attempts. Small correction. Rehashing is commonly done during login, not registration..

« previous php.internals (#132762) next »