Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt
| From: | Kamil Tekiela | Date: | Thu, 01 Oct 2026 17:36:54 +0000 |
| Subject: | Re: [RFC] Throw error for passwords longer than 72 bytes in password_hash() with bcrypt | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132762@lists.php.net to get a copy of this message | ||
On Thu, 1 Oct 2026 at 18:15, Matthew Weier O'Phinney
<mweierophinney@gmail.com> wrote:
>
> If a hash already exists from a truncated password, it will continue to validate. The only time
> this would raise the exception or error is when hashing, which will typically be done once, when a
> user registers, or chooses to change their password. Having an error condition here forces the
> application developer to address the truncation issue when storing new hashes only, and won't
> invalidate existing user hashes and login attempts.
Small correction. Rehashing is commonly done during login, not registration..