Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash
| From: | Anton Smirnov | Date: | Tue, 06 Oct 2026 08:13:00 +0000 |
| Subject: | Re: [RFC] Add PASSWORD_BCRYPT_SHA256 to password_hash | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-132803@lists.php.net to get a copy of this message | ||
On 05/10/2026 16:38, Tim Düsterhus wrote:
roundsandcostare the same thing. The format calls itrounds, but the PHP API calls itcost. Keepingcoston the PHP API makes sense to me for consistency withPASSWORD_BCRYPT, even if it is inconsistent with the hash string. Thank you for the explanation. This inconsistency made me believe there may be several rounds of sha256 too