Re: crypt() should raise error without 2nd parameter

From: Date: Thu, 08 Aug 2013 04:44:59 +0000
Subject: Re: crypt() should raise error without 2nd parameter
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-68426@lists.php.net to get a copy of this message
Hi Hannes, On Thu, Aug 8, 2013 at 1:22 PM, Hannes Magnusson <hannes.magnusson@gmail.com > wrote: > On Wed, Aug 7, 2013 at 6:20 PM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > > Hi all, > > > > It seems there are 2 options for master branch when crypt()'s 2nd > parameter > > is omitted. > > > > - raise E_DEPRECIATED that advice use of stronger salt or > password_hash() > > and make 2nd parameter required for future release. > > - make crypt() use stronger default salt/hash w/o error > > > > Since password_hash() is supposed to do better job, first option seems > > better to me. > > > Deprecating it means it will be removed in the future. > > Please leave the function alone. This should be solved with education, > not a gun to peoples head. This would be third option. I agree that good documentation is always good. E_NOTICE might be better as E_DEPRECIATED means obsolete. I'll write RFC for voting later. Please comment so that your comments are in RFC. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#68426) next »