Re: crypt() BC issue
| From: | Pierre Joye | Date: | Tue, 22 Jul 2014 03:12:38 +0000 |
| Subject: | Re: crypt() BC issue | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75811@lists.php.net to get a copy of this message | ||
Hi Yasuo,
On Tue, Jul 22, 2014 at 5:00 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi Anthony,
>
> On Mon, Jul 21, 2014 at 11:32 PM, Anthony Ferrara <ircmaxell@gmail.com>
> wrote:
>
>> > E_NOTICE for password larger than 72 is mandatory. Current
>> password_hash()
>> > works without any sign of problem even if it may not be working as
>> > authentication.
>> > I'll add E_NOTICE as bug fix if there aren't any more comments.
>>
>> Could you please not.
>>
>> I have asked you to draft an RFC to justify what you intend to do
>> (documentation, errors, etc) so that we may discuss it better. There
>> is not a single person in this thread who has said "I think a notice
>> is a good idea" except you. Yet you insist on just adding it as a "bug
>> fix". Could you please just slow down, and write out the explanations
>> so that we can have a meangingful discussion instead of just rushing
>> through to commit ignoring what everyone is saying?
>>
>
> I see you and Andrey against to have E_NOTICE for password_hash().
> There are only 2 persons to be correct. I don't know about IRC since I
> don't it at all.
I do not see any discussion about that on IRC, but I would rather not
add it either. It brings little but more confusions.
I would suggest to do what Anthony suggested and we will see the outcome.
Cheers,