Re: PHP 7.1 - should we add a random_str() function?

From: Date: Wed, 30 Sep 2015 20:26:05 +0000
Subject: Re: PHP 7.1 - should we add a random_str() function?
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-88583@lists.php.net to get a copy of this message
Hi, Le Wed, 30 Sep 2015 18:15:09 +0200, Scott Arciszewski <scott@paragonie.com> a écrit:
This is probably answerable by a quick yes/no and shouldn't need a ton of bikeshedding, but if that happens anyway I apologize in advance. I think random_bytes() and random_int() are great; they provide a much-needed building block in PHP 7.0. However, I do worry a bit that the most common use for random_int() (generating a random string of a fixed length with a given character set) will be reinvented over and over again, and rarely consistently. I would propose a random_str() function that behaves similar to this userland snippet: http://stackoverflow.com/a/32870871/2224584 Function prototype:
string random_str( int $length, string $charset)
Would return a string or throw an Error|Exception (e.g. invalid input parameters, or the operating system's CSPRNG begins to melt). I can write up an RFC for this, with a patch targeting 7.1, if anyone is interested in it. Scott Arciszewski Chief Development Officer Paragon Initiative Enterprises <https://paragonie.com>
I'm interested, as I generate random strings for default passwords. I can stay with my current system, but it would be sweet to shorten my code a little bit :) Regards.

« previous php.internals (#88583) next »