Re: [RFC][VOTE] Improve hash_hkdf() parameter
| From: | Yasuo Ohgaki | Date: | Wed, 12 Apr 2017 23:07:19 +0000 |
| Subject: | Re: [RFC][VOTE] Improve hash_hkdf() parameter | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-98778@lists.php.net to get a copy of this message | ||
Hi Joe,
On Wed, Apr 12, 2017 at 7:46 PM, Joe Watkins <pthreads@pthreads.org> wrote:
> This RFC was left open for 5 days past the end of voting as declared on
> the RFC.
>
Thank you, I forgot about this.
IMHO, it's a shame for us we should have inconsistent and insecure function
signature for a new function.
I'm going to update the manual to add warning notes and example usages
like advanced CRFS token dedicated for specific URL with expiration time.
I can think of length option only usage, but I cannot think usage that could
be useful for majority of PHP users like advanced CSRF token.
Andrey,
Could you give us some length only and length/info only example
that could be useful for most PHP users.
It should be safe and recommended usage.
I suppose you should have some good examples.
Thank you.
--
Yasuo Ohgaki
yohgaki@ohgaki.net