note 55013 modified in function.mt-rand by bjori
| From: | bjori@php.net | Date: | Sun, 16 Apr 2006 12:24:19 +0000 |
| Subject: | note 55013 modified in function.mt-rand by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-108252@lists.php.net to get a copy of this message | ||
You really shouldn't generate a number to determine the _type_ of the char, then the char
itself. If security is an issue for you, and you want to maintain as much entropy as possible, you
should use a function similar to the one below. Since this seems to be getting repeated
over-and-over, I explained (beat into the ground?) the issue on http://www.codeaholics.com/randomCode.php
The code:
<?php
////
// Returns a random code of the specified length, containing characters that are
// equally likely to be any of the digits, uppercase letters, or lowercase letters.
//
// The default length of 10 provides 839299365868340224 (62^10) possible codes.
//
// NOTE: Do not call wt_srand(). It is handled automatically in PHP 4.2.0 and above
// and any additional calls are likely to DECREASE the randomness.
////
function randomCode($length=10){
$retVal = "";
while(strlen($retVal) < $length){
$nextChar = mt_rand(0, 61); // 10 digits + 26 uppercase + 26 lowercase = 62 chars
if(($nextChar >=10) && ($nextChar < 36)){ // uppercase letters
$nextChar -= 10; // bases the number at 0 instead of 10
$nextChar = chr($nextChar + 65); // ord('A') == 65
} else if($nextChar >= 36){ // lowercase letters
$nextChar -= 36; // bases the number at 0 instead of 36
$nextChar = chr($nextChar + 97); // ord('a') == 97
} else { // 0-9
$nextChar = chr($nextChar + 48); // ord('0') == 48
}
$retVal .= $nextChar;
}
return $retVal;
}
?>
--was--
Donald at design's implementation repeats the error of demographica. You really shouldn't
generate a number to determine the _type_ of the char, then the char itself. If security is an
issue for you, and you want to maintain as much entropy as possible, you should use a function
similar to the one below. Since this seems to be getting repeated over-and-over, I explained (beat
into the ground?) the issue on http://www.codeaholics.com/randomCode.php
The code:
<?php
////
// Returns a random code of the specified length, containing characters that are
// equally likely to be any of the digits, uppercase letters, or lowercase letters.
//
// The default length of 10 provides 839299365868340224 (62^10) possible codes.
//
// NOTE: Do not call wt_srand(). It is handled automatically in PHP 4.2.0 and above
// and any additional calls are likely to DECREASE the randomness.
////
function randomCode($length=10){
$retVal = "";
while(strlen($retVal) < $length){
$nextChar = mt_rand(0, 61); // 10 digits + 26 uppercase + 26 lowercase = 62 chars
if(($nextChar >=10) && ($nextChar < 36)){ // uppercase letters
$nextChar -= 10; // bases the number at 0 instead of 10
$nextChar = chr($nextChar + 65); // ord('A') == 65
} else if($nextChar >= 36){ // lowercase letters
$nextChar -= 36; // bases the number at 0 instead of 36
$nextChar = chr($nextChar + 97); // ord('a') == 97
} else { // 0-9
$nextChar = chr($nextChar + 48); // ord('0') == 48
}
$retVal .= $nextChar;
}
return $retVal;
}
?>
http://php.net/manual/en/function.mt-rand.php