note 32698 added to function.mt-rand
| From: | jsheets at shadonet dot com | Date: | Wed, 04 Jun 2003 18:49:20 +0000 |
| Subject: | note 32698 added to function.mt-rand | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49732@lists.php.net to get a copy of this message | ||
The following function will create a random base64 encoded key, this is very useful for password
reset schemes or anything where you want a random string. To compare the string either compare the
base64 encoded value or base64_decode it and compare that.
I do not use md5 because md5 results in only 1-9 and a-z in the string or 32^36 possibilities, by
using the extended ASCII table and shuffling the array I am able to get a minimum of 32^127
possibilities with a 32 character string, using a longer string will make your value harder to guess
still. A lot of machiens will have 32^255 possibilities in a decoded string.
function MakeResetKey($min_length = 32, $max_length = 64)
{
$key = '';
// build range and shuffle range using ASCII table
for ($i=0; $i<=255; $i++) {
$range[] = chr($i);
}
// shuffle our range 3 times
for ($i=0; $i<=3; $i++) {
shuffle($range);
}
// loop for random number generation
for ($i = 0; $i < mt_rand($min_length, $max_length); $i++) {
$key .= $range[mt_rand(0, count($range))];
}
$return = base64_encode($key);
if (!empty($return)) {
return $return;
} else {
return 0;
}
}
----
Manual Page -- http://www.php.net/manual/en/function.mt-rand.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32698
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32698&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32698&report=yes