代码之家  ›  专栏  ›  技术社区  ›  Craig Francis

确定php7.4中的默认密码

  •  -1
  • Craig Francis  · 技术社区  · 6 年前

    在使用前 password_hash() ,我检查 PASSWORD_DEFAULT === PASSWORD_BCRYPT

    我只是先通过一个快速散列来传递它,因为bcrypt有一个空字符和超过72个字符的密码的问题( more info ,和 a different example ).

    但是在php7.4中,常量 现在设置为 NULL .

    密码哈希()

    0 回复  |  直到 6 年前
        1
  •  0
  •   Rain cheladon    6 年前

    编辑

    PASSWORD_DEFAULT === PASSWORD_BCRYPT

    https://3v4l.org/nN4Qi


    password_hash 两次。一种更好更快的方法是使用 Bcrypt 并对照检查 PASSWORD_DEFAULT password_needs_rehash

    在php5.5.0中,bcrypt算法是默认的

    $hash = '$2y$10$ra4VedcLU8bv3jR0AlpEau3AZevkQz4Utm7F8EqUNE0Jqx0s772NG'; // Bcrypt hash
    
    // if it doesn't need rehash then the default algo is absolutely Bcrypt
    if (! password_needs_rehash($hash, PASSWORD_DEFAULT)) {
        // do some clean up
    }
    

    注意 :确保哈希值($hash)具有中提供的相同成本 password_needs_rehash 的第三个参数,否则它将认为哈希过期,并且由于成本已更改而需要重新计算。

        2
  •  2
  •   Dharman vijay    6 年前

    但我认为这是一个有趣的函数。这不是一个大问题,因为哈希本身包含一个标识符,告诉我们使用了哪个哈希算法。这里需要注意的是 PASSWORD_DEFAULT 是一个 . 常数不变。

    password_get_info()

    $hashInfo = password_get_info(password_hash('pass', PASSWORD_DEFAULT, [ 'cost' => 4 ] ));
    echo $hashInfo['algo']; // should return either 1 or 2y
    
    if($hashInfo['algo'] === PASSWORD_BCRYPT) {
        // will be true for PHP <= 7.4
    }
    
    推荐文章