[stable17] expose Argon2 options (as we did for bcrypt)#19095
[stable17] expose Argon2 options (as we did for bcrypt)#19095
Conversation
| /** | ||
| * The allowed maximum memory in KiB to be used by the algorithm for computing a | ||
| * hash. The smallest possible value is 8. Values that undershoot the minimum | ||
| * will be ignored in favor of the default. |
There was a problem hiding this comment.
Shall we just add a big note here to only set this if you are on php7.2 or later?
There was a problem hiding this comment.
Not necessary – apart of using the constant. Code wouldn't pick Argon2 if it was not available. There are actually PHP 7.2 builds without Argon2, you cannot just rely on the version.
There was a problem hiding this comment.
Then reword it differently. But setting those options if you don't have argon2 basically will do 💥 we just need to be sure nobody does that
There was a problem hiding this comment.
Then reword it differently.
Will do
ut setting those options if you don't have argon2 basically will do boom we just need to be sure nobody does that
no, nothing will happen when these options are set. Unless you mean the constants specifically. I take them all out.
There was a problem hiding this comment.
I meant the constants.
I'm fine with leaving the constants in. Because they might change over time. And if people set them without argon2 support they will know soon enough. But we should just have a clear warning :)
There was a problem hiding this comment.
Because they might change over time
They actually did already, afaik. But anyway, setting there the constants does not make sense anyway, as this is implicit. A URL is given to find more info and also that we rely on defaults. Should be sufficient.
|
@rullzer @ChristophWurst do you approve the sample config refinements? I'd bring it to all other branches as well (18+ can go without the stress on 7.2). |
Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
Co-Authored-By: kesselb <mail@danielkesselberg.de> Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
Signed-off-by: Arthur Schiwon <blizzz@arthur-schiwon.de>
423f9e0 to
518789a
Compare
|
squashed, rebased and also applied to the 16 backport |
backport of #19023