PHP password_needs_rehash() Function

PHP 密码散列算法PHP Password Hashing Algorithms

The password_hash() function is used to detect whether a hash value matches the specified options.

PHP Version Requirements: PHP 5 >= 5.5.0, PHP 7

Syntax

bool password_needs_rehash ( string $hash , int $algo [, array $options ] )

Parameter Description:

  • hash: A hash value created by password_hash().
  • algo: A password algorithm constant used to indicate the algorithm when hashing passwords.
  • options: An associative array containing options. Currently supports two options: salt, the salt (interference string) added when hashing the password, and cost, which indicates the number of recursion layers of the algorithm. Examples of these two values can be found on the crypt() page. If omitted, a random salt value and default cost will be used.

Return Value

This function checks whether the specified hash value implements the provided algorithm and options. If not, the hash value needs to be regenerated.

Examples

password_needs_rehash() Usage

<?php $password = 'rasmuslerdorf'; $hash = '$2y$10$YCFsG6elYca568hBi2pZ0.3LDL5wjgxct1N8w/oLR/jfHsiQwCqTS'; //When hardware performance improves, the cost parameter can be modified again. $options = array('cost' => 11); //Verify the stored hash against the plaintext password. if (password_verify($password, $hash)) { //Detect whether there is a newer available hashing algorithm. //Or the cost changes. if (password_needs_rehash($hash, PASSWORD_DEFAULT, $options)) { //If so, create a new hash and replace the old one. $newHash = password_hash($password, PASSWORD_DEFAULT, $options); } //Log the user in. } ?>

PHP 密码散列算法PHP Password Hashing Algorithms

Other Extensions