On Thu, Oct 1, 2026, at 00:11, Derick Rethans wrote:
> The problem for me is that this a scary BC break.

Yes. I think the BC break is worth it, but I understand how opinions may differ 
on this.

> If this changes to an Exception, then they no longer can [login]

Sort of. I intentionally only proposed changing password_hash and not 
password_verify. However, password_hash may still be used in the login flow, so 
login may fail for long passwords but this depends on the application logic.

Is there anything you could think of that would improve the situation but would 
potentially have your approval? First switch the default password hash from 
bcrypt to something else? Increase the length at which an exception is thrown? 
Not an exception but a warning?

Regards,

Sjoerd

Reply via email to