Hi all,

On Sat, Jan 10, 2015 at 1:45 AM, Anthony Ferrara <ircmax...@gmail.com>
wrote:

> It's worth nothing that failing is the currently documented behavior:
> http://php.net/crypt
>
> Therefore, I'm suggesting we add an E_DEPRECATED error when we detect
> an invalid STD_DES salt but still execute the fallback:
> https://github.com/php/php-src/pull/989
>
> Then in a future version (7.1, 8, whatever) remove the fallback and
> keep the error along with returning a failure indication (*0).
>
> I'm open to tweaking the error message, and possibly changing to
> E_WARNING if people think it's worth it.
>
> Thoughts?
>

+1 for merging it as bug fix.

Regards,

--
Yasuo Ohgaki
yohg...@ohgaki.net

Reply via email to