mirror of
https://github.com/phpbb/phpbb.git
synced 2025-06-28 14:18:52 +00:00
[ticket/16266] Fix argon2 driver issue for Sodium implementation
PHPBB3-16266
This commit is contained in:
parent
230472de45
commit
186a3d40c6
2 changed files with 27 additions and 4 deletions
|
@ -37,11 +37,22 @@ class argon2i extends base_native
|
|||
{
|
||||
parent::__construct($config, $helper);
|
||||
|
||||
// Don't allow cost factors to be below default settings
|
||||
if ($this->is_sodium())
|
||||
{
|
||||
// For Sodium implementation, set special cost factor values (since PHP 7.4)
|
||||
// See https://wiki.php.net/rfc/sodium.argon.hash and PHPBB3-16266
|
||||
$this->memory_cost = max($memory_cost, 256*1024);
|
||||
$this->threads = 1;
|
||||
$this->time_cost = max($time_cost, 3);
|
||||
}
|
||||
else
|
||||
{
|
||||
// Otherwise don't allow cost factors to be below default settings
|
||||
$this->memory_cost = max($memory_cost, 1024);
|
||||
$this->threads = max($threads, 2);
|
||||
$this->time_cost = max($time_cost, 2);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* {@inheritdoc}
|
||||
|
|
|
@ -57,6 +57,18 @@ abstract class base_native extends base
|
|||
return password_hash($password, $this->get_algo_value(), $this->get_options());
|
||||
}
|
||||
|
||||
/**
|
||||
* Check if Sodium implementation for argon2 algorithm is being used
|
||||
*
|
||||
* @link https://wiki.php.net/rfc/sodium.argon.hash
|
||||
*
|
||||
* @return bool
|
||||
*/
|
||||
public function is_sodium()
|
||||
{
|
||||
return defined('PASSWORD_ARGON2_PROVIDER') && PASSWORD_ARGON2_PROVIDER == 'sodium';
|
||||
}
|
||||
|
||||
/**
|
||||
* {@inheritdoc}
|
||||
*/
|
||||
|
|
Loading…
Add table
Reference in a new issue