|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #65501 uniqid(): More entropy parameter should be true by default
Submitted: 2013-08-22 10:51 UTC Modified: 2014-01-26 21:54 UTC
Avg. Score:2.0 ± 1.0
Reproduced:0 of 0 (0.0%)
From: Assigned: yohgaki (profile)
Status: Closed Package: Unknown/Other Function
PHP Version: Irrelevant OS: any
Private report: No CVE-ID: None
 [2013-08-22 10:51 UTC]
uniqid()'s 2nd parameter(more entropy) is optional and false by default.

Without more entropy, uniqid() may produce non unique id even if the name states 
it. This could be security issue under certain cases.

Making it true by default would not break any apps, therefore it should be true 
by default.


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2013-08-22 10:54 UTC]
-Assigned To: +Assigned To: yohgaki
 [2013-08-22 10:54 UTC]
I think uniqid() should have "more entropy" parameter first place. Since we have 
it, we should provide better default.
 [2014-01-26 21:54 UTC]
-Status: Assigned +Status: Closed -Type: Feature/Change Request +Type: Documentation Problem
 [2014-01-26 21:54 UTC]
Made a doc issue.
Warning is added to the doc.
PHP Copyright © 2001-2021 The PHP Group
All rights reserved.
Last updated: Fri Sep 24 00:03:36 2021 UTC