mirror of
https://github.com/php/php-src.git
synced 2026-04-18 21:41:22 +02:00
openssl_encrypt() currently throws a warning if the $tag out parameter is passed for a non-authenticated cipher. This violates the principle that a function should behave the same if a parameter is not passed, and if the default value is passed for the parameter. I believe this warning should simply be dropped and the $tag be populated with null, as is already the case. Otherwise, it is not possible to use openssl_encrypt() in generic wrapper APIs, that are compatible with both authenticated and non-authenticated encryption. Closes GH-6333.
54 lines
1.9 KiB
PHP
54 lines
1.9 KiB
PHP
--TEST--
|
|
openssl_decrypt() error tests
|
|
--SKIPIF--
|
|
<?php if (!extension_loaded("openssl")) print "skip"; ?>
|
|
--FILE--
|
|
<?php
|
|
$data = "openssl_decrypt() tests";
|
|
$method = "AES-128-CBC";
|
|
$password = "openssl";
|
|
$wrong = base64_encode("wrong");
|
|
$iv = str_repeat("\0", openssl_cipher_iv_length($method));
|
|
|
|
$encrypted = openssl_encrypt($data, $method, $password);
|
|
var_dump($encrypted); /* Not passing $iv should be the same as all-NULL iv, but with a warning */
|
|
var_dump(openssl_encrypt($data, $method, $password, 0, $iv));
|
|
var_dump(openssl_decrypt($encrypted, $method, $wrong));
|
|
var_dump(openssl_decrypt($encrypted, $wrong, $password));
|
|
var_dump(openssl_decrypt($wrong, $method, $password));
|
|
var_dump(openssl_decrypt($wrong, $wrong, $password));
|
|
var_dump(openssl_decrypt($encrypted, $wrong, $wrong));
|
|
var_dump(openssl_decrypt($wrong, $wrong, $wrong));
|
|
var_dump(openssl_decrypt(array(), $method, $password));
|
|
var_dump(openssl_decrypt($encrypted, array(), $password));
|
|
var_dump(openssl_decrypt($encrypted, $method, array()));
|
|
|
|
?>
|
|
--EXPECTF--
|
|
Warning: openssl_encrypt(): Using an empty Initialization Vector (iv) is potentially insecure and not recommended in %s on line %d
|
|
string(44) "yof6cPPH4mLee6TOc0YQSrh4dvywMqxGUyjp0lV6+aM="
|
|
string(44) "yof6cPPH4mLee6TOc0YQSrh4dvywMqxGUyjp0lV6+aM="
|
|
bool(false)
|
|
|
|
Warning: openssl_decrypt(): Unknown cipher algorithm in %s on line %d
|
|
bool(false)
|
|
bool(false)
|
|
|
|
Warning: openssl_decrypt(): Unknown cipher algorithm in %s on line %d
|
|
bool(false)
|
|
|
|
Warning: openssl_decrypt(): Unknown cipher algorithm in %s on line %d
|
|
bool(false)
|
|
|
|
Warning: openssl_decrypt(): Unknown cipher algorithm in %s on line %d
|
|
bool(false)
|
|
|
|
Warning: openssl_decrypt() expects parameter 1 to be string, array given in %s on line %d
|
|
NULL
|
|
|
|
Warning: openssl_decrypt() expects parameter 2 to be string, array given in %s on line %d
|
|
NULL
|
|
|
|
Warning: openssl_decrypt() expects parameter 3 to be string, array given in %s on line %d
|
|
NULL
|