Remove deprecated utf8_encode() from the pwned-password check - #568
Open
thisismyurl wants to merge 1 commit into
Open
Remove deprecated utf8_encode() from the pwned-password check#568thisismyurl wants to merge 1 commit into
thisismyurl wants to merge 1 commit into
Conversation
utf8_encode() is deprecated as of PHP 8.2. Here it wraps strtoupper( sha1( $password ) ), which is always a pure-ASCII hex string, so the call is a no-op: utf8_encode() returns that string unchanged. Dropping it removes the deprecation notice with no change to $password_hash or the downstream HIBP range lookup.
Contributor
There was a problem hiding this comment.
Pull request overview
Removes a PHP 8.2 deprecation warning by dropping utf8_encode() from the Have I Been Pwned password-range check, where the input is already an ASCII-only SHA1 hex string and the call is therefore a no-op.
Changes:
- Remove deprecated
utf8_encode()wrapping aroundstrtoupper( sha1( $password ) )inSecurity::check_password_pwnd_status().
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PHP 8.2 housekeeping.
Security::check_password_pwnd_status()wraps its hash inutf8_encode(), which is deprecated as of PHP 8.2. Here the argument isstrtoupper( sha1( $password ) ), which is always a pure-ASCII hex string, soutf8_encode()returns it unchanged and the call is a no-op.Dropping it removes the deprecation notice with no change to
$password_hashor the downstream HIBP range lookup. I went with removing it rather than swapping inmb_convert_encoding(), since there's nothing to convert. Happy to use the wrapper instead if you'd prefer.Clean codebase to work in, thanks for open-sourcing the theme base.
(full disclosure: AI helped me spot this; the change and this note are mine.)