Skip to content

Conversation

@javiereguiluz
Copy link
Member

Q A
Branch? 2.7
Bug fix? no
New feature? no
BC breaks? no
Deprecations? no
Tests pass? yes
Fixed tickets -
License MIT
Doc PR -

As you can see in the source code of the PHP uniqid() function when you don't pass true as the second argument, PHP sleeps the application for 1 microsecond (usleep(1))

Symfony uses true almost everywhere, but there are still some places (mostly in bundles) where this is not the case.

@xarem
Copy link

xarem commented Oct 3, 2016

Hi @javiereguiluz

i found some other usages without more entropy option:

@javiereguiluz
Copy link
Member Author

@xarem thanks! I've updated this PR and created another one (#20137) for the change related to the Cache component.

@nicolas-grekas
Copy link
Member

👍

@fabpot
Copy link
Member

fabpot commented Oct 3, 2016

Thank you @javiereguiluz.

fabpot added a commit that referenced this pull request Oct 3, 2016
This PR was squashed before being merged into the 2.7 branch (closes #20132).

Discussion
----------

Use "more entropy" option for uniqid()

| Q             | A
| ------------- | ---
| Branch?       | 2.7
| Bug fix?      | no
| New feature?  | no
| BC breaks?    | no
| Deprecations? | no
| Tests pass?   | yes
| Fixed tickets | -
| License       | MIT
| Doc PR        | -

As you can see in [the source code of the PHP uniqid() function](https://github.com/php/php-src/blob/1c295d4a9ac78fcc2f77d6695987598bb7abcb83/ext/standard/uniqid.c#L68) when you don't pass `true` as the second argument, PHP sleeps the application for 1 microsecond (`usleep(1)`)

Symfony uses `true` almost everywhere, but there are still some places (mostly in bundles) where this is not the case.

Commits
-------

4403e28 Use "more entropy" option for uniqid()
@fabpot fabpot closed this Oct 3, 2016
fabpot added a commit that referenced this pull request Oct 3, 2016
This PR was merged into the 3.2-dev branch.

Discussion
----------

Add "more entropy" to every uniqid() call

| Q             | A
| ------------- | ---
| Branch?       | master
| Bug fix?      | no
| New feature?  | no
| BC breaks?    | no
| Deprecations? | no
| Tests pass?   | yes
| Fixed tickets | -
| License       | MIT
| Doc PR        | -

Same as #20132 but for the master branch

Commits
-------

50a8c1f Add "more entropy" to every uniqid() call
This was referenced Oct 3, 2016
fabpot added a commit that referenced this pull request Jul 10, 2024
This PR was merged into the 5.4 branch.

Discussion
----------

use more entropy with uniqid()

| Q             | A
| ------------- | ---
| Branch?       | 5.4
| Bug fix?      | no
| New feature?  | no
| Deprecations? | no
| Issues        |
| License       | MIT

It looked like using `uniqid()` without opting for more entropy slipped in after #20132 and #20137.

Commits
-------

770e7fc use more entropy with uniqid()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants