hash_equals

FunctionMisc changes in PHP 8.2

Timing attack safe string comparison.

PHP 5.3-5.5
PHP 5.6
Added
PHP 7
PHP 8.0
Improved
PHP 8.1
PHP 8.2
Changed
PHP 8.3
PHP 8.4
PHP 8.5
PHP 8.6

hash_equals Function synopsis

hash_equals(string $known_string, string $user_string): bool

Parameters

$known_string

Typestring

The known string that must be kept secret.

$user_string

Typestring

The user-supplied string to compare against.

Return value

Typebool

Returns true when the two strings are equal, false otherwise.

Changes to the hash_equals Function

PHP 8.2

PHP 8.0

  • Return type added: bool
  • Parameter type added for parameter #1 ($known_string): string
  • Parameter type added for parameter #2 ($user_string): string
- hash_equals($known_string, $user_string)
+ hash_equals(string $known_string, string $user_string): bool

PHP 5.6

  • Function added

hash_equals Function Availability

PHP VersionAvailability
PHP 8.6Upcoming Release Yes
PHP 8.5Supported (Latest) Yes
PHP 8.4Supported Yes
PHP 8.3Security-Fixes Only Yes
PHP 8.2Security-Fixes Only Yes
PHP 8.1Unsupported Yes
PHP 8.0Unsupported Yes
PHP 7.4Unsupported Yes
PHP 7.3Unsupported Yes
PHP 7.2Unsupported Yes
PHP 7.1Unsupported Yes
PHP 7.0Unsupported Yes
PHP 5.6Unsupported Yes
PHP 5.5Unsupported No
PHP 5.4Unsupported No
PHP 5.3Unsupported No