> */ protected $targetFunctions = [ 'password_hash' => [ 'position' => 2, 'name' => 'algo', ], 'password_needs_rehash' => [ 'position' => 2, 'name' => 'algo', ], ]; /** * Tokens types which indicate that the parameter passed is not the PHP native constant. * * @since 9.3.0 * * @var array */ private $invalidTokenTypes = [ \T_NULL => true, \T_TRUE => true, \T_FALSE => true, \T_LNUMBER => true, \T_DNUMBER => true, \T_CONSTANT_ENCAPSED_STRING => true, \T_DOUBLE_QUOTED_STRING => true, \T_HEREDOC => true, \T_NOWDOC => true, ]; /** * Do a version check to determine if this sniff needs to run at all. * * @since 9.3.0 * * @return bool */ protected function bowOutEarly() { return (ScannedCode::shouldRunOnOrAbove('7.4') === false); } /** * Process the parameters of a matched function. * * @since 9.3.0 * * @param \PHP_CodeSniffer\Files\File $phpcsFile The file being scanned. * @param int $stackPtr The position of the current token in the stack. * @param string $functionName The token content (function name) which was matched. * @param array $parameters Array with information about the parameters. * * @return int|void Integer stack pointer to skip forward or void to continue * normal file processing. */ public function processParameters(File $phpcsFile, $stackPtr, $functionName, $parameters) { $functionLC = \strtolower($functionName); $paramInfo = $this->targetFunctions[$functionLC]; $targetParam = PassedParameters::getParameterFromStack($parameters, $paramInfo['position'], $paramInfo['name']); if ($targetParam === false) { return; } $tokens = $phpcsFile->getTokens(); for ($i = $targetParam['start']; $i <= $targetParam['end']; $i++) { if (isset(Tokens::$emptyTokens[$tokens[$i]['code']]) === true) { continue; } // Ignore anything within square brackets. if (isset($tokens[$i]['bracket_closer'])) { $i = $tokens[$i]['bracket_closer']; continue; } // Skip past nested arrays, function calls and arbitrary groupings. if (isset($tokens[$i]['parenthesis_closer'])) { $i = $tokens[$i]['parenthesis_closer']; continue; } if (isset($this->invalidTokenTypes[$tokens[$i]['code']]) === true) { $phpcsFile->addWarning( 'The value of the password hash algorithm constants has changed in PHP 7.4. Pass a PHP native constant to the %s() function instead of using the value of the constant. Found: %s', $stackPtr, 'NotAlgoConstant', [ $functionName, $targetParam['clean'], ] ); break; } } } }