Skip to content

NonSecureUniqidUsage ​

error on by default quick-fix

Group: Security · PhpStorm name: NonSecureUniqidUsageInspection

Without its more_entropy argument, uniqid() is based only on the current time in microseconds and collides easily. Pass true as second argument, also when uniqid is used as a callback.

Example ​

php
<?php
namespace Shop {
    $id   = uniqid();
    $ref  = \uniqid('ord_');
    $tags = array_map("uniqid", ['a', 'b']);
    $one  = call_user_func_array('\\uniqid', ['x']);

    $ok1 = uniqid('', true);
    $ok2 = uniqid(more_entropy: true, prefix: 'z');
    $ok3 = call_user_func('uniqid');
    $ok4 = array_map('strtoupper', ['a']);
}
php
<?php
namespace Shop {
    $id   = uniqid('', true);
    $ref  = \uniqid('ord_', true);
    $tags = array_map(function ($value) { return uniqid($value, true); }, ['a', 'b']);
    $one  = call_user_func_array(function ($value) { return uniqid($value, true); }, ['x']);

    $ok1 = uniqid('', true);
    $ok2 = uniqid(more_entropy: true, prefix: 'z');
    $ok3 = call_user_func('uniqid');
    $ok4 = array_map('strtoupper', ['a']);
}

Reported:

  • line 3: Pass more_entropy = true to uniqid() to reduce collisions.
  • line 4: Pass more_entropy = true to uniqid() to reduce collisions.
  • line 5: Pass more_entropy = true to uniqid() to reduce collisions.
  • line 6: Pass more_entropy = true to uniqid() to reduce collisions.

Configure ​

In custos.json:

json
{
  "rules": {
    "NonSecureUniqidUsage": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore NonSecureUniqidUsage

/**
 * @noinspection NonSecureUniqidUsageInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.