passay icon indicating copy to clipboard operation
passay copied to clipboard

Consider exposing generated password from PasswordGenerator as a char array or buffer

Open bindul opened this issue 3 years ago • 1 comments

It would be convenient to be able to get the generated password from PasswordGenerator as a char[] or CharBuffer. This would allow us to wipe out contents in the array to avoid Heap_Inspection risk flagged by Static Application Security Tool scans. Creating a String from the buffer with the generated password is disliked by those tools.

bindul avatar Mar 22 '21 22:03 bindul

Hi, I am facing with same in org.passay.PasswordData where password filed as String. If this password field as char[] this would help and resolve our Cleartext Storage of Sensitive Information in Memory issue flagged by veracode.

maulijmehta avatar Jul 07 '22 11:07 maulijmehta