BasicAuthentication is zeroing out the given password

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P4
    • 1.4.1
    • Affects Version/s: 1.3.1
    • Component/s: core-libs
    • None
    • hopper
    • unknown
    • generic

      The BasicAuthentication implementation uses the username and
      password provided by the application Authenticator class,
      but before returning to the user, it clears out the password
      from the char[] passed in. This behavior is not documented
      and means that repeated attempts to use the same PasswordAuthentication
      instance will fail from the second attempt onwards.

            Assignee:
            Michael McMahon
            Reporter:
            Michael McMahon
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: