Shared, wiped container for passwords and raw key material. More...
#include <StormByte/crypto/secure/password.hxx>
Public Member Functions | |
| StormByte::ByteSize | Size () const noexcept |
| Stored size in bytes. | |
| bool | Empty () const noexcept |
| Whether Size() is 0. | |
| operator bool () const noexcept | |
| true if the password is not empty. | |
| bool | operator== (const Password &other) const noexcept |
| Constant-time equality. | |
| bool | operator!= (const Password &other) const noexcept |
| Inequality. | |
Construction | |
| Password (std::string &value) noexcept | |
| From a std::string. | |
| Password (const char *value) noexcept | |
| From a C string up to the terminator. | |
| Password (const void *data, StormByte::ByteSize size) noexcept | |
| From raw bytes. | |
| Password (const Password &other) | |
| Copy constructor. | |
| Password (Password &&other) noexcept | |
| Move constructor. | |
| ~Password () | |
| Destructor. | |
| Password & | operator= (const Password &other) |
| Copy assignment. | |
| Password & | operator= (Password &&other) noexcept |
| Move assignment. | |
Friends | |
| struct | Helpers::PasswordAccess |
Shared, wiped container for passwords and raw key material.
Bytes live in shared storage allocated by this library and are wiped when the last owner is destroyed. Copies share the same buffer. There is no public view of the raw bytes: once ingested, the secret only exists inside this object (and any StormByte::Crypto::Secure::Vault that still holds a share).
A password that stays in the caller's std::string after construction is a leftover secret. std::string_view cannot wipe that source (it does not own it) and would encourage keeping the original buffer alive. Passing std::string by value or by move across a DLL boundary is also unsafe: the string's buffer is allocated by the caller's CRT/heap, and destroying or moving it inside this library can free the wrong heap.
Therefore the caller cedes a non-const std::string&. This constructor copies the bytes into wiped storage owned by this library and then overwrites and clears the caller's object. After return the argument is empty; the only remaining copy is the one Password owns.
String literals (Password("secret")) use const char*. They are copied and the source is not wiped: a literal lives in read-only storage. That form is for tests and non-secret placeholders, not for production secrets typed in source.
Raw bytes (const void* + StormByte::ByteSize) are copied and not wiped; the caller is responsible for the source buffer.
|
explicitnoexcept |
From a std::string.
Copies into secure storage and wipes value.
| value | Password characters. Emptied and zeroed on return. |
|
explicitnoexcept |
From a C string up to the terminator.
The source is not wiped.
| value | Null-terminated password (including literals). |
|
noexcept |
From raw bytes.
Exact size; no terminator is added. The source is not wiped.
| data | Bytes, or nullptr if size is 0. |
| size | Number of bytes. |
| StormByte::Crypto::Secure::Password::Password | ( | const Password & | other | ) |
|
noexcept |
Move constructor.
| other | Password to move. |
| StormByte::Crypto::Secure::Password::~Password | ( | ) |
Destructor.
Wipes the buffer if this is the last owner.
|
noexcept |
Whether Size() is 0.
|
explicitnoexcept |
true if the password is not empty.
|
noexcept |
Inequality.
| other | Other password. |
|
noexcept |
Constant-time equality.
| other | Other password. |
|
noexcept |
Stored size in bytes.
|
friend |