StormByte-Crypto 2.0.0
C++26 cryptography module of the StormByte suite
 
Loading...
Searching...
No Matches
StormByte::Crypto::Secure::Password Class Reference

Shared, wiped container for passwords and raw key material. More...

#include <StormByte/crypto/secure/password.hxx>

Public Member Functions

StormByte::ByteSize Size () const noexcept
 Stored size in bytes.
 
bool Empty () const noexcept
 Whether Size() is 0.
 
 operator bool () const noexcept
 true if the password is not empty.
 
bool operator== (const Password &other) const noexcept
 Constant-time equality.
 
bool operator!= (const Password &other) const noexcept
 Inequality.
 
Construction
 Password (std::string &value) noexcept
 From a std::string.
 
 Password (const char *value) noexcept
 From a C string up to the terminator.
 
 Password (const void *data, StormByte::ByteSize size) noexcept
 From raw bytes.
 
 Password (const Password &other)
 Copy constructor.
 
 Password (Password &&other) noexcept
 Move constructor.
 
 ~Password ()
 Destructor.
 
Password & operator= (const Password &other)
 Copy assignment.
 
Password & operator= (Password &&other) noexcept
 Move assignment.
 

Friends

struct Helpers::PasswordAccess
 

Detailed Description

Shared, wiped container for passwords and raw key material.

Bytes live in shared storage allocated by this library and are wiped when the last owner is destroyed. Copies share the same buffer. There is no public view of the raw bytes: once ingested, the secret only exists inside this object (and any StormByte::Crypto::Secure::Vault that still holds a share).

Why ingest is a non-const reference, not a view and not a move

A password that stays in the caller's std::string after construction is a leftover secret. std::string_view cannot wipe that source (it does not own it) and would encourage keeping the original buffer alive. Passing std::string by value or by move across a DLL boundary is also unsafe: the string's buffer is allocated by the caller's CRT/heap, and destroying or moving it inside this library can free the wrong heap.

Therefore the caller cedes a non-const std::string&. This constructor copies the bytes into wiped storage owned by this library and then overwrites and clears the caller's object. After return the argument is empty; the only remaining copy is the one Password owns.

String literals (Password("secret")) use const char*. They are copied and the source is not wiped: a literal lives in read-only storage. That form is for tests and non-secret placeholders, not for production secrets typed in source.

Raw bytes (const void* + StormByte::ByteSize) are copied and not wiped; the caller is responsible for the source buffer.

Constructor & Destructor Documentation

◆ Password() [1/5]

StormByte::Crypto::Secure::Password::Password ( std::string &  value)
explicitnoexcept

From a std::string.

Copies into secure storage and wipes value.

Parameters
valuePassword characters. Emptied and zeroed on return.

◆ Password() [2/5]

StormByte::Crypto::Secure::Password::Password ( const char *  value)
explicitnoexcept

From a C string up to the terminator.

The source is not wiped.

Parameters
valueNull-terminated password (including literals).

◆ Password() [3/5]

StormByte::Crypto::Secure::Password::Password ( const void *  data,
StormByte::ByteSize  size 
)
noexcept

From raw bytes.

Exact size; no terminator is added. The source is not wiped.

Parameters
dataBytes, or nullptr if size is 0.
sizeNumber of bytes.

◆ Password() [4/5]

StormByte::Crypto::Secure::Password::Password ( const Password &  other)

Copy constructor.

Shares the buffer.

Parameters
otherPassword to copy.

◆ Password() [5/5]

StormByte::Crypto::Secure::Password::Password ( Password &&  other)
noexcept

Move constructor.

Parameters
otherPassword to move.

◆ ~Password()

StormByte::Crypto::Secure::Password::~Password ( )

Destructor.

Wipes the buffer if this is the last owner.

Member Function Documentation

◆ Empty()

bool StormByte::Crypto::Secure::Password::Empty ( ) const
noexcept

Whether Size() is 0.

Returns
true if empty.

◆ operator bool()

StormByte::Crypto::Secure::Password::operator bool ( ) const
explicitnoexcept

true if the password is not empty.

◆ operator!=()

bool StormByte::Crypto::Secure::Password::operator!= ( const Password &  other) const
noexcept

Inequality.

Parameters
otherOther password.
Returns
true if not equal.

◆ operator=() [1/2]

Password & StormByte::Crypto::Secure::Password::operator= ( const Password &  other)

Copy assignment.

Parameters
otherPassword to copy.
Returns
Reference to this password.

◆ operator=() [2/2]

Password & StormByte::Crypto::Secure::Password::operator= ( Password &&  other)
noexcept

Move assignment.

Parameters
otherPassword to move.
Returns
Reference to this password.

◆ operator==()

bool StormByte::Crypto::Secure::Password::operator== ( const Password &  other) const
noexcept

Constant-time equality.

Parameters
otherOther password.
Returns
true if length and content match.

◆ Size()

StormByte::ByteSize StormByte::Crypto::Secure::Password::Size ( ) const
noexcept

Stored size in bytes.

Returns
Byte count.

Friends And Related Symbol Documentation

◆ Helpers::PasswordAccess

friend struct Helpers::PasswordAccess
friend

The documentation for this class was generated from the following file: