View Javadoc
1   /*
2    *  Copyright 2018 The shiro-root contributors
3    *
4    *  Licensed under the Apache License, Version 2.0 (the "License");
5    *  you may not use this file except in compliance with the License.
6    *  You may obtain a copy of the License at
7    *
8    *    http://www.apache.org/licenses/LICENSE-2.0
9    *
10   *  Unless required by applicable law or agreed to in writing, software
11   *  distributed under the License is distributed on an "AS IS" BASIS,
12   *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13   *  See the License for the specific language governing permissions and
14   *  limitations under the License.
15   */
16  
17  package org.apache.shiro.lang.util;
18  
19  import java.util.Arrays;
20  
21  public final class ByteUtils {
22  
23      private ByteUtils() {
24          // private utility class
25      }
26  
27      /**
28       * For security, sensitive information in array should be zeroed-out at end of use (SHIRO-349).
29       *
30       * @param value An array holding sensitive data
31       */
32      public static void wipe(Object value) {
33          if (value instanceof byte[]) {
34              byte[] array = (byte[]) value;
35              Arrays.fill(array, (byte) 0);
36          } else if (value instanceof char[]) {
37              char[] array = (char[]) value;
38              Arrays.fill(array, '\u0000');
39          }
40      }
41  
42  }