diff --git a/platform/credential-store/src/libraries/macOsKeychainLibrary.kt b/platform/credential-store/src/libraries/macOsKeychainLibrary.kt index 2f40a00832ab..7de55f442691 100644 --- a/platform/credential-store/src/libraries/macOsKeychainLibrary.kt +++ b/platform/credential-store/src/libraries/macOsKeychainLibrary.kt @@ -46,7 +46,7 @@ internal class KeyChainCredentialStore() : CredentialStore { return } - val password = credentials!!.password!!.toByteArray() + val password = credentials!!.password!!.toByteArray(false) saveGenericPassword(attributes.serviceName.toByteArray(), attributes.userName ?: credentials.userName, password, password.size) password.fill(0) } diff --git a/platform/platform-api/src/com/intellij/credentialStore/CredentialAttributes.kt b/platform/platform-api/src/com/intellij/credentialStore/CredentialAttributes.kt index fc98200d6f67..b3dc99f24044 100644 --- a/platform/platform-api/src/com/intellij/credentialStore/CredentialAttributes.kt +++ b/platform/platform-api/src/com/intellij/credentialStore/CredentialAttributes.kt @@ -86,13 +86,16 @@ class OneTimeString(value: CharArray, offset: Int = 0, length: Int = value.size) } // string will be cleared and not valid after - fun toByteArray(): ByteArray { - if (!consumed.compareAndSet(false, true)) { + @JvmOverloads + fun toByteArray(clear: Boolean = true): ByteArray { + if (clear && !consumed.compareAndSet(false, true)) { throw Error("Already consumed") } val result = Charsets.UTF_8.encode(CharBuffer.wrap(myChars, myStart, length)) - myChars.fill('\u0000', myStart, myEnd) + if (clear) { + myChars.fill('\u0000', myStart, myEnd) + } return result.toByteArray() } diff --git a/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/BasePasswordSafeProvider.java b/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/BasePasswordSafeProvider.java index 008f41a98360..a9f305ad9fd4 100644 --- a/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/BasePasswordSafeProvider.java +++ b/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/BasePasswordSafeProvider.java @@ -43,11 +43,11 @@ public abstract class BasePasswordSafeProvider implements PasswordStorage { public final void set(@NotNull CredentialAttributes attributes, @Nullable Credentials value) { byte[] key = EncryptionUtil.encryptKey(key(), EncryptionUtil.rawKey(attributes)); - if (value == null) { + if (value == null || value.getPassword() == null) { removeEncryptedPassword(key); } else { - storeEncryptedPassword(key, EncryptionUtil.encryptText(key(), value == null ? null : value.getPassword())); + storeEncryptedPassword(key, EncryptionUtil.encryptText(key(), value.getPassword())); } } diff --git a/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/EncryptionUtil.java b/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/EncryptionUtil.java index d38ec6f15f24..5ffaa7b22103 100644 --- a/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/EncryptionUtil.java +++ b/platform/platform-impl/src/com/intellij/ide/passwordSafe/impl/providers/EncryptionUtil.java @@ -171,7 +171,7 @@ public class EncryptionUtil { * @return encrypted text */ public static byte[] encryptText(byte[] password, @NotNull OneTimeString value) { - byte[] data = value.toByteArray(); + byte[] data = value.toByteArray(false); return encryptData(password, data.length, data); }