42 lines
1.0 KiB
Plaintext
42 lines
1.0 KiB
Plaintext
include::../description.adoc[]
|
|
|
|
include::../ask-yourself.adoc[]
|
|
|
|
include::../recommended.adoc[]
|
|
|
|
== Sensitive Code Example
|
|
|
|
----
|
|
Connection conn = null;
|
|
try {
|
|
conn = DriverManager.getConnection("jdbc:mysql://localhost/test?" +
|
|
"user=steve&password=blue"); // Sensitive
|
|
String uname = "steve";
|
|
String password = "blue";
|
|
conn = DriverManager.getConnection("jdbc:mysql://localhost/test?" +
|
|
"user=" + uname + "&password=" + password); // Sensitive
|
|
|
|
java.net.PasswordAuthentication pa = new java.net.PasswordAuthentication("userName", "1234".toCharArray()); // Sensitive
|
|
----
|
|
|
|
== Compliant Solution
|
|
|
|
----
|
|
Connection conn = null;
|
|
try {
|
|
String uname = getEncryptedUser();
|
|
String password = getEncryptedPass();
|
|
conn = DriverManager.getConnection("jdbc:mysql://localhost/test?" +
|
|
"user=" + uname + "&password=" + password);
|
|
----
|
|
|
|
include::../see.adoc[]
|
|
|
|
ifdef::env-github,rspecator-view[]
|
|
'''
|
|
== Comments And Links
|
|
(visible only on this page)
|
|
|
|
include::comments-and-links.adoc[]
|
|
endif::env-github,rspecator-view[]
|