On Wed, 19 Aug 2026 14:03:26 GMT, Sean Mullan <[email protected]> wrote:
>> Valerie Peng has updated the pull request incrementally with one additional
>> commit since the last revision:
>>
>> import cleanup.
>
> src/java.base/share/classes/javax/crypto/spec/Argon2ParameterSpec.java line
> 440:
>
>> 438:
>> 439: /**
>> 440: * {@return a copy of the optional secret value, or an empty array
>
> Why return an empty array instead of null? Seems a bit unusual for security
> APIs.
Because the optional secret value if not supplied, is encoded internally by
Argon2 as an empty array. So, I just return an empty array when it's not
overridden. Caller does not have to check for null value this way.
-------------
PR Review Comment: https://git.openjdk.org/jdk/pull/29597#discussion_r4202931243