On Wed, 19 Aug 2026 14:03:26 GMT, Sean Mullan <[email protected]> wrote:

>> Valerie Peng has updated the pull request incrementally with one additional 
>> commit since the last revision:
>> 
>>   import cleanup.
>
> src/java.base/share/classes/javax/crypto/spec/Argon2ParameterSpec.java line 
> 440:
> 
>> 438: 
>> 439:     /**
>> 440:      * {@return a copy of the optional secret value, or an empty array
> 
> Why return an empty array instead of null? Seems a bit unusual for security 
> APIs.

Because the optional secret value if not supplied, is encoded internally by 
Argon2 as an empty array. So, I just return an empty array when it's not 
overridden. Caller does not have to check for null value this way.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/29597#discussion_r4202931243

Reply via email to