Add MakeSecureString helper, eliminate .c_str() in password paths

- Add MakeSecureString(const std::string&) in allocators.h
- Replace .c_str() shims in walletpassphrase, walletpassphrasechange,
  encryptwallet RPCs and askpassphrasedialog
- Update TODO_DOCUMENTATION.md to mark issue as resolved

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-03-24 18:44:19 -07:00
parent 4405d34f4b
commit 7adf92df7a
4 changed files with 19 additions and 23 deletions
+3 -5
View File
@@ -99,11 +99,9 @@ void AskPassphraseDialog::accept()
oldpass.reserve(MAX_PASSPHRASE_SIZE);
newpass1.reserve(MAX_PASSPHRASE_SIZE);
newpass2.reserve(MAX_PASSPHRASE_SIZE);
// TODO: get rid of this .c_str() by implementing SecureString::operator=(std::string)
// Alternately, find a way to make this input mlock()'d to begin with.
oldpass.assign(ui->passEdit1->text().toStdString().c_str());
newpass1.assign(ui->passEdit2->text().toStdString().c_str());
newpass2.assign(ui->passEdit3->text().toStdString().c_str());
oldpass = MakeSecureString(ui->passEdit1->text().toStdString());
newpass1 = MakeSecureString(ui->passEdit2->text().toStdString());
newpass2 = MakeSecureString(ui->passEdit3->text().toStdString());
switch(mode)
{