Details

    • Type: Bug Bug
    • Status: Open
    • Priority: Major Major
    • Resolution: Unresolved
    • Affects Version/s: 2.0
    • Fix Version/s: None
    • Labels:
      None

      Description

      The JMS 2.0 specification, section 12.4.3 "Injection syntax" includes an example of the use of password aliases in Java EE. Although password aliases were discussed for Java EE they were not included in the final release, so the example should be removed.

        Activity

        Hide
        Nigel Deakin added a comment -

        Proposed change

        In the JMS 2.0 specification, section 12.4.3 "Injection syntax", delete the following text:

        Since it is undesirable to hardcode clear text passwords in an application, the password may be specified as an alias:

        @Inject
        @JMSPasswordCredential(
           username="admin",
           password="${ALIAS=myAdminPassword}")
        private JMSContext context;
        

        The use of a password alias allows the password to be defined in a secure manner separately from the application. See the Java EE 7 platform specification for more information on password aliases.

        Show
        Nigel Deakin added a comment - Proposed change In the JMS 2.0 specification, section 12.4.3 "Injection syntax", delete the following text: Since it is undesirable to hardcode clear text passwords in an application, the password may be specified as an alias: @Inject @JMSPasswordCredential( username="admin", password="${ALIAS=myAdminPassword}") private JMSContext context; The use of a password alias allows the password to be defined in a secure manner separately from the application. See the Java EE 7 platform specification for more information on password aliases.
        Hide
        Nigel Deakin added a comment -

        I have updated the specification in the source code repository. PDF may be downloaded here.

        Show
        Nigel Deakin added a comment - I have updated the specification in the source code repository. PDF may be downloaded here .

          People

          • Assignee:
            Unassigned
            Reporter:
            Nigel Deakin
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated: