Sample code for 30+ languages & platforms
C

Set the FTP Password from a SecureString

See more FTP Examples

Demonstrates the Chilkat Ftp2.SetSecurePassword method, which sets the login password from a SecureString. The only argument is the SecureString. It is equivalent to setting the Password property but avoids holding the password as an ordinary immutable string.

Background: An ordinary string password can linger in memory (and in memory dumps) because strings are immutable and copied freely. A SecureString keeps the value encrypted under a session key and clears it deterministically, reducing that exposure — a sensible upgrade for a credential the process holds for the life of the connection. Populate it from a runtime source rather than a hard-coded literal.

Chilkat C Downloads

C
#include <C_CkFtp2.h>
#include <C_CkSecureString.h>

void ChilkatSample(void)
    {
    BOOL success;
    HCkFtp2 ftp;
    const char *password;
    HCkSecureString securePassword;

    success = FALSE;

    //  Demonstrates the Ftp2.SetSecurePassword method, which sets the login password from a
    //  SecureString.  The only argument is the SecureString.  This avoids holding the password as an
    //  ordinary immutable string.

    ftp = CkFtp2_Create();

    CkFtp2_putHostname(ftp,"ftp.example.com");
    CkFtp2_putUsername(ftp,"myFtpLogin");

    //  Normally you would not hard-code the password in source.  You should instead obtain it
    //  from an interactive prompt, environment variable, or a secrets vault.
    password = "myPassword";

    //  Place the password into a SecureString, which keeps it encrypted in memory.
    securePassword = CkSecureString_Create();
    CkSecureString_Append(securePassword,password);

    //  Setting the secure password is equivalent to setting the Password property, but more
    //  protective.
    success = CkFtp2_SetSecurePassword(ftp,securePassword);
    if (success == FALSE) {
        printf("%s\n",CkFtp2_lastErrorText(ftp));
        CkFtp2_Dispose(ftp);
        CkSecureString_Dispose(securePassword);
        return;
    }

    success = CkFtp2_Connect(ftp);
    if (success == FALSE) {
        printf("%s\n",CkFtp2_lastErrorText(ftp));
        CkFtp2_Dispose(ftp);
        CkSecureString_Dispose(securePassword);
        return;
    }

    printf("Connected using a secure password.\n");

    success = CkFtp2_Disconnect(ftp);
    if (success == FALSE) {
        printf("%s\n",CkFtp2_lastErrorText(ftp));
        CkFtp2_Dispose(ftp);
        CkSecureString_Dispose(securePassword);
        return;
    }



    CkFtp2_Dispose(ftp);
    CkSecureString_Dispose(securePassword);

    }