# gpui_windows: Handle null UserName and CredentialBlob from CredReadW \(\#64735\) · gitcafe/zed

[View on GitCafe](https://git.cafe/gitcafe/zed/commit/8720fd1d093963be0aeb36954c15fd1aca1b94d2)

Repository: [gitcafe/zed](https://git.cafe/gitcafe/zed)

Visibility: public

Requested revision: 8720fd1d093963be0aeb36954c15fd1aca1b94d2

Requested commit: 8720fd1d093963be0aeb36954c15fd1aca1b94d2

Commit: 8720fd1d093963be0aeb36954c15fd1aca1b94d2

Tree: e4ebb06ab04296229fbef8026f512501d2cff469

Author: Agus Zubiaga

Committer: GitHub

## Message

```
gpui_windows: Handle null UserName and CredentialBlob from CredReadW (#64735)

# Objective

`CredReadW` returns a null `UserName` when the stored credential has no
username, and a null `CredentialBlob` when the blob is empty
([docs](https://learn.microsoft.com/en-us/windows/win32/api/wincred/ns-wincred-credentialw)).
`read_credentials` dereferenced both unconditionally, so `wcslen`
faulted on the null username and crashed Zed.

Fixes ZED-BTS

## Solution

We now treat a null `UserName` as an empty username and a null
`CredentialBlob` as an empty password. Every caller either ignores the
username or parses it with `.ok()?`, so an empty one just reads as "no
credentials", same as on macOS and Linux. Also, `CredFree` now runs
before a UTF-16 conversion error is propagated, so the allocation can't
leak.

## Testing

- Added round-trip tests through Credential Manager for a generic
credential with and without a username.
- Verified against the ZED-BTS minidump that the faulting read is
`wcslen` on `UserName` inside `read_credentials`.

## Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [ ] The content adheres to Zed's UI standards
([UX/UI](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
and
[icon](https://github.com/zed-industries/zed/blob/main/crates/icons/README.md)
guidelines)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

---

Release Notes:

- Fixed a crash on Windows when reading a stored credential that has no
username.
- [GPUI] `Platform::read_credentials` on Windows no longer crashes on
credentials with a null `UserName` or `CredentialBlob`.
```

## Parents

- [2c4bc2d7b2c5b7832ad964f39840d823d961cb0e](https://git.cafe/gitcafe/zed/commit/2c4bc2d7b2c5b7832ad964f39840d823d961cb0e?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zed/tree/8720fd1d093963be0aeb36954c15fd1aca1b94d2?format=markdown)
