Why is returning this.variable not a vulnerability?

Viewed 1512

Sonar rule squid:S2384 raises an issue on this code:

public Date getCreatedOn() {
    return createdOn;
}

following the rule Mutable members should not be stored or returned directly

I understand that we should not return the original, instead we should return a copy of the object.

On the other hand, Sonar does not raise an issue on this code:

public Date getCreatedOn() {
    return this.createdOn;
}

What makes this code different?

Are we not returning the original copy in the 2nd case?

2 Answers
Related