Hi, I can’t comment on the official background, but this is correct. It should not be possible to fetch a password once set. This follows best security practices.
Hth.
James
This field is intentionally kept to indicate that, although Username is present, Password has not been omitted by mistake, but is unavailable for security reasons. Although this may seem pedantic, removing the field could introduce backward compatibility issues in some client applications.