dzr171712 opened a new pull request, #66836:
URL: https://github.com/apache/doris/pull/66836

   ### What problem does this PR solve?
   
   Issue Number: close #CIR-27839
   
   Related PR: #xxx
   
   Problem Summary:
   
   The `tls_private_key_password` configuration value is exposed in plaintext 
through `information_schema.backend_configuration`.
   
   The value is collected by `config::get_config_info()` from the BE 
configuration map and returned without masking. Since the default role has read 
access to `information_schema.*`, an authenticated user can query the table and 
obtain the TLS private key password.
   
   This change masks `tls_private_key_password` as `******` at the shared 
configuration export layer. The masking applies to 
`information_schema.backend_configuration` and other output paths that reuse 
`get_config_info()`, while preserving the configuration name, type, and 
mutability fields.
   
   ### Release note
   
   None
   
   ### Check List (For Author)
   
   - Test <!-- At least one of them must be included. -->
     - [ ] Regression test
     - [ ] Unit Test
     - [ ] Manual test (add detailed scripts or steps below)
     - [x] No need to test or manual test. Explain why:
       - [ ] This is a refactor/code format and no logic has been changed.
       - [ ] Previous test can cover this change.
       - [ ] No code files have been changed.
       - [x] Other reason: The change is limited to replacing one sensitive 
configuration value at the shared output point. `clang-format`, `git diff 
--check`, and `config.cpp` compilation passed.
   
   - Behavior changed:
     - [ ] No.
     - [x] Yes. `tls_private_key_password` is now returned as `******` instead 
of its plaintext value.
   
   - Does this need documentation?
     - [x] No.
     - [ ] Yes. <!-- Add document PR link here. eg: 
https://github.com/apache/doris-website/pull/1214 -->
   
   ### Check List (For Reviewer who merge this PR)
   
   - [ ] Confirm the release note
   - [ ] Confirm test cases
   - [ ] Confirm document
   - [ ] Add branch pick label <!-- Add branch pick label that this PR should 
merge into -->
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to