lasdf1234 opened a new issue, #13538:
URL: https://github.com/apache/gravitino/issues/13538

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   After the shared cloud credential properties were declared on every catalog, 
access key IDs (`aws-access-key-id`, `s3-access-key-id`, `oss-access-key-id`, 
`cos-access-key-id`, and equivalents such as `dlf-access-key-id`) are declared 
with `hidden=false`. Secret keys are masked as `******`, but access key IDs are 
returned in cleartext to any caller who can load the catalog.
   
   An access key ID is not the secret, but it is not harmless: for AWS, 
`sts:GetAccessKeyInfo` returns the owning account for any key ID, so every 
catalog reader learns which account the static credential belongs to, and holds 
half of the credential pair.
   
   ### Error message and/or stacktrace
   
   N/A — behavioral issue on catalog load / property read paths.
   
   ### How to reproduce
   
   1. Create a catalog (e.g. fileset / Glue / Iceberg) with static 
`*-access-key-id` and `*-secret-access-key` (or OSS/COS equivalents).
   2. Load the catalog via the REST/Java API.
   3. Observe access key IDs returned in cleartext while secret keys are masked.
   
   ### Additional context
   
   Related enterprise issue: datastrato/gravitino-enterprise#2266
   Related: credential masking consistency work that declared shared cloud 
properties on every catalog.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to