lasdf1234 opened a new pull request, #13539: URL: https://github.com/apache/gravitino/pull/13539
### What changes were proposed in this pull request? Declare the identifier half of static cloud credentials as `hidden=true` in shared property metadata (AWS / S3 / OSS / COS) and Paimon DLF, so load/list responses mask them as `******` consistently across catalogs. Update unit tests accordingly. ### Why are the changes needed? Access key IDs were left visible after shared cloud credential metadata was merged into every catalog. Callers who can load a catalog therefore see cleartext access key IDs (half of the credential pair; on AWS this also reveals the owning account via `sts:GetAccessKeyInfo`). Fix: #13538 ### Does this PR introduce _any_ user-facing change? Yes. Catalog load/list responses now return `******` for `aws-access-key-id`, `s3-access-key-id`, `oss-access-key-id`, `cos-access-key-id`, and `dlf-access-key-id` (previously cleartext). Plaintext remains available via `getSecrets` for authorized callers, same as other declared hidden secrets. ### How was this patch tested? - `TestCloudPropertiesMetadata` - `TestBaseCatalogPropertiesMetadata` - `TestSecretPropertyOperationDispatcher` - `TestFilesetCloudPropertiesMetadata` / `TestFilesetCatalogCredential` - `TestGlueCatalogPropertiesMetadata` - `TestIcebergCatalogPropertiesMetadata` - `TestPaimonCatalogPropertiesMetadata` Made with [Cursor](https://cursor.com) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
