lasdf1234 commented on PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#issuecomment-5890806858

   @diqiu50 Thanks for the follow-up — addressed both points:
   
   1. **Static providers + unprivileged `getCredentials`** — Documented the 
risk and temporary mitigations in `docs/security/credential-vending.md` 
(section *Static providers and `getCredentials` privilege risk*): prefer 
token/IRSA providers, restrict who can load catalogs with static providers, and 
treat lasting authz for static credentials as a follow-up. Will track that 
follow-up in a separate issue.
   
   2. **Glue `AWS_ACCESS_KEY_ID` hidden vs test** — Updated 
`TestGlueCatalogPropertiesMetadata` to expect both `aws-access-key-id` and 
`aws-secret-access-key` hidden (aligned with shared `AWSPropertiesMetadata`). 
Confirmed with `:catalogs:catalog-glue:test --tests 
TestGlueCatalogPropertiesMetadata`.
   
   Fix commit: cbd106adb


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to