lasdf1234 commented on PR #13539: URL: https://github.com/apache/gravitino/pull/13539#issuecomment-5890806858
@diqiu50 Thanks for the follow-up — addressed both points: 1. **Static providers + unprivileged `getCredentials`** — Documented the risk and temporary mitigations in `docs/security/credential-vending.md` (section *Static providers and `getCredentials` privilege risk*): prefer token/IRSA providers, restrict who can load catalogs with static providers, and treat lasting authz for static credentials as a follow-up. Will track that follow-up in a separate issue. 2. **Glue `AWS_ACCESS_KEY_ID` hidden vs test** — Updated `TestGlueCatalogPropertiesMetadata` to expect both `aws-access-key-id` and `aws-secret-access-key` hidden (aligned with shared `AWSPropertiesMetadata`). Confirmed with `:catalogs:catalog-glue:test --tests TestGlueCatalogPropertiesMetadata`. Fix commit: cbd106adb -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
