lasdf1234 commented on code in PR #13539:
URL: https://github.com/apache/gravitino/pull/13539#discussion_r4132238490
##########
core/src/main/java/org/apache/gravitino/secret/SecretPropertyUtils.java:
##########
@@ -89,8 +89,10 @@ public static boolean isSensitivePropertyKey(@Nullable
String key) {
* <li>{@code metadata == null}: do <strong>not</strong> recover
(URN-only). Used when the
* catalog does not expose properties metadata for the entity type.
* <li>otherwise: recover only undeclared keys or declared {@code hidden}
keys. Declared
- * non-hidden configuration (for example {@code credential-providers},
{@code
- * s3-access-key-id}) stays in {@code properties()} and is excluded
here.
+ * non-hidden configuration (for example {@code credential-providers})
stays in {@code
+ * properties()} and is excluded here. Declared hidden static access
key IDs (for example
+ * {@code s3-access-key-id}) are included in {@code getSecrets()} when
present as inline
+ * plaintext.
Review Comment:
Fixed in `24f993509`.
`buildSecrets` now recovers every declared-`hidden` property without the
sensitive-keyword gate, so shortening `gravitino.secret.sensitiveKeyKeywords`
(e.g. dropping `access`) cannot leave a masked property without a recovery
path. Undeclared keys still use the keyword matcher. Covered by
`TestSecretPropertyUtils.testBuildSecretsRecoversDeclaredHiddenWithoutKeywordGate`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]