lasdf1234 commented on code in PR #13599:
URL: https://github.com/apache/gravitino/pull/13599#discussion_r4140916507
##########
docs/lakehouse-paimon-catalog.md:
##########
@@ -136,7 +136,8 @@ Download the corresponding JDBC driver and place it to the
`catalogs/lakehouse-p
Refer to [Manage Catalogs and
Schemas](./manage-catalogs-and-schemas.md#catalog-operations) for more details.
:::note
-Sensitive catalog properties such as `jdbc-password` are hidden from the
default load catalog response (`jdbc-user` is returned in plaintext). Retrieve
secret-manager-backed properties (including `jdbc-password` when stored as a
secret URN) via `getSecrets` / `GET .../objects/{type}/{fullName}/secrets`. The
[credential vending API](security/credential-vending.md) (`getCredentials` /
`JdbcCredential`) remains available for typed credential delivery.
+Sensitive catalog properties such as `jdbc-password` and DLF credential keys
are hidden from the default load catalog response (`jdbc-user` is returned in
plaintext). Recover JDBC / DLF credential fields via the [credential vending
API](security/credential-vending.md) (`getCredentials` / `JdbcCredential` /
`DlfSecretKeyCredential`). Other non-credential secrets (secret-manager URNs,
declared `hidden` properties, undeclared sensitive-named keys) use `getSecrets`
/ `GET .../objects/{type}/{fullName}/secrets` with `USE_SECRETS` (cloud
access-key pairs also need `INCLUDE_CREDENTIAL_SECRETS`).
Review Comment:
Fixed in a95f083b5. Rewrote the docs to state that both `getSecrets` and
`getCredentials` work, and that `getCredentials` requires no extra privilege.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]