lasdf1234 commented on code in PR #13599:
URL: https://github.com/apache/gravitino/pull/13599#discussion_r4140916507


##########
docs/lakehouse-paimon-catalog.md:
##########
@@ -136,7 +136,8 @@ Download the corresponding JDBC driver and place it to the 
`catalogs/lakehouse-p
 Refer to [Manage Catalogs and 
Schemas](./manage-catalogs-and-schemas.md#catalog-operations) for more details.
 
 :::note
-Sensitive catalog properties such as `jdbc-password` are hidden from the 
default load catalog response (`jdbc-user` is returned in plaintext). Retrieve 
secret-manager-backed properties (including `jdbc-password` when stored as a 
secret URN) via `getSecrets` / `GET .../objects/{type}/{fullName}/secrets`. The 
[credential vending API](security/credential-vending.md) (`getCredentials` / 
`JdbcCredential`) remains available for typed credential delivery.
+Sensitive catalog properties such as `jdbc-password` and DLF credential keys 
are hidden from the default load catalog response (`jdbc-user` is returned in 
plaintext). Recover JDBC / DLF credential fields via the [credential vending 
API](security/credential-vending.md) (`getCredentials` / `JdbcCredential` / 
`DlfSecretKeyCredential`). Other non-credential secrets (secret-manager URNs, 
declared `hidden` properties, undeclared sensitive-named keys) use `getSecrets` 
/ `GET .../objects/{type}/{fullName}/secrets` with `USE_SECRETS` (cloud 
access-key pairs also need `INCLUDE_CREDENTIAL_SECRETS`).

Review Comment:
   Fixed in a95f083b5. Rewrote the docs to state that both `getSecrets` and 
`getCredentials` work, and that `getCredentials` requires no extra privilege.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to