Claus Ibsen created CAMEL-25096:
-----------------------------------

             Summary: camel-core - Properties component: mask the values of 
vault functions and sensitive keys when logging
                 Key: CAMEL-25096
                 URL: https://issues.apache.org/jira/browse/CAMEL-25096
             Project: Camel
          Issue Type: Improvement
          Components: camel-core
            Reporter: Claus Ibsen


The properties component logs the resolved value of a property placeholder at 
DEBUG/TRACE level (such as "Property with key [aws:db/password] applied by 
function [aws] -> <value>"). The values of properties functions for vaults 
(aws, aws-parameterstore, azure, gcp, hashicorp, ibm, cyberark and the 
kubernetes secret functions) and of properties with a sensitive key (such as 
db.password) should be logged as {{xxxxxx}}, the same mask as used for endpoint 
uris.

* A new default method {{isSensitive()}} on {{PropertiesFunction}} (default 
false), which the vault functions return true for.
* DefaultPropertiesParser, DefaultPropertiesLookup and PropertiesComponent mask 
the values of sensitive functions and sensitive keys in their logging.
* Add {{db_password}} (such as DB_PASSWORD) and {{apisecret}} (such as 
apiSecret) as sensitive keys.

_Claude Code on behalf of Claus Ibsen_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to