Matt Gilman created NIFI-16250:
----------------------------------

             Summary: hasPropertyValue and fromValueReference treat an 
unconfigured SECRET_REFERENCE as a configured secret
                 Key: NIFI-16250
                 URL: https://issues.apache.org/jira/browse/NIFI-16250
             Project: Apache NiFi
          Issue Type: Bug
          Components: Core UI
            Reporter: Matt Gilman
            Assignee: Matt Gilman


{{buildSecretKey}} 
({{nifi-frontend/src/main/frontend/libs/shared/src/types/index.ts:570}}) joins 
its three parts with a {{::}} delimiter:

{code:javascript}
return [providerId ?? '', providerName ?? '', fullyQualifiedName ?? 
''].join('::');
{code}

It therefore never returns an empty string. For an entirely empty reference it 
returns {{"::::"}}, and for a reference carrying only a provider name it 
returns {{"::Provider Name::"}}. Two callers assume the opposite and misbehave 
as a result.

h3. 1. Required-property validation accepts an unconfigured secret

The SECRET branch of {{hasPropertyValue}} 
({{libs/shared/src/utils/connector-validation.utils.ts:44-57}}) guards with 
{{secretKey !== ''}}. Because the key is never empty, that check is always 
true, so any object with {{valueType: 'SECRET_REFERENCE'}} is reported as 
having a value -- including one with no {{fullyQualifiedSecretName}} and no 
{{secretName}}.

The connector configuration summary step uses this function for its 
required-field check 
({{libs/shared/src/components/connector-configuration-summary-step/connector-configuration-summary-step.component.ts:167}}),
 so {{hasMissingRequiredFields}} returns false and the user can proceed to 
apply a configuration in which a required secret was never selected.

h3. 2. The secret dropdown shows "(no longer available)" instead of its 
placeholder

{{fromValueReference}} 
({{libs/shared/src/services/value-reference.helper.ts:174-182}}) returns the 
composite key verbatim for a {{SECRET_REFERENCE}}. For an unconfigured 
reference the resulting non-empty string is written into the form control, so 
{{ConnectorPropertyInput}} treats it as a saved selection. Finding no matching 
secret, it appends a disabled orphan option 
({{libs/shared/src/components/connector-property-input/connector-property-input.component.ts:622-629}})
 labelled from the parsed fully-qualified name -- which is empty, producing a 
bare " (no longer available)" entry where the user should simply see the 
"Select a secret" placeholder.

h3. Steps to reproduce

# Configure a connector having a required SECRET property whose stored value 
reference is {{{ valueType: 'SECRET_REFERENCE', secretProviderName: '<some 
provider>' \}}} with no {{fullyQualifiedSecretName}} and no {{secretName}}.
# Open the connector configuration wizard and go to the step containing that 
property.
# Observe the secret dropdown.
# Advance to the summary step.

h3. Expected

The dropdown shows its "Select a secret" placeholder, and the summary step 
reports the required secret as missing, blocking apply.

h3. Actual

The dropdown shows a disabled "(no longer available)" option with an empty 
name, and the summary step reports no missing required fields, allowing apply.

h3. Suggested fix

In the SECRET branch of {{hasPropertyValue}}, check the identifying fields 
directly rather than the joined key, treating a reference with neither 
{{fullyQualifiedSecretName}} nor {{secretName}} as unset. In 
{{fromValueReference}}, return {{undefined}} for a {{SECRET_REFERENCE}} with no 
secret selected so the select component falls back to its placeholder. The 
{{secretKey !== ''}} comparison should be removed rather than left in place, 
since it cannot be false.

Note that {{libs/shared/src/utils/}} currently has no 
{{connector-validation.utils.spec.ts}}, so {{hasPropertyValue}} is untested. 
This fix is a good opportunity to add one, covering at minimum: a fully 
configured reference, a provider-name-only reference, an all-empty-strings 
reference, a reference with {{secretName}} but no {{fullyQualifiedSecretName}}, 
and a cleared secret arriving as {{STRING_LITERAL}} with a null value.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to