Github user gatorsmile commented on the issue:

    https://github.com/apache/spark/pull/21158
  
    The default value introduced by SPARK-22479 was already part of Apache 
Spark 2.3. It is hard to say this is a regression, since URIs could contain the 
access keys and usernames could have potentially personal identifiable 
information. Thus, it also makes sense to block them. Although the original 
JIRA is for JDBC, we also make it more secure. If users do not want to redact 
them, they can change the default. I am not feeling comfortable to not redact 
them in the current situation, since we already did it in Spark 2.3.  All the 
security issues could be serious. Thus, I think we should make it unchanged. 


---

---------------------------------------------------------------------
To unsubscribe, e-mail: reviews-unsubscr...@spark.apache.org
For additional commands, e-mail: reviews-h...@spark.apache.org

Reply via email to