fat-catTW commented on PR #73791:
URL: https://github.com/apache/airflow/pull/73791#issuecomment-5955039646

   I think this fixes the sensitive part, but the new XCom branch seems to drop 
the existing path/query audit context when the request has a body. 
   
   Before this change, XCom requests fell through to the generic JSON branch, 
which merged the existing `extra_fields` with the masked body:
   `extra_fields = {**extra_fields, **masked_body_json}`
   So a PATCH like `.../xcomEntries/report_rows?map_index=0` kept `xcom_key` / 
`map_index` from path/query and added the body.
   
   With the new branch:
   `extra_fields = _mask_xcom_fields(request_body or extra_fields)`
   a body such as `{"value": "secret"}` replaces the existing `extra_fields`, 
so the audit entry becomes essentially `{"value": "***", "method": "PATCH"}` 
and no longer identifies which XCom was updated.
   
   Maybe we can merge the masked XCom body into the existing extra_fields 
instead? I think that would keep the previous audit context while still masking 
value.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to