github-actions[bot] commented on code in PR #68803:
URL: https://github.com/apache/doris/pull/68803#discussion_r4226535753


##########
fe/fe-filesystem/fe-filesystem-s3-base/src/test/java/org/apache/doris/filesystem/s3/S3FileSystemPropertiesTest.java:
##########
@@ -256,6 +258,32 @@ void toHadoopProperties_returnsS3AConfigurationMap() {
         Assertions.assertEquals("true", 
hadoopMap.get("fs.s3a.path.style.access"));
     }
 
+    @Test
+    void toHadoopConfigurationMap_keysFileSystemCacheByCredentialFingerprint() 
{
+        S3FileSystemProperties properties = S3FileSystemProperties.of(Map.of(
+                "s3.endpoint", "https://s3.us-west-2.amazonaws.com";,
+                "s3.access_key", "ak",
+                "s3.secret_key", "sk"));
+        S3FileSystemProperties otherCredentials = 
S3FileSystemProperties.of(Map.of(
+                "s3.endpoint", "https://s3.us-west-2.amazonaws.com";,

Review Comment:
   [P2] Vary the secret independently when testing cache identity. This test, 
like the COS/GCS/OBS/OSS additions, changes both the access key and secret. If 
a provider stops including its secret in the fingerprint, the access-key change 
still makes every assertion pass, while two definitions with the same access 
key and rotated secret can reuse a FileSystem carrying the old secret. Please 
keep the access key fixed in an additional case and assert the emitted 
per-scheme key changes; a session-token-only case would cover the other 
rotating credential.



##########
fe/fe-core/src/test/java/org/apache/doris/connector/DefaultConnectorContextVendTest.java:
##########
@@ -60,6 +62,33 @@ public void normalizesOssTokenToBackendAwsProps() {
         Assertions.assertEquals("testSessionToken789", be.get("AWS_TOKEN"));
     }
 
+    @Test
+    public void vendedTokenCarriesItsOwnFsCacheKey() {

Review Comment:
   [P2] Exercise a static token when validating the vended overlay. This test 
calls `vendStorageCredentials` alone, so it misses a REST catalog with static 
`oss.endpoint` and `oss.session_token`, then a vended OSS access/secret pair 
without `fs.oss.securityToken`. The vended map omits `AWS_TOKEN`; Paimon and 
Iceberg overlay only present keys, leaving the static token beside the vended 
keys, and BE uses that mixed credential set. Please add a scan-property case 
for this input and replace or clear the static credential fields as a unit when 
vending.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to