lasdf1234 opened a new issue, #13353: URL: https://github.com/apache/gravitino/issues/13353
### What would you like to be improved? Name-based (fuzzy) masking in `HiddenPropertyMaskUtils` currently runs when: ```text !metadata.containsProperty(key) && SecretPropertyUtils.isSensitivePropertyKey(key) ``` `metadata` is per-catalog. A key that Gravitino officially defines elsewhere (for example `s3-access-key-id` in `S3PropertiesMetadata`) but is not declared on the current catalog (for example a Glue runtime copy) is treated as unknown and fuzzy-masked, while the same name on another catalog that declares it is not. Declared `hidden=false` keys that match sensitive keywords (for example `aws-access-key-id`) skip the heuristic entirely, so redaction is inconsistent across catalogs. Related: datastrato/gravitino-enterprise#2184. ### How should we improve? 1. Maintain a complete registry of all Gravitino-defined property keys (base + credential config + shared cloud storage + each connector's official keys) in a shared module. Use string / `PropertyEntry` definitions so core does not depend on catalog modules; connectors may depend on the shared definitions. 2. Apply fuzzy name-based masking only when the key is **not** in that registry (Gravitino never defined it). Official keys always follow their registered `hidden` / `reserved` semantics. 3. Keep per-catalog `PropertiesMetadata` for validation and catalog-local schema; use the registry as the source of truth for "is this an official Gravitino key?" when masking and secret recovery must be consistent across catalogs. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
