This is an automated email from the ASF dual-hosted git repository.

yuqi1129 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git


The following commit(s) were added to refs/heads/main by this push:
     new 11981f8e62 [#13246] fix(catalog-common): complete the static 
credential key set for GVFS filtering (#13247)
11981f8e62 is described below

commit 11981f8e6287d39f9bccdf4adf9135432dc4ab18
Author: YangJie <[email protected]>
AuthorDate: Sun Sep 20 21:42:11 2026 -0400

    [#13246] fix(catalog-common): complete the static credential key set for 
GVFS filtering (#13247)
    
    ### What changes were proposed in this pull request?
    
    Adds `azure-client-secret` to the `STATIC_CREDENTIAL_KEYS` set that
    `omitStaticCredentialProperties` strips from a fileset catalog's
    properties before they are merged into GVFS client configuration. This
    branch merges the latest `main` (whose #13204 reframed the set to
    secret-bearing cloud-storage keys only) and follows that contract:
    `azure-client-secret` is a shared cloud-storage secret (declared in
    `AzurePropertiesMetadata` and pulled into
    `FilesetCatalogPropertiesMetadata`) that reaches the GVFS/HCFS storage
    config for ABS/ADLS filesets, and it was the one such secret still
    missing from the set.
    
    Access-key IDs are intentionally left out (they are non-hidden and must
    stay available from `properties()`). Glue and Paimon-DLF credentials are
    out of scope: they are catalog-connection credentials declared only in
    their own catalogs' `PropertiesMetadata` (already masked via `hidden`),
    and never appear in the fileset-catalog properties map this filter
    governs.
    
    ### Why are the changes needed?
    
    `azure-client-secret` is a cloud-storage secret consumed by fileset
    catalogs, but it was missing from the strip set, so it could pass
    through into GVFS client configuration.
    
    ### Does this PR introduce _any_ user-facing change?
    
    No. No property keys are added or removed. One additional secret
    (`azure-client-secret`) is now stripped from fileset-catalog REST
    metadata before it is merged into GVFS client configuration.
    
    ### How was this patch tested?
    
    `TestCloudStorageCredentialPropertyKeys` asserts `azure-client-secret`
    is detected by `isStaticCredentialKey` and stripped by
    `omitStaticCredentialProperties`, that access-key IDs survive, and that
    the Glue and DLF catalog secrets are not treated as cloud-storage
    credential keys.
    
    Fix: #13246
---
 .../CloudStorageCredentialPropertyKeys.java        |  1 +
 .../TestCloudStorageCredentialPropertyKeys.java    | 46 ++++++++++++++++++++++
 2 files changed, 47 insertions(+)

diff --git 
a/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
 
b/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
index 97bae3cef1..962c87d770 100644
--- 
a/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
+++ 
b/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
@@ -50,6 +50,7 @@ public final class CloudStorageCredentialPropertyKeys {
           S3Properties.GRAVITINO_S3_SECRET_ACCESS_KEY,
           OSSProperties.GRAVITINO_OSS_ACCESS_KEY_SECRET,
           AzureProperties.GRAVITINO_AZURE_STORAGE_ACCOUNT_KEY,
+          AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET,
           COSProperties.GRAVITINO_COS_ACCESS_KEY_SECRET);
 
   private CloudStorageCredentialPropertyKeys() {}
diff --git 
a/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
 
b/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
index 768890dd8f..b4affbee94 100644
--- 
a/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
+++ 
b/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
@@ -23,6 +23,8 @@ import static org.junit.jupiter.api.Assertions.assertFalse;
 import static org.junit.jupiter.api.Assertions.assertTrue;
 
 import java.util.Map;
+import org.apache.gravitino.catalog.glue.GlueConstants;
+import org.apache.gravitino.catalog.lakehouse.paimon.PaimonConstants;
 import org.junit.jupiter.api.Test;
 
 public class TestCloudStorageCredentialPropertyKeys {
@@ -64,5 +66,49 @@ public class TestCloudStorageCredentialPropertyKeys {
     assertFalse(
         CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
             COSProperties.GRAVITINO_COS_REGION));
+
+    // Azure client secret is a cloud-storage static credential and is 
stripped.
+    assertTrue(
+        CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+            AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET));
+
+    // Glue/Paimon-DLF secrets are catalog/metastore-connection credentials, 
not cloud-storage
+    // secrets in the fileset properties map this filter governs; they never 
reach it (declared
+    // hidden and outside FilesetCatalogPropertiesMetadata), so this set must 
not claim them.
+    assertFalse(
+        CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+            GlueConstants.AWS_SECRET_ACCESS_KEY));
+    assertFalse(
+        CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+            PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_SECRET));
+    assertFalse(
+        CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+            PaimonConstants.GRAVITINO_DLF_SECURITY_TOKEN));
+
+    // Access key IDs are non-hidden identifiers, not secrets; they behave 
like s3/oss/cos IDs.
+    assertFalse(
+        
CloudStorageCredentialPropertyKeys.isStaticCredentialKey(GlueConstants.AWS_ACCESS_KEY_ID));
+    assertFalse(
+        CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+            PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID));
+  }
+
+  @Test
+  void testAzureClientSecretStrippedButAccessKeyIdsSurvive() {
+    Map<String, String> input =
+        Map.of(
+            AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET, "aad-secret",
+            GlueConstants.AWS_ACCESS_KEY_ID, "ak",
+            PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID, "dlf-ak");
+
+    Map<String, String> filtered =
+        
CloudStorageCredentialPropertyKeys.omitStaticCredentialProperties(input);
+
+    // azure-client-secret is the sole branch-added cloud-storage secret this 
filter strips.
+    
assertFalse(filtered.containsKey(AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET));
+
+    // Access key IDs are non-hidden identifiers and must survive in 
properties().
+    assertEquals("ak", filtered.get(GlueConstants.AWS_ACCESS_KEY_ID));
+    assertEquals("dlf-ak", 
filtered.get(PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID));
   }
 }

Reply via email to