Frun1na opened a new pull request, #5666:
URL: https://github.com/apache/rocketmq-dashboard/pull/5666

   ### Which Issue(s) This PR Fixes
   
   - No issue: the change removes a committed literal credential, too small to 
need one.
   
   ### Brief Description
   
   `application.yml` shipped a literal key pair for the cluster admin 
credential reference:
   
   ```yaml
         credentials:
           rmq-test:
             access-key: rocketmq2
             secret-key: 12345678
   ```
   
   `MqAdminProperties.Credential` documents the opposite contract — "Access 
keys and secret keys must be supplied through externalized Spring 
configuration, such as environment variables or a Kubernetes Secret" — and 
every other deployment-specific value in the same file is written as 
`${ENV_VAR:default}`. Nothing else in the repository references this reference 
(it is dead config today; the default platform cluster resolves `admin`), so it 
only serves as a way for a deployment that happens to use `rmq-test` to 
silently authenticate with credentials published in the repository.
   
   The values now come from the environment, following the file's convention:
   
   ```yaml
           rmq-test:
             access-key: ${STUDIO_CLUSTER_ADMIN_ACCESS_KEY:}
             secret-key: ${STUDIO_CLUSTER_ADMIN_SECRET_KEY:}
   ```
   
   Leaving them unset stays a supported state: `RuntimeAdminClientResolver` 
already treats a blank pair as unconfigured and answers `422 Admin credential 
reference is not configured: <ref>`, which its own tests pin — so a deployment 
that uses this reference without supplying the keys now gets a clear failure 
instead of the published pair.
   
   ### How Did You Test This Change?
   
   A new `MqAdminCredentialPropertiesTest` binds the shipped `application.yml` 
through `ApplicationContextRunner` + `ConfigDataApplicationContextInitializer` 
(the same pattern `AiConversationPropertiesTest` uses) and asserts both halves: 
the shipped reference carries no usable key, and environment-supplied keys are 
bound to it.
   
   ```
   $ cd server && mvn -B -ntp test -Dtest='MqAdminCredentialPropertiesTest' 
-DforkCount=1
   Tests run: 2, Failures: 0, Errors: 0, Skipped: 0
   ```
   
   Both assertions fail against the current file, so the test pins the change 
rather than restating it:
   
   ```
   # with the trunk file (literals still present)
   expected: "deployment-ak" but was: "rocketmq2"
   Expecting null or empty but was: "rocketmq2"
   
   # with the placeholder renamed (environment no longer wired)
   expected: "deployment-ak" but was: ""
   ```
   
   I did not run the `@SpringBootTest` context test locally: it needs the MySQL 
instance that only CI provisions, and this change does not touch Java code.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [x] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   
   ---
   
   The alternative I did not take: deleting the `rmq-test` entry outright. 
Keeping it as a documented placeholder preserves a working example of the 
reference shape for deployments that use an ACL-enabled cluster.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to