Frun1na opened a new pull request, #5666:
URL: https://github.com/apache/rocketmq-dashboard/pull/5666
### Which Issue(s) This PR Fixes
- No issue: the change removes a committed literal credential, too small to
need one.
### Brief Description
`application.yml` shipped a literal key pair for the cluster admin
credential reference:
```yaml
credentials:
rmq-test:
access-key: rocketmq2
secret-key: 12345678
```
`MqAdminProperties.Credential` documents the opposite contract — "Access
keys and secret keys must be supplied through externalized Spring
configuration, such as environment variables or a Kubernetes Secret" — and
every other deployment-specific value in the same file is written as
`${ENV_VAR:default}`. Nothing else in the repository references this reference
(it is dead config today; the default platform cluster resolves `admin`), so it
only serves as a way for a deployment that happens to use `rmq-test` to
silently authenticate with credentials published in the repository.
The values now come from the environment, following the file's convention:
```yaml
rmq-test:
access-key: ${STUDIO_CLUSTER_ADMIN_ACCESS_KEY:}
secret-key: ${STUDIO_CLUSTER_ADMIN_SECRET_KEY:}
```
Leaving them unset stays a supported state: `RuntimeAdminClientResolver`
already treats a blank pair as unconfigured and answers `422 Admin credential
reference is not configured: <ref>`, which its own tests pin — so a deployment
that uses this reference without supplying the keys now gets a clear failure
instead of the published pair.
### How Did You Test This Change?
A new `MqAdminCredentialPropertiesTest` binds the shipped `application.yml`
through `ApplicationContextRunner` + `ConfigDataApplicationContextInitializer`
(the same pattern `AiConversationPropertiesTest` uses) and asserts both halves:
the shipped reference carries no usable key, and environment-supplied keys are
bound to it.
```
$ cd server && mvn -B -ntp test -Dtest='MqAdminCredentialPropertiesTest'
-DforkCount=1
Tests run: 2, Failures: 0, Errors: 0, Skipped: 0
```
Both assertions fail against the current file, so the test pins the change
rather than restating it:
```
# with the trunk file (literals still present)
expected: "deployment-ak" but was: "rocketmq2"
Expecting null or empty but was: "rocketmq2"
# with the placeholder renamed (environment no longer wired)
expected: "deployment-ak" but was: ""
```
I did not run the `@SpringBootTest` context test locally: it needs the MySQL
instance that only CI provisions, and this change does not touch Java code.
### Checklist
- [x] One coherent change; unrelated modifications are not bundled in
- [x] Commit subject follows Conventional Commits (`feat:` / `fix:` /
`refactor:` / `chore:` / `docs:` / `perf:`)
- [x] Tests added or updated for non-trivial changes, test methods named
`...Test`
- [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
- [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit
checks)
- [x] New source files carry the ASF license header
- [x] Documentation touched where behaviour changed (README / `docs/` /
in-app help)
---
The alternative I did not take: deleting the `rmq-test` entry outright.
Keeping it as a documented placeholder preserves a working example of the
reference shape for deployments that use an ACL-enabled cluster.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]