Frun1na opened a new pull request, #6094:
URL: https://github.com/apache/rocketmq-dashboard/pull/6094
### Which Issue(s) This PR Fixes
- Fixes #6091
### Brief Description
A Lombok `@Data` class prints every field, secret columns included, so one
log line, exception message or
diagnostic dump that renders one of these objects writes the credential to
disk. The repository already
excludes the secret fields of the other credential types (`RmqSettings`,
`RmqStudioUser`,
`RmqK8sCertificate`, `K8sCertVO`, `CreateCloudCredentialDTO`,
`UpsertPlainAccessConfigDTO`,
`DataSourceTestDTO`, `MetricsDataSourceQueryRequest`, `GeneralSettingsVO`,
`GeneralSettingsUpdateDTO`,
`LoginDTO`, `ResetPasswordDTO`), and the note on the certificate redaction
fix (#4555) names the missing ones
as a follow-up.
`RmqCloudCredential` and `RmqAclUser` now exclude `accessKey` / `secretKey`,
`RmqDataSource` excludes `json`
(the serialized `MetricsDataSourceConfig` carries `password` /
`bearerToken`, which that model's own javadoc
calls sensitive), and `PlainAccessConfigVO` excludes `accessKey` /
`secretKey`, matching the request DTO for
the same model. Persistence, JSON shape and the API responses are untouched:
only the generated
representations change, so a log line that renders one of these objects no
longer carries the secret.
### How Did You Test This Change?
```
cd server && mvn -B -ntp -DforkCount=1
-Dtest=CredentialToStringRedactionTest test
[INFO] --- checkstyle:3.6.0:check (validate) @ rocketmq-studio ---
[INFO] Tests run: 4, Failures: 0, Errors: 0, Skipped: 0
[INFO] BUILD SUCCESS
mvn -B -ntp -DforkCount=1 test (whole server module)
[ERROR] Tests run: 3438, Failures: 0, Errors: 19, Skipped: 0
```
The 19 errors are the `@SpringBootTest` classes failing to load their
context on `Communications link
failure` (this machine has no MySQL 8 container); every other test passes.
The new tests fail without the fix, with only the four product files
reverted:
```
[ERROR] Tests run: 4, Failures: 4, Errors: 0, Skipped: 0
CredentialToStringRedactionTest.cloudCredentialEntityToStringShouldExcludeTheCredentialTest
-- <<< FAILURE!
Expecting actual:
"RmqCloudCredential(id=null, name=aliyun-prod, vendor=null,
accessKey=sensitive-access-key, secretKey=sensitive-secret-key, remark=null,
gmtCreate=null, gmtModified=null)"
not to contain:
"sensitive-access-key"
CredentialToStringRedactionTest.aclUserEntityToStringShouldExcludeTheCredentialTest
-- <<< FAILURE!
"RmqAclUser(id=null, username=order-service,
accessKey=sensitive-access-key, secretKey=sensitive-secret-key, admin=null,
clusters=null, whiteRemoteAddress=null, gmtCreate=null, gmtModified=null)"
CredentialToStringRedactionTest.dataSourceEntityToStringShouldExcludeTheSerializedConfigurationTest
-- <<< FAILURE!
"RmqDataSource(id=null, dsKey=prometheus-prod,
json={"username":"sensitive-access-key","password":"sensitive-secret-key"},
gmtCreate=null, gmtModified=null)"
CredentialToStringRedactionTest.plainAccessConfigToStringShouldExcludeTheCredentialTest
-- <<< FAILURE!
"PlainAccessConfigVO(accessKey=sensitive-access-key,
secretKey=sensitive-secret-key, whiteRemoteAddress=10.0.0.0/8, admin=false,
...)"
```
### Checklist
- [x] One coherent change; unrelated modifications are not bundled in
- [x] Commit subject follows Conventional Commits (`feat:` / `fix:` /
`refactor:` / `chore:` / `docs:` / `perf:`)
- [x] Tests added or updated for non-trivial changes, test methods named
`...Test`
- [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
- [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit
checks)
- [x] New source files carry the ASF license header
- [ ] Documentation touched where behaviour changed (README / `docs/` /
in-app help)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]