Frun1na opened a new pull request, #6094:
URL: https://github.com/apache/rocketmq-dashboard/pull/6094

   ### Which Issue(s) This PR Fixes
   
   - Fixes #6091
   
   ### Brief Description
   
   A Lombok `@Data` class prints every field, secret columns included, so one 
log line, exception message or
   diagnostic dump that renders one of these objects writes the credential to 
disk. The repository already
   excludes the secret fields of the other credential types (`RmqSettings`, 
`RmqStudioUser`,
   `RmqK8sCertificate`, `K8sCertVO`, `CreateCloudCredentialDTO`, 
`UpsertPlainAccessConfigDTO`,
   `DataSourceTestDTO`, `MetricsDataSourceQueryRequest`, `GeneralSettingsVO`, 
`GeneralSettingsUpdateDTO`,
   `LoginDTO`, `ResetPasswordDTO`), and the note on the certificate redaction 
fix (#4555) names the missing ones
   as a follow-up.
   
   `RmqCloudCredential` and `RmqAclUser` now exclude `accessKey` / `secretKey`, 
`RmqDataSource` excludes `json`
   (the serialized `MetricsDataSourceConfig` carries `password` / 
`bearerToken`, which that model's own javadoc
   calls sensitive), and `PlainAccessConfigVO` excludes `accessKey` / 
`secretKey`, matching the request DTO for
   the same model. Persistence, JSON shape and the API responses are untouched: 
only the generated
   representations change, so a log line that renders one of these objects no 
longer carries the secret.
   
   ### How Did You Test This Change?
   
   ```
   cd server && mvn -B -ntp -DforkCount=1 
-Dtest=CredentialToStringRedactionTest test
   [INFO] --- checkstyle:3.6.0:check (validate) @ rocketmq-studio ---
   [INFO] Tests run: 4, Failures: 0, Errors: 0, Skipped: 0
   [INFO] BUILD SUCCESS
   
   mvn -B -ntp -DforkCount=1 test          (whole server module)
   [ERROR] Tests run: 3438, Failures: 0, Errors: 19, Skipped: 0
   ```
   
   The 19 errors are the `@SpringBootTest` classes failing to load their 
context on `Communications link
   failure` (this machine has no MySQL 8 container); every other test passes.
   
   The new tests fail without the fix, with only the four product files 
reverted:
   
   ```
   [ERROR] Tests run: 4, Failures: 4, Errors: 0, Skipped: 0
   
CredentialToStringRedactionTest.cloudCredentialEntityToStringShouldExcludeTheCredentialTest
 -- <<< FAILURE!
   Expecting actual:
     "RmqCloudCredential(id=null, name=aliyun-prod, vendor=null, 
accessKey=sensitive-access-key, secretKey=sensitive-secret-key, remark=null, 
gmtCreate=null, gmtModified=null)"
   not to contain:
     "sensitive-access-key"
   
CredentialToStringRedactionTest.aclUserEntityToStringShouldExcludeTheCredentialTest
 -- <<< FAILURE!
     "RmqAclUser(id=null, username=order-service, 
accessKey=sensitive-access-key, secretKey=sensitive-secret-key, admin=null, 
clusters=null, whiteRemoteAddress=null, gmtCreate=null, gmtModified=null)"
   
CredentialToStringRedactionTest.dataSourceEntityToStringShouldExcludeTheSerializedConfigurationTest
 -- <<< FAILURE!
     "RmqDataSource(id=null, dsKey=prometheus-prod, 
json={"username":"sensitive-access-key","password":"sensitive-secret-key"}, 
gmtCreate=null, gmtModified=null)"
   
CredentialToStringRedactionTest.plainAccessConfigToStringShouldExcludeTheCredentialTest
 -- <<< FAILURE!
     "PlainAccessConfigVO(accessKey=sensitive-access-key, 
secretKey=sensitive-secret-key, whiteRemoteAddress=10.0.0.0/8, admin=false, 
...)"
   ```
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to