Frun1na opened a new pull request, #6123:
URL: https://github.com/apache/rocketmq-dashboard/pull/6123

   ### Which Issue(s) This PR Fixes
   
   - Fixes #6122
   
   ### Brief Description
   
   A Lombok `@Data` class prints every field, secret fields included, so one 
log line, exception message or
   diagnostic dump that renders these objects writes the credential to disk. 
The certificate redaction fix (#4555)
   listed the credential-bearing types that still did that as its follow-up; 
#6094 covered the persistence and ACL
   ones (`RmqCloudCredential`, `RmqAclUser`, `RmqDataSource`, 
`PlainAccessConfigVO`) and these are the remaining
   two:
   
   - `model/MetricsDataSourceConfig` now excludes `password` and `bearerToken` 
— the two fields its own javadoc
     calls sensitive and the same two `MetricsDataSourceQueryRequest`, its 
request counterpart, already excludes.
   - `model/Acl2PolicyContext` now excludes `accessKey` and `secretKey`, 
matching `UpsertPlainAccessConfigDTO`.
   
   Persistence, JSON shape and the API responses are untouched: only the 
generated representations change, so a log
   line that renders one of these objects no longer carries the secret.
   
   ### How Did You Test This Change?
   
   ```
   cd server && mvn -B -ntp test -DforkCount=1 
-Dsurefire.failIfNoSpecifiedTests=false \
     
-Dtest=CredentialModelToStringRedactionTest,AclServiceTest,MetricsServiceTest,MultiBackendMetricsSourceTest
   [INFO] --- checkstyle:3.6.0:check (validate) @ rocketmq-studio ---
   [INFO] Tests run: 36, Failures: 0, Errors: 0, Skipped: 0
   [INFO] BUILD SUCCESS
   ```
   
   Both new tests fail without the fix, with only the two product files 
reverted:
   
   ```
   [ERROR] Tests run: 2, Failures: 2, Errors: 0, Skipped: 0
   dataSourceConfigToStringShouldExcludeTheCredentialsTest -- <<< FAILURE!
   Expecting actual:
     "MetricsDataSourceConfig(name=prometheus-prod, url=http://prometheus:9090, 
authType=null, username=null, password=sensitive-secret-material, 
bearerToken=sensitive-secret-material, providerType=PROMETHEUS, 
tlsEnabled=false, ...)"
   not to contain:
     "sensitive-secret-material"
   acl2PolicyContextToStringShouldExcludeTheCredentialsTest -- <<< FAILURE!
   Expecting actual:
     "Acl2PolicyContext(accessKey=sensitive-secret-material, 
secretKey=sensitive-secret-material, ...)"
   not to contain:
     "sensitive-secret-material"
   ```
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to