The GitHub Actions job "CI" on 
rocketmq-dashboard.git/fix/model-credential-tostring has failed.
Run started by GitHub user Frun1na (triggered by Frun1na).

Head commit for run:
bb76eb165c4f87f6eff3d6b257f0ba6b6b1856ba / Apulupie 
<[email protected]>
fix(model): keep the data source and ACL 2.0 credentials out of toString

fix(model): keep the data source and ACL 2.0 credentials out of toString

The certificate redaction fix (#4555) listed the credential-bearing types that 
still print their
secrets in the generated representation; #6094 covered the persistence and ACL 
ones
(RmqCloudCredential, RmqAclUser, RmqDataSource, PlainAccessConfigVO) and these 
two are the rest.
MetricsDataSourceConfig carries the data source password and bearer token - its 
own javadoc calls
them sensitive - and Acl2PolicyContext carries an ACL access key and secret 
key; a Lombok @Data
toString prints both, so any log line, exception message or diagnostic dump 
that renders one of
them writes the credential to disk. MetricsDataSourceQueryRequest, the request 
counterpart of the
data source model, already excludes exactly these two fields.

CredentialModelToStringRedactionTest: 2 tests green, 0 checkstyle violations. 
AclServiceTest /
MetricsServiceTest / MultiBackendMetricsSourceTest stay green, and both new 
tests fail on the
unfixed code with the rendered credential in the assertion output.

Report URL: 
https://github.com/apache/rocketmq-dashboard/actions/runs/38040829094

With regards,
GitHub Actions via GitBox

Reply via email to