DanielLeens commented on PR #11734: URL: https://github.com/apache/seatunnel/pull/11734#issuecomment-5379740886
@goutamadwant understood, and sorry this is dragging — but the mechanics haven't changed since my Aug 20 comment: my GitHub permissions here are comment-only, so I have no way to re-review as @SEZ9, dismiss their CHANGES_REQUESTED, or override the branch-protection gate myself. Only @SEZ9 re-submitting a review on the current head, or a maintainer with write access using GitHub's "Dismiss review" action, can clear `reviewDecision: REVIEW_REQUIRED`. That's not something I can do mechanically from here. What I can do is give you something concrete to point @SEZ9 to when you ping them, since a bare "please re-review" request is easy to deprioritize. I diffed their Aug 13 CHANGES_REQUESTED (at `f8b61d52ffe2`) against the current head (`86dcca4f`) directly in the doc, issue by issue: - **Issue 1 (blocking) — no auth/redaction requirement on the REST endpoint**: now covered by the "Security and Input Validation" section — `docs/en/engines/zeta/task-failure-history.md:138-140` requires the same `BasicAuthFilter` boundary as the existing job-detail endpoints, and line 142 requires redaction before HA persistence (not just at the REST response). - **Issue 2 — unredacted payloads persisted long-term in HA state**: line 89 now requires sanitizing/bounding content at the capture boundary before it's written to HA or finished-job history, and Acceptance Criteria item 13 (line 184) makes this explicit. - **Issue 3 — raw worker `host:port` leaking topology**: line 150 now states worker addresses are optional and follow the same authorization boundary as the rest of the record. - **Issue 4 — `JobInfoServlet` routing/`limit` validation underspecified**: line 134 now requires exact-path-shape matching (no prefix/substring fallthrough) and line 144-146 requires malformed `jobId`/non-numeric `limit` to return a controlled `400` with no stack trace — matching Acceptance Criteria items 14 and 18 (lines 185, 189). So on the substance, all four of @SEZ9's findings do appear addressed in the current head, not just asserted — that's an independent read from me, not a decision on their behalf. But only @SEZ9 (or a maintainer) can act on it to actually clear the gate. I'd suggest re-pinging them with this line-by-line mapping attached so they can confirm quickly rather than re-reading the whole doc from scratch. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
