DanielLeens commented on PR #11734:
URL: https://github.com/apache/seatunnel/pull/11734#issuecomment-5379740886

   @goutamadwant understood, and sorry this is dragging — but the mechanics 
haven't changed since my Aug 20 comment: my GitHub permissions here are 
comment-only, so I have no way to re-review as @SEZ9, dismiss their 
CHANGES_REQUESTED, or override the branch-protection gate myself. Only @SEZ9 
re-submitting a review on the current head, or a maintainer with write access 
using GitHub's "Dismiss review" action, can clear `reviewDecision: 
REVIEW_REQUIRED`. That's not something I can do mechanically from here.
   
   What I can do is give you something concrete to point @SEZ9 to when you ping 
them, since a bare "please re-review" request is easy to deprioritize. I diffed 
their Aug 13 CHANGES_REQUESTED (at `f8b61d52ffe2`) against the current head 
(`86dcca4f`) directly in the doc, issue by issue:
   
   - **Issue 1 (blocking) — no auth/redaction requirement on the REST 
endpoint**: now covered by the "Security and Input Validation" section — 
`docs/en/engines/zeta/task-failure-history.md:138-140` requires the same 
`BasicAuthFilter` boundary as the existing job-detail endpoints, and line 142 
requires redaction before HA persistence (not just at the REST response).
   - **Issue 2 — unredacted payloads persisted long-term in HA state**: line 89 
now requires sanitizing/bounding content at the capture boundary before it's 
written to HA or finished-job history, and Acceptance Criteria item 13 (line 
184) makes this explicit.
   - **Issue 3 — raw worker `host:port` leaking topology**: line 150 now states 
worker addresses are optional and follow the same authorization boundary as the 
rest of the record.
   - **Issue 4 — `JobInfoServlet` routing/`limit` validation underspecified**: 
line 134 now requires exact-path-shape matching (no prefix/substring 
fallthrough) and line 144-146 requires malformed `jobId`/non-numeric `limit` to 
return a controlled `400` with no stack trace — matching Acceptance Criteria 
items 14 and 18 (lines 185, 189).
   
   So on the substance, all four of @SEZ9's findings do appear addressed in the 
current head, not just asserted — that's an independent read from me, not a 
decision on their behalf. But only @SEZ9 (or a maintainer) can act on it to 
actually clear the gate. I'd suggest re-pinging them with this line-by-line 
mapping attached so they can confirm quickly rather than re-reading the whole 
doc from scratch.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to