DanielLeens commented on PR #10900:
URL: https://github.com/apache/seatunnel/pull/10900#issuecomment-5476919710

   Thanks @SEZ9 for consolidating this so clearly, and it matches my read 
exactly.
   
   To restate for the record on this still-unchanged head (`7d2cd7b3ff32`, no 
new commit since my last check):
   
   - **Issue 1 (unauthenticated `0.0.0.0` listener) is the one remaining 
source-level blocker.** Either an optional shared-secret/allowlist mechanism 
mirroring `connector-edge-socket`'s `__AUTH__:<token>` handshake, or a 
loopback-by-default bind with an explicit opt-in + security warning, would 
resolve it.
   - **Issue 2** is a documentation-only ask now (at-most-once delivery 
semantics on task failure) — no code change needed, and the parallelism 
sub-point is already covered by the framework-level `checkArgument` as noted 
above.
   - **Issues 3-5** are agreed/verified Medium/Low items worth folding into the 
same pass since they touch the same small config/docs surface, but none of them 
block on their own.
   
   @MartinLam12, once Issue 1 has an auth/allowlist story, I don't see a 
remaining blocker from my side, and I'm happy to do a full re-review as soon as 
a new commit lands. If you're stuck on the approach or short on time, flagging 
that here works too — the community (myself included) is glad to help get this 
across the line.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to