DanielLeens commented on issue #12025:
URL: https://github.com/apache/seatunnel/issues/12025#issuecomment-5493783666

   Thanks for picking this up and for opening PR #12040 so quickly.
   
   I rechecked the current `dev` source on September 1, 2026 before replying. 
The gap is real in the shared HTTP base path: `HttpParameter` still uses Lombok 
`@Data` while carrying raw `headers`, and `buildWithConfig(...)` accepts the 
configured URL and headers without any scheme validation before the source/sink 
paths use them.
   
   Keeping the first fix centered in `connector-http-base` is the right 
direction. For this PR, please keep these guardrails:
   
   1. Apply the credential redaction on the shared `HttpParameter` path, not 
one connector at a time.
   2. Make the transport check depend on the presence of credential-bearing 
headers, so plain unauthenticated `http://` test endpoints do not break 
accidentally.
   3. Cover both source and sink flows with focused tests.
   4. Avoid logging raw header values anywhere in new validation failures.
   
   With that boundary, this issue is in the "fix in progress" stage rather than 
a per-connector follow-up.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to