sudeephazra commented on PR #12293:
URL: https://github.com/apache/seatunnel/pull/12293#issuecomment-5883807357

   @SEZ9 Please see below
   
   - Validation rules and template: Done. Account/container naming, endpoint 
suffix, authentication-mode exclusivity, and blocked hadoop_adls_properties 
keys are enforced in ADLSConfigValidator. The same rules are documented under 
“ADLS configuration rules” in all four en/zh source and sink pages. The 
lowercase replacewithaccount and replacewithcontainer values in 
config/v2.batch.adls.config.template satisfy those naming rules; the account 
key remains an environment variable.
   
   - OAuth endpoint validation: Done. tenant_id and authority_host are 
validated before the token endpoint is assembled. The authority must be an 
HTTPS origin without user info, port redirection/path, query, or fragment, and 
the tenant must be a GUID or DNS name. This is covered by ADLSConfigValidator, 
ADLSRuntimeCompatibility, and the corresponding validator/runtime/Hadoop-conf 
tests.
   
   - Option-table coverage and en/zh alignment: Done for the ADLS and file 
options registered by the source and sink factories; shared framework options 
remain linked through the common-options row. The en/zh sink option keys are 
aligned.
   
   - account_key log masking: Done. account_key was added to 
ConfigShadeUtils.DEFAULT_LOG_MASK_ONLY_KEYWORDS. The en/zh source and sink docs 
also note that this is global core-starter log masking rather than 
configuration encryption.
   
   - English source defaults: Done. The English source table now shows 
discovery_mode = ONCE and start_mode = EARLIEST, matching FileBaseSourceOptions 
and the Chinese page.
   
   - ABFS advanced-property denylist: Done. The validator blocks routing, 
credential, token-provider, and class-loading prefixes, including 
fs.azure.account.oauth, fs.azure.sas., fs.azure.delegation., 
fs.azure.enable.delegation.token, fs.azure.identity., and 
fs.azure.shellkeyprovider.. The behavior is covered by ADLSConfigValidatorTest 
and documented in the en/zh source and sink pages.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to