vyommani opened a new pull request, #1152:
URL: https://github.com/apache/ranger/pull/1152

   
   ## What changes were proposed in this pull request?
   
   Service config masking (read) and encryption (write) previously only matched 
the literal key "password". Service-defs can declare other config items with 
type="password" under different names (e.g. NiFi's nifi.ssl.keystorePassword 
/truststorePassword) - those were left unmasked/unencrypted.
   
   This change treats any config item as a secret if its key is "password" OR 
the service-def declares it with type="password", applied consistently across 
RangerServiceService (read/view) and ServiceDBStore (create/update). 
updateService now preserves the correct per-key value on the hidden-sentinel 
case instead of a single shared variable. Shared classification logic lives in 
one place (ServiceDBStore) to avoid drift.
   
   
   ## How was this patch tested?
   
   Added/updated unit tests in TestRangerServiceService and TestServiceDBStore 
covering masking, encryption, and per-key update behavior for 
service-def-declared secret keys.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to