vyommani opened a new pull request, #1152: URL: https://github.com/apache/ranger/pull/1152
## What changes were proposed in this pull request? Service config masking (read) and encryption (write) previously only matched the literal key "password". Service-defs can declare other config items with type="password" under different names (e.g. NiFi's nifi.ssl.keystorePassword /truststorePassword) - those were left unmasked/unencrypted. This change treats any config item as a secret if its key is "password" OR the service-def declares it with type="password", applied consistently across RangerServiceService (read/view) and ServiceDBStore (create/update). updateService now preserves the correct per-key value on the hidden-sentinel case instead of a single shared variable. Shared classification logic lives in one place (ServiceDBStore) to avoid drift. ## How was this patch tested? Added/updated unit tests in TestRangerServiceService and TestServiceDBStore covering masking, encryption, and per-key update behavior for service-def-declared secret keys. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
