bamaer opened a new pull request, #8396: URL: https://github.com/apache/hop/pull/8396
…, fixes #8392 verifyingSsl had no initialiser, so a resolver verified the secrets server's certificate only when someone ticked the option. Both resolvers extend the same base class, so neither did. The initialiser alone is not enough: both serializers overwrite a boolean with HopMetadataProperty.defaultBoolean() before reading the stored value, so the annotation carries the default and the initialiser covers resolvers built in code. The property is serialised per resolver and booleans are always written, so this only reaches resolvers created from now on. Definitions saved with the option off keep reaching the secrets server unverified, which the docs now tell operators to go and check. A resolver that does so on an https address logs a warning, once per address; plain http has no certificate to verify and stays quiet. The vault integration-test project gained a second Vault on HTTPS with a self-signed certificate and three resolvers against it: one given the CA, one without it, and one that stores verifyingSsl=false. Only the middle one fails to resolve, and the third proves existing definitions keep working. **Please** add a meaningful description for your change here ------------------------ Thank you for your contribution! Follow this checklist to help us incorporate your contribution quickly and easily: - [x] Run `mvn clean install apache-rat:check` to make sure basic checks pass. A more thorough check will be performed on your pull request automatically. - [x] If you have a group of commits related to the same change, please squash your commits into one and force push your branch using `git rebase -i`. - [x] Mention the appropriate issue in your description (for example: `addresses #123`), if applicable. To make clear that you license your contribution under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) you have to acknowledge this by using the following check-box. - [x] I hereby declare this contribution to be licensed under the [Apache License Version 2.0, January 2004](http://www.apache.org/licenses/LICENSE-2.0) - [ ] In any other case, please file an [Apache Individual Contributor License Agreement](https://www.apache.org/licenses/icla.pdf). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
