Skip to content

[DSIP-105][API] Encrypt sensitive definition params with PasswordUtils - #18659

Open
det101 wants to merge 4 commits into
apache:devfrom
det101:feature-18587-sensitive-encrypt
Open

det101 wants to merge 4 commits into
apache:devfrom
det101:feature-18587-sensitive-encrypt

Conversation

@det101

@det101 det101 commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Purpose

Implements #18587 (subtask of #17937 / DSIP-105). Depends on #18586 / #18585.

Reuse PasswordUtils for definition-time at-rest protection of sensitive=true values when datasource.encryption.enable=true. Do not change datasource CRUD. Runtime instance params stay plaintext materialization; API/UI still return masked copies only.

Changes

  • Definition create/update: merge keep-original (******) then encode new sensitive plaintext; skip re-encode when value equals existing sensitive DB value
  • Instance update: merge only (no encode)
  • Start path: decrypt definition globals before restoreStartParams
  • Master: decrypt definition globals before instance materialization; decrypt localParams in TaskExecutionContext / prepare-params so Worker receives plaintext
  • Same-cluster Copy unchanged (JSON copied as-is)

Tests

  • Unit tests for encode on create, keep-original no double-encrypt, false→true keep-original then encode, encryption flag on/off, start-path decrypt, Master localParams decrypt

Related issues

@SbloodyS SbloodyS added feature new feature DSIP labels Sep 24, 2026
@SbloodyS SbloodyS added this to the 3.5.0 milestone Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants