wiasliaw opened a new pull request, #73599:
URL: https://github.com/apache/airflow/pull/73599

   ## Why
   
   #73179 made `airflow info --anonymize` mask a netloc-less connection string 
by handing the whole value to `process_path`, whose username substitution is an 
unanchored substring replacement — so the scheme itself is in the replacement's 
reach. An OS username that happens to be a substring of the scheme corrupts the 
report:
   
   ```
   username "lite":  sqlite:////home/lite/airflow.db  ->  
sq${USER}:///${HOME}/airflow.db
   username "db":    duckdb:////home/db/wh.duckdb     ->  
duck${USER}:///${HOME}/wh.duck${USER}
   ```
   
   This was called out as an optional follow-up in the review of #73179.
   
   ## What
   
   `airflow-core/src/airflow/cli/commands/info_command.py` — the netloc-less 
branch of `PiiAnonymizer.process_url` now splits the value on the first colon 
and masks only what follows, so the scheme is out of the substitution's reach. 
Output is byte-identical for every realistic input (checked against the Docker 
`sqlite:////opt/${USER}/${USER}.db` case, `sqlite:///:memory:`, `sqlite://`); a 
side effect is that non-URL fallback values such as `NOT AVAILABLE` are no 
longer touched by the substitution either.
   
   Covered by a new parametrized test that mocks `getuser`/`expanduser` to 
force the colliding usernames; all three cases fail without the change, and the 
existing `test_should_remove_pii_from_url` cases are unchanged.
   
   No newsfragment: CLI output fix, not a major or breaking change.
   
   related: #73179
   
   ## Verification
   
   Run the anonymizer unit tests:
   
   ```bash
   uv run --project airflow-core pytest 
airflow-core/tests/unit/cli/commands/test_info_command.py::TestPiiAnonymizer -v
   ```
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [X] Yes — Claude Code (Fable 5)
   
   Generated-by: Claude Code (Fable 5) following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to