davsclaus commented on code in PR #26997:
URL: https://github.com/apache/camel/pull/26997#discussion_r4129735359


##########
core/camel-base/src/main/java/org/apache/camel/component/properties/DefaultPropertiesParser.java:
##########
@@ -369,7 +373,7 @@ private String getPropertyValue(String prevKey, String key, 
String input) {
                     } else {
                         if (log.isDebugEnabled()) {
                             log.debug("Property with key [{}] applied by 
function [{}] -> {}", key, function.getName(),
-                                    value);
+                                    function.isSensitive() ? MASK : mask(key, 
value));

Review Comment:
   Confirmed, thanks. Fixed in eed49e2aff6f: the function line checks the key 
without the function prefix, and `isSensitiveKey` in `PropertiesComponent` 
checks both the part before the first `:` (key with a default value) and the 
part after it (the key of a function). `{{sys:DB_PASSWORD}}` is now in 
`PropertiesComponentMaskSensitiveLogTest`.
   
   _Claude Code on behalf of davsclaus_



##########
core/camel-base/src/main/java/org/apache/camel/component/properties/PropertiesComponent.java:
##########
@@ -346,7 +380,9 @@ protected String parseUri(final String uri, 
PropertiesLookup properties, boolean
             // Remove the escape characters if any
             answer = unescape(answer);
         }
-        LOG.trace("Parsed uri {} -> {}", uri, answer);
+        if (LOG.isTraceEnabled()) {
+            LOG.trace("Parsed uri {} -> {}", uri, isSensitive(uri) ? "xxxxxx" 
: answer);

Review Comment:
   Fixed in eed49e2aff6f. Rather than threading a flag through the parser, the 
summary line reuses the resolved-value record that the parser already updates: 
a placeholder key whose resolved value came from a sensitive function 
(`source`) is treated as sensitive. The properties dev console now also masks a 
value whose `source` is a sensitive function. Added `{{app.db.conn}}` → 
`{{myvault:db/conn}}` to the test.
   
   _Claude Code on behalf of davsclaus_



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to