det101 opened a new pull request, #18659: URL: https://github.com/apache/dolphinscheduler/pull/18659
## Purpose Implements #18587 (subtask of #17937 / DSIP-105). Depends on #18586 / #18585. Reuse `PasswordUtils` for definition-time at-rest protection of `sensitive=true` values when `datasource.encryption.enable=true`. Do not change datasource CRUD. Runtime instance params stay plaintext materialization; API/UI still return masked copies only. ## Changes - Definition create/update: merge keep-original (`******`) then encode new sensitive plaintext; skip re-encode when value equals existing sensitive DB value - Instance update: merge only (no encode) - Start path: decrypt definition globals before `restoreStartParams` - Master: decrypt definition globals before instance materialization; decrypt `localParams` in `TaskExecutionContext` / prepare-params so Worker receives plaintext - Same-cluster Copy unchanged (JSON copied as-is) ## Tests - Unit tests for encode on create, keep-original no double-encrypt, `false→true` keep-original then encode, encryption flag on/off, start-path decrypt, Master localParams decrypt ## Related issues - Parent: #17937 - This subtask: #18587 - Previous: #18586 / #18585 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
