This is an automated email from the ASF dual-hosted git repository.
yuqi1129 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/main by this push:
new 11981f8e62 [#13246] fix(catalog-common): complete the static
credential key set for GVFS filtering (#13247)
11981f8e62 is described below
commit 11981f8e6287d39f9bccdf4adf9135432dc4ab18
Author: YangJie <[email protected]>
AuthorDate: Sun Sep 20 21:42:11 2026 -0400
[#13246] fix(catalog-common): complete the static credential key set for
GVFS filtering (#13247)
### What changes were proposed in this pull request?
Adds `azure-client-secret` to the `STATIC_CREDENTIAL_KEYS` set that
`omitStaticCredentialProperties` strips from a fileset catalog's
properties before they are merged into GVFS client configuration. This
branch merges the latest `main` (whose #13204 reframed the set to
secret-bearing cloud-storage keys only) and follows that contract:
`azure-client-secret` is a shared cloud-storage secret (declared in
`AzurePropertiesMetadata` and pulled into
`FilesetCatalogPropertiesMetadata`) that reaches the GVFS/HCFS storage
config for ABS/ADLS filesets, and it was the one such secret still
missing from the set.
Access-key IDs are intentionally left out (they are non-hidden and must
stay available from `properties()`). Glue and Paimon-DLF credentials are
out of scope: they are catalog-connection credentials declared only in
their own catalogs' `PropertiesMetadata` (already masked via `hidden`),
and never appear in the fileset-catalog properties map this filter
governs.
### Why are the changes needed?
`azure-client-secret` is a cloud-storage secret consumed by fileset
catalogs, but it was missing from the strip set, so it could pass
through into GVFS client configuration.
### Does this PR introduce _any_ user-facing change?
No. No property keys are added or removed. One additional secret
(`azure-client-secret`) is now stripped from fileset-catalog REST
metadata before it is merged into GVFS client configuration.
### How was this patch tested?
`TestCloudStorageCredentialPropertyKeys` asserts `azure-client-secret`
is detected by `isStaticCredentialKey` and stripped by
`omitStaticCredentialProperties`, that access-key IDs survive, and that
the Glue and DLF catalog secrets are not treated as cloud-storage
credential keys.
Fix: #13246
---
.../CloudStorageCredentialPropertyKeys.java | 1 +
.../TestCloudStorageCredentialPropertyKeys.java | 46 ++++++++++++++++++++++
2 files changed, 47 insertions(+)
diff --git
a/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
b/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
index 97bae3cef1..962c87d770 100644
---
a/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
+++
b/catalogs/catalog-common/src/main/java/org/apache/gravitino/storage/CloudStorageCredentialPropertyKeys.java
@@ -50,6 +50,7 @@ public final class CloudStorageCredentialPropertyKeys {
S3Properties.GRAVITINO_S3_SECRET_ACCESS_KEY,
OSSProperties.GRAVITINO_OSS_ACCESS_KEY_SECRET,
AzureProperties.GRAVITINO_AZURE_STORAGE_ACCOUNT_KEY,
+ AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET,
COSProperties.GRAVITINO_COS_ACCESS_KEY_SECRET);
private CloudStorageCredentialPropertyKeys() {}
diff --git
a/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
b/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
index 768890dd8f..b4affbee94 100644
---
a/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
+++
b/catalogs/catalog-common/src/test/java/org/apache/gravitino/storage/TestCloudStorageCredentialPropertyKeys.java
@@ -23,6 +23,8 @@ import static org.junit.jupiter.api.Assertions.assertFalse;
import static org.junit.jupiter.api.Assertions.assertTrue;
import java.util.Map;
+import org.apache.gravitino.catalog.glue.GlueConstants;
+import org.apache.gravitino.catalog.lakehouse.paimon.PaimonConstants;
import org.junit.jupiter.api.Test;
public class TestCloudStorageCredentialPropertyKeys {
@@ -64,5 +66,49 @@ public class TestCloudStorageCredentialPropertyKeys {
assertFalse(
CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
COSProperties.GRAVITINO_COS_REGION));
+
+ // Azure client secret is a cloud-storage static credential and is
stripped.
+ assertTrue(
+ CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+ AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET));
+
+ // Glue/Paimon-DLF secrets are catalog/metastore-connection credentials,
not cloud-storage
+ // secrets in the fileset properties map this filter governs; they never
reach it (declared
+ // hidden and outside FilesetCatalogPropertiesMetadata), so this set must
not claim them.
+ assertFalse(
+ CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+ GlueConstants.AWS_SECRET_ACCESS_KEY));
+ assertFalse(
+ CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+ PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_SECRET));
+ assertFalse(
+ CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+ PaimonConstants.GRAVITINO_DLF_SECURITY_TOKEN));
+
+ // Access key IDs are non-hidden identifiers, not secrets; they behave
like s3/oss/cos IDs.
+ assertFalse(
+
CloudStorageCredentialPropertyKeys.isStaticCredentialKey(GlueConstants.AWS_ACCESS_KEY_ID));
+ assertFalse(
+ CloudStorageCredentialPropertyKeys.isStaticCredentialKey(
+ PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID));
+ }
+
+ @Test
+ void testAzureClientSecretStrippedButAccessKeyIdsSurvive() {
+ Map<String, String> input =
+ Map.of(
+ AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET, "aad-secret",
+ GlueConstants.AWS_ACCESS_KEY_ID, "ak",
+ PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID, "dlf-ak");
+
+ Map<String, String> filtered =
+
CloudStorageCredentialPropertyKeys.omitStaticCredentialProperties(input);
+
+ // azure-client-secret is the sole branch-added cloud-storage secret this
filter strips.
+
assertFalse(filtered.containsKey(AzureProperties.GRAVITINO_AZURE_CLIENT_SECRET));
+
+ // Access key IDs are non-hidden identifiers and must survive in
properties().
+ assertEquals("ak", filtered.get(GlueConstants.AWS_ACCESS_KEY_ID));
+ assertEquals("dlf-ak",
filtered.get(PaimonConstants.GRAVITINO_DLF_ACCESS_KEY_ID));
}
}