lasdf1234 opened a new pull request, #13366: URL: https://github.com/apache/gravitino/pull/13366
### What changes were proposed in this pull request? - Add `RegisteredPropertyKeys`, a registry of Gravitino-defined property keys (base, credential, cloud storage, and connector official keys) with hidden/reserved semantics. - Change `HiddenPropertyMaskUtils` so name-based (fuzzy) masking applies only to keys **not** in that registry. Official keys omitted from the current catalog metadata still follow the registry's `hidden` / `reserved` flags (for example a Glue runtime copy of `s3-access-key-id`). - Align `SecretPropertyUtils.shouldRecoverSensitiveNamedSecret` with the same rule so `getSecrets` no longer fuzzy-recovers official non-hidden identifiers. - Update unit tests for cross-catalog consistency and unknown sensitive names. ### Why are the changes needed? Per-catalog `PropertiesMetadata` made fuzzy masking inconsistent: the same official key could be cleartext on one catalog and masked on another when only one metadata declared it. Declaring a credential property also skipped name-based masking while an undeclared copy of the same value did not. Fix: #13353 ### Does this PR introduce _any_ user-facing change? API responses may change for catalogs that previously fuzzy-masked official non-hidden keys (for example `s3-access-key-id` copied onto Glue): those values now follow the official `hidden=false` definition and remain visible in `properties()`, consistent with catalogs that already declare them. Unknown sensitive-named keys are still masked. Official hidden secrets remain masked / recoverable via `getSecrets`. ### How was this patch tested? - `./gradlew :core:spotlessApply` - `./gradlew :core:test --tests 'org.apache.gravitino.connector.TestHiddenPropertyMaskUtils' --tests 'org.apache.gravitino.connector.TestRegisteredPropertyKeys' --tests 'org.apache.gravitino.secret.TestSecretPropertyUtils' -PskipITs` - `./gradlew :core:test --tests 'org.apache.gravitino.secret.*' -PskipITs` Made with [Cursor](https://cursor.com) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
