danielnadean opened a new pull request, #11568:
URL: https://github.com/apache/seatunnel/pull/11568
### Purpose of this pull request
REST HOCON submission parsed request bodies and uploaded configuration files
without resolving environment substitutions. This change adds the same
capability to both HOCON paths while protecting the Engine process boundary
with an explicit `seatunnel.engine.http.hocon-environment-variable-allowlist`.
The allowlist is empty by default, and JVM system properties are never exposed.
### Does this PR introduce _any_ user-facing change?
Yes. Operators can list environment variable names under
`seatunnel.engine.http.hocon-environment-variable-allowlist`, then use
substitutions such as `job.name = ${JOB_NAME}` in direct or uploaded HOCON REST
submissions. English and Chinese REST/security documentation and the default
configuration template are updated.
### How was this patch tested?
- Added `RestUtilTest` coverage for allowlisted and denied variables, JVM
system-property isolation, internal HOCON references, optional substitutions,
connector placeholders, and ConfigShade decryption ordering.
- Extended YAML parsing coverage for the new allowlist.
- Extended the existing REST integration test for direct HOCON submission,
uploaded HOCON submission, exact resolved job names, and denied-variable
non-disclosure.
- Ran scoped `spotless:apply`, scoped `spotless:check`, and `git diff
--check` locally. Compile and functional test results are delegated to GitHub
CI for the current PR head.
### Check list
* [x] No new Jar binary package is added.
* [x] English and Chinese documentation are updated.
* [x] No incompatible change is introduced.
* [x] This is not a connector change.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]