DanielLeens commented on issue #12025: URL: https://github.com/apache/seatunnel/issues/12025#issuecomment-5493783666
Thanks for picking this up and for opening PR #12040 so quickly. I rechecked the current `dev` source on September 1, 2026 before replying. The gap is real in the shared HTTP base path: `HttpParameter` still uses Lombok `@Data` while carrying raw `headers`, and `buildWithConfig(...)` accepts the configured URL and headers without any scheme validation before the source/sink paths use them. Keeping the first fix centered in `connector-http-base` is the right direction. For this PR, please keep these guardrails: 1. Apply the credential redaction on the shared `HttpParameter` path, not one connector at a time. 2. Make the transport check depend on the presence of credential-bearing headers, so plain unauthenticated `http://` test endpoints do not break accidentally. 3. Cover both source and sink flows with focused tests. 4. Avoid logging raw header values anywhere in new validation failures. With that boundary, this issue is in the "fix in progress" stage rather than a per-connector follow-up. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
