chovy-3012 opened a new pull request, #12403:
URL: https://github.com/apache/seatunnel/pull/12403

   <!--
   
   Thank you for contributing to SeaTunnel! Please make sure that your code 
changes
   are covered with tests. And in case of new features or big changes
   remember to adjust the documentation.
   
   Feel free to ping committers for the review!
   
   ## Contribution Checklist
     - Make sure that the pull request corresponds to a [GITHUB 
issue](https://github.com/apache/seatunnel/issues).
     - Name the pull request in the form "[Feature] [component] Title of the 
pull request", where *Feature* can be replaced by `Hotfix`, `Bug`, etc.
     - Minor fixes should be named following this pattern: `[hotfix] [docs] Fix 
typo in README.md doc`.
   -->
   
   ### Purpose of this pull request
   
   <!-- Describe the purpose of this pull request. For example: This pull 
request adds checkstyle plugin.-->
   Add two AES crypto functions to the Zeta SQL engine:
   - AES_ENCRYPT(value, key[, iv]): encrypts with AES/CBC/PKCS5Padding and
     returns a Base64-encoded ciphertext. Returns null for null input.
   - AES_DECRYPT(value, key[, iv]): decrypts a Base64 ciphertext and returns
     the UTF-8 plaintext. Returns null for null input.
   Key handling:
   - A key prefixed with "base64:" is decoded as a raw AES key (16/24/32
     bytes for AES-128/192/256), matching the FieldEncrypt AesCbcEncryptor
     key format.
   - Otherwise the passphrase is hashed with SHA-256 and the first 16 bytes
     are used as an AES-128 key, so arbitrary-length passphrases are supported.
   IV handling:
   - When the IV is omitted, a random 16-byte IV is generated and prepended
     to the ciphertext so AES_DECRYPT can recover it without an explicit IV.
   - When the IV is provided (must be 16 bytes), the caller manages it and the
     ciphertext carries only the encrypted bytes.
   The implementation reuses the established crypto conventions from the
   transform/encrypt/encryptor package (algorithm, IV prepending, Base64
   output, TransformCommonError.encryptionError) and introduces no new
   dependencies (javax.crypto is part of the JDK).
   - Register AES_ENCRYPT/AES_DECRYPT constants and dispatch in ZetaSQLFunction
   - Infer STRING return type in ZetaSQLType
   - Add CryptoFunction with aesEncrypt/aesDecrypt and key/IV helpers
   - Add CryptoFunctionTest (29 cases) covering round-trips, passphrase and
     base64 keys (AES-128/192/256), explicit and random IVs, null/empty/blank
     keys, argument-count validation, and negative paths
   - Document the functions in docs/{en,zh}/transforms/sql-functions.md
   
   ### Does this PR introduce _any_ user-facing change?
   
   <!--
   Note that it means *any* user-facing change including all aspects such as 
the documentation fix.
   If yes, please clarify the previous behavior and the change this PR proposes 
- provide the console output, description and/or an example to show the 
behavior difference if possible.
   If possible, please also clarify if this is a user-facing change compared to 
the released SeaTunnel versions or within the unreleased branches such as dev.
   If no, write 'No'.
   If you are adding/modifying connector documents, please follow our new 
specifications: https://github.com/apache/seatunnel/issues/4544.
   -->
   Previously, the Zeta SQL engine had no built-in encryption functions — users 
had to implement AES via a custom UDF or the separate FieldEncryptTransform 
plugin. This PR adds two built-in SQL functions, AES_ENCRYPT and AES_DECRYPT, 
that can be used directly in Sql / FieldMapper transform SQL:
   
   ```sql
   -- before: no built-in AES function available in SQL transform
   
   -- after
   CALL AES_ENCRYPT(name, 'mySecretPass')
   CALL AES_DECRYPT(AES_ENCRYPT(name, 'mySecretPass'), 'mySecretPass')
   
   -- explicit 16-byte IV (deterministic ciphertext)
   CALL AES_ENCRYPT(name, 'mySecretPass', '1234567890123456')
   CALL AES_DECRYPT(cipher, 'mySecretPass', '1234567890123456')
   
   -- raw Base64 key (16/24/32 bytes; interoperable with AesCbcEncryptor key 
format)
   CALL AES_ENCRYPT(name, 'base64:MTIzNDU2Nzg5MDEyMzQ1Ng==')
   ```
   
   ### How was this patch tested?
   ```shell
   ./mvnw spotless:apply
   ./mvnw -pl seatunnel-transforms-v2 test -Dtest=CryptoFunctionTest
   ./mvnw -pl seatunnel-transforms-v2 -DskipTests verify
   ```
   
   <!--
   If tests were added, say they were added here. Please make sure to add some 
test cases that check the changes thoroughly including negative and positive 
cases if possible.
   If it was tested in a way different from regular unit tests, please clarify 
how you tested step by step, ideally copy and paste-able, so that other 
reviewers can test and check, and descendants can verify in the future.
   If tests were not added, please describe why they were not added and/or why 
it was difficult to add.
   If you are adding E2E test cases, maybe refer to 
https://github.com/apache/seatunnel/blob/dev/seatunnel-e2e/seatunnel-connector-v2-e2e/connector-cdc-mysql-e2e/src/test/resources/mysqlcdc_to_mysql.conf,
 here is a good example.
   -->
   
   
   ### Check list
   
   * [x] If any new Jar binary package adding in your PR, please add License 
Notice according
     [New License 
Guide](https://github.com/apache/seatunnel/blob/dev/docs/en/developer/new-license.md)
   * [x] If necessary, please update the documentation to describe the new 
feature. https://github.com/apache/seatunnel/tree/dev/docs
   * [x] If necessary, please update `incompatible-changes.md` to describe the 
incompatibility caused by this PR.
   * [x] If you are contributing the connector code, please check that the 
following files are updated:
     1. Update 
[plugin-mapping.properties](https://github.com/apache/seatunnel/blob/dev/plugin-mapping.properties)
 and add new connector information in it
     2. Update the pom file of 
[seatunnel-dist](https://github.com/apache/seatunnel/blob/dev/seatunnel-dist/pom.xml)
     3. Add ci label in 
[label-scope-conf](https://github.com/apache/seatunnel/blob/dev/.github/workflows/labeler/label-scope-conf.yml)
     4. Add e2e testcase in 
[seatunnel-e2e](https://github.com/apache/seatunnel/tree/dev/seatunnel-e2e/seatunnel-connector-v2-e2e/)
     5. Update connector 
[plugin_config](https://github.com/apache/seatunnel/blob/dev/config/plugin_config)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to