chovy-3012 opened a new pull request, #12403:
URL: https://github.com/apache/seatunnel/pull/12403
<!--
Thank you for contributing to SeaTunnel! Please make sure that your code
changes
are covered with tests. And in case of new features or big changes
remember to adjust the documentation.
Feel free to ping committers for the review!
## Contribution Checklist
- Make sure that the pull request corresponds to a [GITHUB
issue](https://github.com/apache/seatunnel/issues).
- Name the pull request in the form "[Feature] [component] Title of the
pull request", where *Feature* can be replaced by `Hotfix`, `Bug`, etc.
- Minor fixes should be named following this pattern: `[hotfix] [docs] Fix
typo in README.md doc`.
-->
### Purpose of this pull request
<!-- Describe the purpose of this pull request. For example: This pull
request adds checkstyle plugin.-->
Add two AES crypto functions to the Zeta SQL engine:
- AES_ENCRYPT(value, key[, iv]): encrypts with AES/CBC/PKCS5Padding and
returns a Base64-encoded ciphertext. Returns null for null input.
- AES_DECRYPT(value, key[, iv]): decrypts a Base64 ciphertext and returns
the UTF-8 plaintext. Returns null for null input.
Key handling:
- A key prefixed with "base64:" is decoded as a raw AES key (16/24/32
bytes for AES-128/192/256), matching the FieldEncrypt AesCbcEncryptor
key format.
- Otherwise the passphrase is hashed with SHA-256 and the first 16 bytes
are used as an AES-128 key, so arbitrary-length passphrases are supported.
IV handling:
- When the IV is omitted, a random 16-byte IV is generated and prepended
to the ciphertext so AES_DECRYPT can recover it without an explicit IV.
- When the IV is provided (must be 16 bytes), the caller manages it and the
ciphertext carries only the encrypted bytes.
The implementation reuses the established crypto conventions from the
transform/encrypt/encryptor package (algorithm, IV prepending, Base64
output, TransformCommonError.encryptionError) and introduces no new
dependencies (javax.crypto is part of the JDK).
- Register AES_ENCRYPT/AES_DECRYPT constants and dispatch in ZetaSQLFunction
- Infer STRING return type in ZetaSQLType
- Add CryptoFunction with aesEncrypt/aesDecrypt and key/IV helpers
- Add CryptoFunctionTest (29 cases) covering round-trips, passphrase and
base64 keys (AES-128/192/256), explicit and random IVs, null/empty/blank
keys, argument-count validation, and negative paths
- Document the functions in docs/{en,zh}/transforms/sql-functions.md
### Does this PR introduce _any_ user-facing change?
<!--
Note that it means *any* user-facing change including all aspects such as
the documentation fix.
If yes, please clarify the previous behavior and the change this PR proposes
- provide the console output, description and/or an example to show the
behavior difference if possible.
If possible, please also clarify if this is a user-facing change compared to
the released SeaTunnel versions or within the unreleased branches such as dev.
If no, write 'No'.
If you are adding/modifying connector documents, please follow our new
specifications: https://github.com/apache/seatunnel/issues/4544.
-->
Previously, the Zeta SQL engine had no built-in encryption functions — users
had to implement AES via a custom UDF or the separate FieldEncryptTransform
plugin. This PR adds two built-in SQL functions, AES_ENCRYPT and AES_DECRYPT,
that can be used directly in Sql / FieldMapper transform SQL:
```sql
-- before: no built-in AES function available in SQL transform
-- after
CALL AES_ENCRYPT(name, 'mySecretPass')
CALL AES_DECRYPT(AES_ENCRYPT(name, 'mySecretPass'), 'mySecretPass')
-- explicit 16-byte IV (deterministic ciphertext)
CALL AES_ENCRYPT(name, 'mySecretPass', '1234567890123456')
CALL AES_DECRYPT(cipher, 'mySecretPass', '1234567890123456')
-- raw Base64 key (16/24/32 bytes; interoperable with AesCbcEncryptor key
format)
CALL AES_ENCRYPT(name, 'base64:MTIzNDU2Nzg5MDEyMzQ1Ng==')
```
### How was this patch tested?
```shell
./mvnw spotless:apply
./mvnw -pl seatunnel-transforms-v2 test -Dtest=CryptoFunctionTest
./mvnw -pl seatunnel-transforms-v2 -DskipTests verify
```
<!--
If tests were added, say they were added here. Please make sure to add some
test cases that check the changes thoroughly including negative and positive
cases if possible.
If it was tested in a way different from regular unit tests, please clarify
how you tested step by step, ideally copy and paste-able, so that other
reviewers can test and check, and descendants can verify in the future.
If tests were not added, please describe why they were not added and/or why
it was difficult to add.
If you are adding E2E test cases, maybe refer to
https://github.com/apache/seatunnel/blob/dev/seatunnel-e2e/seatunnel-connector-v2-e2e/connector-cdc-mysql-e2e/src/test/resources/mysqlcdc_to_mysql.conf,
here is a good example.
-->
### Check list
* [x] If any new Jar binary package adding in your PR, please add License
Notice according
[New License
Guide](https://github.com/apache/seatunnel/blob/dev/docs/en/developer/new-license.md)
* [x] If necessary, please update the documentation to describe the new
feature. https://github.com/apache/seatunnel/tree/dev/docs
* [x] If necessary, please update `incompatible-changes.md` to describe the
incompatibility caused by this PR.
* [x] If you are contributing the connector code, please check that the
following files are updated:
1. Update
[plugin-mapping.properties](https://github.com/apache/seatunnel/blob/dev/plugin-mapping.properties)
and add new connector information in it
2. Update the pom file of
[seatunnel-dist](https://github.com/apache/seatunnel/blob/dev/seatunnel-dist/pom.xml)
3. Add ci label in
[label-scope-conf](https://github.com/apache/seatunnel/blob/dev/.github/workflows/labeler/label-scope-conf.yml)
4. Add e2e testcase in
[seatunnel-e2e](https://github.com/apache/seatunnel/tree/dev/seatunnel-e2e/seatunnel-connector-v2-e2e/)
5. Update connector
[plugin_config](https://github.com/apache/seatunnel/blob/dev/config/plugin_config)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]