sudeephazra commented on PR #12293:
URL: https://github.com/apache/seatunnel/pull/12293#issuecomment-5864966476
@SEZ9 yes, all of these have been addressed
- The validator trims option values but ADLSHadoopConf consumes the raw
values, so surrounding whitespace (e.g. from env-var substitution) can pass
validation and then fail later with an unmapped exception or a worker-side 403.
Please normalize once and pass the trimmed values through, or trim again in
ADLSHadoopConf. - Addressed - [`required()` returns trimmed values (line
126)](seatunnel-connectors-v2/connector-file/connector-file-adls/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/adls/config/ADLSConfigValidator.java:126),
and [`ADLSHadoopConf` uses it for every relevant field (line
63)](seatunnel-connectors-v2/connector-file/connector-file-adls/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/adls/config/ADLSHadoopConf.java:63).
Whitespace regression tests are present.
- Sink docs: add the HNS (hierarchical namespace) requirement alongside the
exactly-once / transactional-commit claim, since that is what makes the
tmp_path → path rename atomic. - Addressed - English and Chinese sink docs
explain the atomic rename requirement, including same-container tmp_path
([English (line 39)](docs/en/connectors/sink/ADLSFile.md:39)).
- Document the validation rules that reject configs (account_name /
container naming, auth mutual exclusion, blocked hadoop_adls_properties keys)
and update the shipped template placeholders so they pass those rules. -
Addressed - Naming, authentication exclusivity, and blocked Hadoop keys are
documented. Template placeholders at [`account_name`/`container` (line
39)](D:/SourceCode/GitHub/seatunnel-adls-connector-v2/config/v2.batch.adls.config.template:39)
now satisfy the naming rules.
- Validate authority_host / tenant_id before building the OAuth token
endpoint (require https and a well-formed host) so client_secret can't be
POSTed over plain HTTP or to an arbitrary URL. - Addressed - Tenant validation
and HTTPS-origin validation happen before endpoint construction ([validation
(line
178)](seatunnel-connectors-v2/connector-file/connector-file-adls-runtime/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/adls/config/ADLSRuntimeCompatibility.java:178),
[endpoint construction (line
132)](seatunnel-connectors-v2/connector-file/connector-file-adls-runtime/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/adls/config/ADLSRuntimeCompatibility.java:132)).
HTTP, paths, queries, fragments, and malformed hosts are rejected.
- Option tables: make the en and zh sink tables list the same options and
match what the factories actually expose, and fix the en source doc defaults
for discovery_mode and start_mode (code defaults are ONCE and EARLIEST; the zh
doc already says so). These don't need a native speaker. - Addressed - English
and Chinese sink tables contain the same option sequence and match the sink
factory. English source defaults are now ONCE and EARLIEST
- Mention the ConfigShadeUtils change adding account_key to the default
log-mask list in the docs and the PR description, since it affects all
connectors. - Addressed - The implementation includes account_key
([ConfigShadeUtils (line
57)](D:/SourceCode/GitHub/seatunnel-adls-connector-v2/seatunnel-core/seatunnel-core-starter/src/main/java/org/apache/seatunnel/core/starter/utils/ConfigShadeUtils.java:57)),
and both languages document the global effect ([English (line
117)](docs/en/connectors/sink/ADLSFile.md:117)).
- Tighten the hadoop_adls_properties denylist so class-loading and
token-provider ABFS keys are blocked too, matching the "non-routing,
non-credential" wording on the option. - Addressed - The denylist blocks
credential, OAuth provider, key-provider, SAS provider, delegation-token
provider, identity-transformer, shell-key-provider, routing, and S3 keys
([validator (line
97)](seatunnel-connectors-v2/connector-file/connector-file-adls/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/adls/config/ADLSConfigValidator.java:97)).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]