venkateshwaracholan opened a new pull request, #4770:
URL: https://github.com/apache/polaris/pull/4770

   Fixes #4769
   
   ## Summary
   
   Hardens Python CLI profile secret handling:
   
   - Use getpass() for client_secret input
   - Mask client_secret in profile display output
   - Write config files with 0600 permissions
   - Use atomic writes via temporary file + os.replace()
   - Add tests covering secret masking, permissions, and atomic writes
   
   ## Testing
   
   - Added tests for secret masking
   - Added tests for secure config permissions
   - Added tests for atomic writes
   - Added tests verifying getpass() usage
   
   ## Notes
   
   The Python test environment was not available locally (pytest/uv not 
installed), so test execution could not be completed locally. The new and 
updated tests are included and will run in CI.
   
   ## Checklist
   - [ ] ๐Ÿ›ก๏ธ Don't disclose security issues! (contact [email protected])
   - [ ] ๐Ÿ”— Clearly explained why the changes are needed, or linked related 
issues: Fixes #
   - [ ] ๐Ÿงช Added/updated tests with good coverage, or manually tested (and 
explained how)
   - [ ] ๐Ÿ’ก Added comments for complex logic
   - [ ] ๐Ÿงพ Updated `CHANGELOG.md` (if needed)
   - [ ] ๐Ÿ“š Updated documentation in `site/content/in-dev/unreleased` (if needed)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to