davsclaus opened a new pull request, #26997:
URL: https://github.com/apache/camel/pull/26997

   Implements [CAMEL-25096](https://issues.apache.org/jira/browse/CAMEL-25096).
   
   At DEBUG and TRACE level, the properties component logs the resolved value 
of a property placeholder, for example `Property with key [aws:db/password] 
applied by function [aws] -> <value>`. With this change, values from vault 
functions and from properties with a sensitive key are logged as `xxxxxx`, the 
same mask used for endpoint URIs. The key and the function name are still 
logged.
   
   ## Changes
   - **New SPI method:** `PropertiesFunction.isSensitive()` (default `false`, 
`@since 4.23`). These functions override it to return `true`: aws, 
aws-parameterstore, azure, gcp, hashicorp, ibm and cyberark, plus the 
kubernetes `secret` and `secret-binary` functions (the `configmap` functions 
stay `false`).
   - **Masked logging:** `DefaultPropertiesParser`, `DefaultPropertiesLookup` 
and `PropertiesComponent` now mask values in their logging when either:
     - the value comes from a sensitive function, or
     - the key is sensitive according to `SensitiveUtils.containsSensitive`.
   - **New sensitive keys:** `db_password` (such as `DB_PASSWORD`) and 
`apisecret` (such as `apiSecret`). They are added in `UpdateSensitizeHelper`, 
the generated list in `SensitiveUtils` and the catalog's `sensitive-keys.json`.
   
   ## Tests
   - **New `PropertiesComponentMaskSensitiveLogTest` (camel-core):** captures 
the DEBUG and TRACE logging of the properties component.
     - It checks that values from a vault function, and values whose keys are 
`db.password`, `DB_PASSWORD` and `apiSecret`, are never logged.
     - It checks that ordinary values are still logged.
     - It fails without the change.
   - **`SensitiveUtilsTest`:** extended for the new keys.
   - **Existing tests:** the properties and placeholder tests in camel-core, 
camel-base and camel-util pass. The changed vault components compile.
   
   _Claude Code on behalf of Claus Ibsen_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to