davsclaus opened a new pull request, #26997: URL: https://github.com/apache/camel/pull/26997
Implements [CAMEL-25096](https://issues.apache.org/jira/browse/CAMEL-25096). At DEBUG and TRACE level, the properties component logs the resolved value of a property placeholder, for example `Property with key [aws:db/password] applied by function [aws] -> <value>`. With this change, values from vault functions and from properties with a sensitive key are logged as `xxxxxx`, the same mask used for endpoint URIs. The key and the function name are still logged. ## Changes - **New SPI method:** `PropertiesFunction.isSensitive()` (default `false`, `@since 4.23`). These functions override it to return `true`: aws, aws-parameterstore, azure, gcp, hashicorp, ibm and cyberark, plus the kubernetes `secret` and `secret-binary` functions (the `configmap` functions stay `false`). - **Masked logging:** `DefaultPropertiesParser`, `DefaultPropertiesLookup` and `PropertiesComponent` now mask values in their logging when either: - the value comes from a sensitive function, or - the key is sensitive according to `SensitiveUtils.containsSensitive`. - **New sensitive keys:** `db_password` (such as `DB_PASSWORD`) and `apisecret` (such as `apiSecret`). They are added in `UpdateSensitizeHelper`, the generated list in `SensitiveUtils` and the catalog's `sensitive-keys.json`. ## Tests - **New `PropertiesComponentMaskSensitiveLogTest` (camel-core):** captures the DEBUG and TRACE logging of the properties component. - It checks that values from a vault function, and values whose keys are `db.password`, `DB_PASSWORD` and `apiSecret`, are never logged. - It checks that ordinary values are still logged. - It fails without the change. - **`SensitiveUtilsTest`:** extended for the new keys. - **Existing tests:** the properties and placeholder tests in camel-core, camel-base and camel-util pass. The changed vault components compile. _Claude Code on behalf of Claus Ibsen_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
