Search before asking
Description
Subtask of #17937 (DSIP-105). Parent remains the DSIP design tracker; this issue is the first implementation slice.
Add Property.sensitive and mask sensitive parameter values as ****** on API/UI read paths. Keep-original merge on write/start. No encryption in this subtask.
In scope (aligned with PR #18585)
- Add
Property.sensitive (default false; missing JSON field is false)
- Deep-copy mask on workflow / task / instance query responses and
view-variables (never mutate shared entities in place)
- Write-path merge: only
****** means keep the DB original value
- Empty / null is a real empty value, not keep-original
- Create rejects placeholder-only
****** (no previous value to restore)
- Update:
****** is keep-original when a same-named property already exists (including flipping false → true); true → false with only ****** is rejected (would persist the mask or expose the secret as non-sensitive)
- UI: Sensitive checkbox on workflow global params and task
localParams; echo ****** after reload
- Start / command path:
****** in start params is replaced with the definition value
Out of scope (follow-up subtasks)
- Definition-time encrypt/decrypt via
PasswordUtils (next API subtask)
- Worker stdout dynamic redaction + cleanup (Worker subtask)
- Project parameters, Export / Import (parent out of scope)
Acceptance
Implementation: #18585
Use case
Users store passwords / API keys as workflow global params or task local params. After this subtask, UI and API responses must not show those values in plaintext. Persistence may still be plaintext; at-rest encryption is a later subtask.
Related issues
Are you willing to submit a PR?
Code of Conduct
Search before asking
Description
Subtask of #17937 (DSIP-105). Parent remains the DSIP design tracker; this issue is the first implementation slice.
Add
Property.sensitiveand mask sensitive parameter values as******on API/UI read paths. Keep-original merge on write/start. No encryption in this subtask.In scope (aligned with PR #18585)
Property.sensitive(defaultfalse; missing JSON field isfalse)view-variables(never mutate shared entities in place)******means keep the DB original value******(no previous value to restore)******is keep-original when a same-named property already exists (including flippingfalse → true);true → falsewith only******is rejected (would persist the mask or expose the secret as non-sensitive)localParams; echo******after reload******in start params is replaced with the definition valueOut of scope (follow-up subtasks)
PasswordUtils(next API subtask)Acceptance
sensitive=trueparams never return real values in external API/UI (******only)******does not overwrite the stored secret when an existing property can be merged******is rejectedfalse → truewith only******keeps the existing value and marks it sensitive (keep-original)true → falsewith only******is rejectedImplementation: #18585
Use case
Users store passwords / API keys as workflow global params or task local params. After this subtask, UI and API responses must not show those values in plaintext. Persistence may still be plaintext; at-rest encryption is a later subtask.
Related issues
Are you willing to submit a PR?
Code of Conduct