Skip to content

[DSIP-105][Feature][API] Encrypt sensitive definition params with PasswordUtils #18587

Description

@det101

Search before asking

  • I had searched in the issues and found no similar feature requirement.

Description

Subtask of #17937 (DSIP-105). Depends on #18586 (Property.sensitive + API/UI masking).

Reuse existing PasswordUtils.encodePassword / decodePassword for definition-time at-rest protection of sensitive=true values. Do not change datasource CRUD.

In scope

  • On workflow/task definition save: encode new plaintext sensitive values when datasource.encryption.enable=true
  • Keep-original (******) writes the DB value as-is; never re-encode
  • Empty / null is a real empty value (PasswordUtils empty → ""), not keep-original; ****** is write-path only and is never decoded
  • false → true: on create, reject ****** (no existing value to merge); on update, ****** is keep-original — merge the existing plaintext, then encode and persist with sensitive=true
  • true → false: decode then persist plaintext with sensitive=false
  • Internal execution / start merge uses a decrypt copy; API/UI still return masked copies only
  • Runtime instance global_params stays plaintext materialization (as agreed on the parent)
  • Same-cluster Copy copies JSON as-is (ciphertext + sensitive); no double encryption

Out of scope

  • Datasource create/update/password UI (reuse utils only)
  • Worker log masking (see Worker subtask)
  • Project parameters, Export / Import, KMS / key rotation
  • Encrypting instance global_params

Acceptance

  • With encryption on, sensitive definition values are not stored as plaintext in DB JSON
  • Saving unchanged sensitive params (******) does not double-encrypt
  • After Copy, sensitive params still work at runtime
  • API/UI still return ****** (decrypt is internal-only)
  • Encryption off (default): behavior matches [DSIP-105][Feature][API] Add Property.sensitive and mask values in API/UI #18586 except encode is skipped
  • Unit tests: encode new plaintext only; keep-original; false↔true; encryption flag on/off

Use case

Definition JSON in the metadata DB should not store secrets in plaintext when the existing datasource encryption switch is enabled. Runtime still materializes plaintext for dispatch.

Related issues

Are you willing to submit a PR?

  • Yes I am willing to submit a PR!

Code of Conduct

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions