Search before asking
Description
Subtask of #17937 (DSIP-105). Depends on #18586 (Property.sensitive + API/UI masking).
Reuse existing PasswordUtils.encodePassword / decodePassword for definition-time at-rest protection of sensitive=true values. Do not change datasource CRUD.
In scope
- On workflow/task definition save: encode new plaintext sensitive values when
datasource.encryption.enable=true
- Keep-original (
******) writes the DB value as-is; never re-encode
- Empty / null is a real empty value (
PasswordUtils empty → ""), not keep-original; ****** is write-path only and is never decoded
false → true: on create, reject ****** (no existing value to merge); on update, ****** is keep-original — merge the existing plaintext, then encode and persist with sensitive=true
true → false: decode then persist plaintext with sensitive=false
- Internal execution / start merge uses a decrypt copy; API/UI still return masked copies only
- Runtime instance
global_params stays plaintext materialization (as agreed on the parent)
- Same-cluster Copy copies JSON as-is (ciphertext +
sensitive); no double encryption
Out of scope
- Datasource create/update/password UI (reuse utils only)
- Worker log masking (see Worker subtask)
- Project parameters, Export / Import, KMS / key rotation
- Encrypting instance
global_params
Acceptance
Use case
Definition JSON in the metadata DB should not store secrets in plaintext when the existing datasource encryption switch is enabled. Runtime still materializes plaintext for dispatch.
Related issues
Are you willing to submit a PR?
Code of Conduct
Search before asking
Description
Subtask of #17937 (DSIP-105). Depends on #18586 (Property.sensitive + API/UI masking).
Reuse existing
PasswordUtils.encodePassword/decodePasswordfor definition-time at-rest protection ofsensitive=truevalues. Do not change datasource CRUD.In scope
datasource.encryption.enable=true******) writes the DB value as-is; never re-encodePasswordUtilsempty →""), not keep-original;******is write-path only and is never decodedfalse → true: on create, reject******(no existing value to merge); on update,******is keep-original — merge the existing plaintext, then encode and persist withsensitive=truetrue → false: decode then persist plaintext withsensitive=falseglobal_paramsstays plaintext materialization (as agreed on the parent)sensitive); no double encryptionOut of scope
global_paramsAcceptance
******) does not double-encrypt******(decrypt is internal-only)false↔true; encryption flag on/offUse case
Definition JSON in the metadata DB should not store secrets in plaintext when the existing datasource encryption switch is enabled. Runtime still materializes plaintext for dispatch.
Related issues
Are you willing to submit a PR?
Code of Conduct