[Improvement] S3 AK/SK and other cloud credential in catalog properties should be protected
Open
improvement
- Dominant language
- Java
- Stars
- 3.2k
- Forks
- 935
- Avg merge
- 1d 16h
- Merged PRs (30d)
- 298
Description
### What would you like to be improved?
S3 AK/SK in catalog properties should be protected.
### How should we improve?
Only owner can the sensitive information, others can't get the sensitive information.
Contributor guide
Research direction
The issue names S3 AK/SK and other cloud credentials in catalog properties but does not identify files, tests, or entry points. Start by locating catalog-property handling and the existing owner authorization model. Done should define and verify how sensitive values are protected and that only the owner can access them.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- authorization, backend, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100