Skip to content

branch-4.1: [fix](security) Mask sensitive fields in encryption keys schema table #66834 - #66931

Merged
yiguolei merged 1 commit into
branch-4.1from
auto-pick-66834-branch-4.1
Aug 20, 2026
Merged

branch-4.1: [fix](security) Mask sensitive fields in encryption keys schema table #66834#66931
yiguolei merged 1 commit into
branch-4.1from
auto-pick-66834-branch-4.1

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Cherry-picked from #66834

…#66834)
### What problem does this PR solve?
Issue Number: close #CIR-27838
Related PR: #xxx
Problem Summary:
Querying `information_schema.encryption_keys` exposes the original
Base64-encoded initialization vector and ciphertext through the `IV` and
`CIPHER` columns.
The schema scanner previously copied `iv_base64` and `ciphertext_base64`
directly into the result block. This change masks both fields with
`******` when their values are present, while preserving the existing
empty-string behavior when the fields are absent.
A BE unit test is added to verify both the masked-value and empty-value
cases.
### Release note
None
### Check List (For Author)
- Test <!-- At least one of them must be included. -->
- [ ] Regression test
- [x] Unit Test
- [ ] Manual test (add detailed scripts or steps below)
- [ ] No need to test or manual test. Explain why:
- [ ] This is a refactor/code format and no logic has been changed.
- [ ] Previous test can cover this change.
- [ ] No code files have been changed.
- [ ] Other reason <!-- Add your reason? -->
- Behavior changed:
- [ ] No.
- [x] Yes. The `IV` and `CIPHER` columns in
`information_schema.encryption_keys` now return `******` instead of
exposing their original values.
@hello-stephen

Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@hello-stephen

Copy link
Copy Markdown
Contributor

run buildall

@yiguolei

Copy link
Copy Markdown
Contributor

skip buildall

@github-actionsgithub-actionsBot added the approved Indicates a PR has been approved by one committer. label Aug 20, 2026
@github-actions

Copy link
Copy Markdown
ContributorAuthor

PR approved by at least one committer and no changes requested.

@github-actions

Copy link
Copy Markdown
ContributorAuthor

PR approved by anyone and no changes requested.

@yiguolei
yiguolei merged commit b0a79b2 into branch-4.1Aug 20, 2026
33 of 35 checks passed
@morrySnow
morrySnow deleted the auto-pick-66834-branch-4.1 branch August 20, 2026 04:01
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approvedIndicates a PR has been approved by one committer.reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hello-stephen@yiguolei@dzr171712