mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-28 07:57:01 +00:00
feat(targets): complete redis mysql postgres target wiring (#2842)
Signed-off-by: jaehanbyun <awbrg789@naver.com> Signed-off-by: houseme <housemecn@gmail.com> Signed-off-by: Gunther Xing <jiengup@gmail.com> Signed-off-by: JaySon-Huang <tshent@qq.com> Co-authored-by: jaehanbyun <awbrg789@naver.com> Co-authored-by: Gunther Xing <jiengup@gmail.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: cxymds <Cxymds@qq.com> Co-authored-by: JaySon <tshent@qq.com> Co-authored-by: 安正超 <anzhengchao@gmail.com>
This commit is contained in:
@@ -38,10 +38,24 @@ fn is_sensitive_target_field(field_name: &str) -> bool {
|
||||
|| field_name.contains("client_key")
|
||||
|| field_name.contains("access_key")
|
||||
|| field_name.contains("auth")
|
||||
|| field_name.contains(rustfs_config::BASE_DSN_STRING)
|
||||
}
|
||||
|
||||
fn redact_target_field_value(field_name: &str, value: &str) -> String {
|
||||
if is_sensitive_target_field(field_name) && !value.is_empty() {
|
||||
if value.is_empty() {
|
||||
return value.to_string();
|
||||
}
|
||||
// MySQL DSN fields need partial redaction instead of full masking so the
|
||||
// remaining connection details (host, port, database) remain visible in
|
||||
// debug logs while the password is hidden.
|
||||
if field_name == rustfs_config::BASE_DSN_STRING {
|
||||
let trimmed = value.trim_start();
|
||||
if trimmed.starts_with("postgres://") || trimmed.starts_with("postgresql://") {
|
||||
return crate::target::postgres::redact_postgres_dsn(value);
|
||||
}
|
||||
return crate::target::mysql::redact_mysql_dsn(value);
|
||||
}
|
||||
if is_sensitive_target_field(field_name) {
|
||||
return "***redacted***".to_string();
|
||||
}
|
||||
value.to_string()
|
||||
@@ -283,6 +297,23 @@ mod tests {
|
||||
assert_eq!(redact_target_field_value("queue_limit", "1000"), "1000");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redact_dsn_string_partial_redaction() {
|
||||
let dsn = "rustfs:secret123@tcp(mysql.example.com:3306)/rustfs_events";
|
||||
let redacted = redact_target_field_value(rustfs_config::MYSQL_DSN_STRING, dsn);
|
||||
assert_eq!(redacted, "rustfs:***@tcp(mysql.example.com:3306)/rustfs_events");
|
||||
// empty dsn_string value
|
||||
assert_eq!(redact_target_field_value(rustfs_config::MYSQL_DSN_STRING, ""), "");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redact_postgres_dsn_string_partial_redaction() {
|
||||
let dsn = "postgres://rustfs:secret123@pg.example.com:5432/rustfs_events?search_path=public";
|
||||
let redacted = redact_target_field_value(rustfs_config::POSTGRES_DSN_STRING, dsn);
|
||||
assert_eq!(redacted, "postgres://rustfs:***@pg.example.com:5432/rustfs_events?search_path=public");
|
||||
assert_eq!(redact_target_field_value(rustfs_config::POSTGRES_DSN_STRING, ""), "");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redacted_target_config_masks_sensitive_values_without_mutating_shape() {
|
||||
let mut config = KVS::new();
|
||||
|
||||
Reference in New Issue
Block a user