Skip to content

feat: 数据源口令传输改为固定 AES,禁止明文 password - #675

Merged
iwanghc merged 3 commits into
mainfrom
dms/feat-994
Sep 29, 2026
Merged

iwanghc merged 3 commits into
mainfrom
dms/feat-994

Conversation

@LordofAvernus

@LordofAvernus LordofAvernus commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

关联的 issue

https://github.com/actiontech/dms-ee/issues/994

描述你的变更

  • 数据源测连通、创建、更新三条接口改为只接受 secret_password,请求里若带明文 password 则拒绝
  • 解密复用固定密钥 AES-256-CBC(aes_transport,与前端同一把 SecretKey),解密后的口令只留在内存,写日志前清掉请求中的口令字段
  • 不兼容旧客户端:仍提交明文 password 的调用会失败。不需要改文档

确认项(pr提交后操作)

Tip

请在指定复审人之前,确认并完成以下事项,完成后✅


  • 我已完成自测
  • 我已记录完整日志方便进行诊断
  • 我已在关联的issue里补充了实现方案
  • 我已在关联的issue里补充了测试影响面
  • 我已确认了变更的兼容性,如果不兼容则在issue里标记 not_compatible
  • 我已确认了是否要更新文档,如果要更新则在issue里标记 need_update_doc

Provide a dedicated aes_transport package that decrypts/encrypts with the
compile-time SecretKey so DB service APIs can stop accepting plaintext passwords.
Reject plaintext password keys and accept fixed AES secret_password on
connectivity check, create, and update request models, with unit coverage.
…plaintext

Decrypt transport ciphertext into locals, clear request password fields before
logging, and pass plaintext only into usecases for check/create/update.
@github-actions

Copy link
Copy Markdown

PR Reviewer Guide 🔍

⏱️ Estimated effort to review: 4 🔵🔵🔵🔵⚪
🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected

@github-actions

Copy link
Copy Markdown

PR Code Suggestions ✨

No code suggestions found in the successfully analyzed chunks.

⚠️ Suggestion coverage: 1 of 1 analysis chunks failed; no suggestions were found in the successful chunks; failed chunks could not be analyzed.

@iwanghc
iwanghc merged commit d63b4ea into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants