Repository navigation
Conversation
SbloodyS
left a comment
There was a problem hiding this comment.
Encrypt definition snapshots created by instance edits
updateWorkflowInstance() is not an instance-only persistence path. It calls saveTaskDefine() and saveWorkflowDefine(), which write definition history even when syncDefine=false and also update current definitions when syncDefine=true.
Passing false to mergeLocalParams() therefore persists newly entered sensitive local values as plaintext in definition tables. The merged runtime globalParams are also passed directly into workflowDefinition.set(), so even keeping an existing sensitive global unchanged can copy its plaintext instance value back into the definition.
Please preserve plaintext instance globals while encrypting the copies persisted as task/workflow definitions. Add service-level coverage for instance edits with encryption enabled and both syncDefine values; the new utility tests do not cover this persistence path.
Purpose
Implements #18587 (subtask of #17937 / DSIP-105). Depends on #18586 / #18585.
Reuse
PasswordUtilsfor definition-time at-rest protection ofsensitive=truevalues whendatasource.encryption.enable=true. Do not change datasource CRUD. Runtime instance params stay plaintext materialization; API/UI still return masked copies only.Changes
******) then encode new sensitive plaintext; skip re-encode when value equals existing sensitive DB valuerestoreStartParamslocalParamsinTaskExecutionContext/ prepare-params so Worker receives plaintextTests
false→truekeep-original then encode, encryption flag on/off, start-path decrypt, Master localParams decryptRelated issues