apache / amoro

Apache Amoro (incubating) is a Lakehouse management system built on open data lake formats.
https://amoro.apache.org/
Apache License 2.0
874 stars 290 forks source link

[Improvement]: AK/SK Leakage Security #3310

Open shouwangyw opened 3 weeks ago

shouwangyw commented 3 weeks ago

Search before asking

What would you like to be improved?

image

The rest api should probably not be whitelist, as this may expose the user's AK/SK, we need to think about a better way to provide OpenAPI.

How should we improve?

No response

Are you willing to submit PR?

Subtasks

No response

Code of Conduct

XBaith commented 3 weeks ago

Thanks for reporting this issue. I reproduce this issue in my dev enviorment. image

XBaith commented 3 weeks ago

Currently we can remove AK/SK in our configs and inject temporary iam credential via vended-credentials