Skip to content

MINIFICPP-2787 Do not encrypt empty properties and parameters#2217

Open
fgerlits wants to merge 2 commits into
apache:mainfrom
fgerlits:MINIFICPP-2787_Do-not-encrypt-empty-properties
Open

MINIFICPP-2787 Do not encrypt empty properties and parameters#2217
fgerlits wants to merge 2 commits into
apache:mainfrom
fgerlits:MINIFICPP-2787_Do-not-encrypt-empty-properties

Conversation

@fgerlits

Copy link
Copy Markdown
Contributor

This also fixes a bug: if a sensitive value was set as

  sensitive_property:

instead of

  sensitive_property: ""

in a YAML flow configuration, then the value was null instead of an empty string, and it got expanded to the string "null", and then encrypted.

https://issues.apache.org/jira/browse/MINIFICPP-2787


Thank you for submitting a contribution to Apache NiFi - MiNiFi C++.

In order to streamline the review of the contribution we ask you to ensure the following steps have been taken:

For all changes:

  • Is there a JIRA ticket associated with this PR? Is it referenced in the commit message?

  • Does your PR title start with MINIFICPP-XXXX where XXXX is the JIRA number you are trying to resolve? Pay particular attention to the hyphen "-" character.

  • Has your PR been rebased against the latest commit within the target branch (typically main)?

  • Is your initial contribution a single, squashed commit?

For code changes:

  • If adding new dependencies to the code, are these dependencies licensed in a way that is compatible for inclusion under ASF 2.0?
  • If applicable, have you updated the LICENSE file?
  • If applicable, have you updated the NOTICE file?

For documentation related changes:

  • Have you ensured that format looks appropriate for the output in which it is rendered?

Note:

Please ensure that once the PR is submitted, you check GitHub Actions CI results for build issues and submit an update to your PR as soon as possible.

fgerlits added 2 commits July 24, 2026 10:35
This also fixes a bug: if a sensitive value was set as
  sensitive_property:
instead of
  sensitive_property: ""
in a YAML flow configuration, then the value was null instead of an empty
string, and it got expanded to the string "null", and then encrypted.
@fgerlits
fgerlits force-pushed the MINIFICPP-2787_Do-not-encrypt-empty-properties branch from 124e95a to 8242544 Compare July 24, 2026 13:19
Comment on lines +65 to +71
if (!expected) {
return "error: " + Catch::Detail::stringify(expected.error());
}
if constexpr (!std::is_void_v<T>) {
return Catch::Detail::stringify(*expected);
}
return "OK";

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would represent expected alternatives like this. What do you think?

Suggested change
if (!expected) {
return "error: " + Catch::Detail::stringify(expected.error());
}
if constexpr (!std::is_void_v<T>) {
return Catch::Detail::stringify(*expected);
}
return "OK";
if (expected.has_value() && std::is_void_v<T>) {
return "expected(void)";
} else if (expected.has_value()) {
return fmt::format("expected({})", Catch::Detail::stringify(expected.value()));
} else {
return fmt::format("unexpected({})", Catch::Detail::stringify(expected.error()));
}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure -- I think

  CHECK(processor_after->getProperty("invokehttp-proxy-password") == "")
with expansion:
  "null" == ""

reads better than

  CHECK(processor_after->getProperty("invokehttp-proxy-password") == "")
with expansion:
  expected("null") == ""

but the second option has its advantages, too. If you still like the second option better after sleeping on it, I don't mind changing it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants