From 2554589e4adeb50858a2c99d66e55d675fbd501d Mon Sep 17 00:00:00 2001 From: Daman Arora Date: Mon, 5 Oct 2026 07:08:23 -0400 Subject: [PATCH] return stored value for secure configs so listConfigurations stays the same --- .../framework/config/impl/ConfigurationVO.java | 7 +++++++ .../java/com/cloud/api/ApiResponseHelper.java | 5 ++++- .../com/cloud/api/ApiResponseHelperTest.java | 18 ++++++++++++++++++ 3 files changed, 29 insertions(+), 1 deletion(-) diff --git a/framework/config/src/main/java/org/apache/cloudstack/framework/config/impl/ConfigurationVO.java b/framework/config/src/main/java/org/apache/cloudstack/framework/config/impl/ConfigurationVO.java index d12a41864b05..190c71e5c781 100644 --- a/framework/config/src/main/java/org/apache/cloudstack/framework/config/impl/ConfigurationVO.java +++ b/framework/config/src/main/java/org/apache/cloudstack/framework/config/impl/ConfigurationVO.java @@ -162,6 +162,13 @@ public String getValue() { } } + /** + * Returns the value as stored in the database, without decrypting it. + */ + public String getRawValue() { + return value; + } + public void setValue(String value) { if(isEncrypted()) { this.value = DBEncryptionUtil.encrypt(value); diff --git a/server/src/main/java/com/cloud/api/ApiResponseHelper.java b/server/src/main/java/com/cloud/api/ApiResponseHelper.java index f56cda6e557a..5f53b0de1ccf 100644 --- a/server/src/main/java/com/cloud/api/ApiResponseHelper.java +++ b/server/src/main/java/com/cloud/api/ApiResponseHelper.java @@ -213,6 +213,7 @@ import org.apache.cloudstack.engine.subsystem.api.storage.DataStoreManager; import org.apache.cloudstack.engine.subsystem.api.storage.SnapshotDataFactory; import org.apache.cloudstack.engine.subsystem.api.storage.SnapshotInfo; +import org.apache.cloudstack.framework.config.impl.ConfigurationVO; import org.apache.cloudstack.framework.jobs.AsyncJob; import org.apache.cloudstack.framework.jobs.AsyncJobManager; import org.apache.cloudstack.framework.jobs.dao.AsyncJobDao; @@ -686,7 +687,9 @@ public ConfigurationResponse createConfigurationResponse(Configuration cfg) { cfgResponse.setSubGroup(configGroupAndSubGroup.second()); cfgResponse.setDescription(cfg.getDescription()); cfgResponse.setName(cfg.getName()); - if (cfg.isEncrypted()) { + if (cfg instanceof ConfigurationVO && cfg.isEncrypted()) { + cfgResponse.setValue(((ConfigurationVO) cfg).getRawValue()); + } else if (cfg.isEncrypted()) { cfgResponse.setValue(DBEncryptionUtil.encrypt(cfg.getValue())); } else { cfgResponse.setValue(cfg.getValue()); diff --git a/server/src/test/java/com/cloud/api/ApiResponseHelperTest.java b/server/src/test/java/com/cloud/api/ApiResponseHelperTest.java index c0c019f6dbd8..c1661fcf7379 100644 --- a/server/src/test/java/com/cloud/api/ApiResponseHelperTest.java +++ b/server/src/test/java/com/cloud/api/ApiResponseHelperTest.java @@ -46,6 +46,7 @@ import org.apache.cloudstack.api.ResponseObject; import org.apache.cloudstack.api.response.AutoScaleVmGroupResponse; import org.apache.cloudstack.api.response.AutoScaleVmProfileResponse; +import org.apache.cloudstack.api.response.ConfigurationResponse; import org.apache.cloudstack.api.response.ConsoleSessionResponse; import org.apache.cloudstack.api.response.DirectDownloadCertificateResponse; import org.apache.cloudstack.api.response.GuestOSCategoryResponse; @@ -57,10 +58,12 @@ import org.apache.cloudstack.api.response.UsageRecordResponse; import org.apache.cloudstack.api.response.TrafficTypeResponse; import org.apache.cloudstack.context.CallContext; +import org.apache.cloudstack.framework.config.impl.ConfigurationVO; import org.apache.cloudstack.usage.UsageService; import org.apache.cloudstack.vm.UnmanagedInstanceTO; import com.cloud.capacity.Capacity; +import com.cloud.configuration.ConfigurationManager; import com.cloud.configuration.Resource; import com.cloud.domain.DomainVO; import com.cloud.host.HostVO; @@ -93,6 +96,7 @@ import com.cloud.user.UserDataVO; import com.cloud.user.UserVO; import com.cloud.user.dao.UserDataDao; +import com.cloud.utils.Pair; import com.cloud.utils.net.Ip; import com.cloud.vm.ConsoleSessionVO; import com.cloud.vm.NicSecondaryIp; @@ -137,6 +141,9 @@ public class ApiResponseHelperTest { @Mock ResourceIconManager resourceIconManager; + @Mock + ConfigurationManager configurationManagerMock; + @Mock private ConsoleSessionVO consoleSessionMock; @Mock @@ -800,4 +807,15 @@ public void createConsoleSessionResponseTestShouldReturnFullResponse() { Assert.assertEquals(expected.getVmName(), response.getVmName()); } } + + @Test + public void testCreateConfigurationResponseSecureValueIsReturnedAsStored() { + ConfigurationVO cfg = new ConfigurationVO("Secure", "DEFAULT", "test", "test.secure.setting", null, "test"); + ReflectionTestUtils.setField(cfg, "value", "storedEncryptedValue"); + Mockito.when(configurationManagerMock.getConfigurationGroupAndSubGroup(cfg.getName())).thenReturn(new Pair<>("Miscellaneous", "Others")); + + ConfigurationResponse response = apiResponseHelper.createConfigurationResponse(cfg); + + assertEquals("storedEncryptedValue", response.getValue()); + } }