{"record":{"id":"db19888cc4d2bed3","repo":"apache/seatunnel","slug":"failed-to-decode-auth-api-key-encoded-as-base64","errorCode":null,"errorMessage":"Failed to decode 'auth.api_key_encoded' as Base64","messagePattern":"Failed to decode 'auth\\.api_key_encoded' as Base64","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-elasticsearch/src/main/java/org/apache/seatunnel/connectors/seatunnel/elasticsearch/config/ElasticsearchValidators.java","lineNumber":61,"sourceCode":"     * the corresponding conditional rules.\n     */\n    @Slf4j\n    public static class ApiKeyEncodedFormatValidator implements ConditionExtension<String> {\n        @Override\n        public String description() {\n            return \"'auth.api_key_encoded' must be a Base64-encoded 'id:key' string\";\n        }\n\n        @Override\n        public boolean evaluate(ReadonlyConfig config, String value) {\n            if (value == null || value.trim().isEmpty()) {\n                return true;\n            }\n            try {\n                byte[] decoded = Base64.getDecoder().decode(value);\n                return new String(decoded, StandardCharsets.UTF_8).contains(\":\");\n            } catch (IllegalArgumentException e) {\n                log.warn(\"Failed to decode 'auth.api_key_encoded' as Base64\", e);\n                return false;\n            }\n        }\n    }\n}\n","sourceCodeStart":43,"sourceCodeEnd":67,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-elasticsearch/src/main/java/org/apache/seatunnel/connectors/seatunnel/elasticsearch/config/ElasticsearchValidators.java#L43-L67","documentation":"ElasticsearchValidators' ApiKeyEncodedValidator validates that auth.api_key_encoded is valid Base64 encoding of 'id:api_key'. If Base64 decoding throws IllegalArgumentException, this warn is logged and the validator returns false, failing config validation before the job runs.","triggerScenarios":"Supplying an auth.api_key_encoded value that is not valid Base64 (wrong padding, URL-safe base64, or a raw id:key string pasted directly).","commonSituations":"Users pasting the Elasticsearch API key with URL-safe characters or without padding; providing an unencoded 'id:secret' pair instead of the encoded form.","solutions":["Base64-encode the 'id:api_key' string (standard Base64, with padding) and use that value","Alternatively use the plain auth.api_key (id and key separately) option","Verify with: echo -n 'id:api_key' | base64"],"exampleFix":"// before\nauth.api_key_encoded = \"myId:myKey\" // raw, not base64\n// after\nauth.api_key_encoded = \"bXlJZDpteUtleQ==\" // base64(\"myId:myKey\")","handlingStrategy":"validation","validationCode":"// validate base64 before submitting config\nString v = config.getString(\"auth.api_key_encoded\");\nboolean ok = v != null && v.matches(\"[A-Za-z0-9+/]+={0,2}\")\n    && new String(java.util.Base64.getDecoder().decode(v)).contains(\":\");","typeGuard":"java.util.function.Predicate<String> isStdBase64 = s -> s != null && s.matches(\"[A-Za-z0-9+/]+={0,2}\");","tryCatchPattern":null,"preventionTips":["Generate the encoded key with: echo -n 'id:api_key' | base64","Never paste the raw id:key pair into api_key_encoded","Watch for URL-safe Base64 (- and _) which the validator rejects"],"tags":["elasticsearch","base64","config-validation"],"backgroundTag":"invalid-argument-format","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}