Vyom Mani Tiwari created RANGER-5808:
----------------------------------------
Summary: Validate JDBC connection configuration in Hive, Presto
and Trino resource lookup clients
Key: RANGER-5808
URL: https://issues.apache.org/jira/browse/RANGER-5808
Project: Ranger
Issue Type: Bug
Components: admin
Reporter: Vyom Mani Tiwari
Assignee: Vyom Mani Tiwari
Fix For: 3.0.0
The Hive, Presto and Trino service clients ({{{}HiveClient{}}},
{{{}PrestoClient{}}}, {{{}TrinoClient{}}}) build their JDBC connection for
test-connection and resource lookup directly from the {{jdbc.driverClassName}}
and {{jdbc.url}} values in the service configuration. The validation is
inconsistent across these clients:
* {{HiveClient}} on master validates {{jdbc.url}} with
{{{}JdbcUrlValidator{}}}, but {{PrestoClient}} and {{TrinoClient}} do not.
* On ranger-2.9 and ranger-2.10, the {{JdbcUrlValidator.validate(url)}} call
in {{HiveClient}} was lost during the RANGER-5513 backport, so the validator
class and its tests are present but unused.
* None of the three clients restrict {{jdbc.driverClassName}} to the expected
driver. The configured class is loaded and instantiated as given.
* The URL check doesn't restrict the URL scheme, so a URL meant for one
service type can be handled by another JDBC driver on the Admin classpath.
Proposed changes:
# Move {{JdbcUrlValidator}} from hive-agent to ranger-plugins-common, keeping
the existing rules and tests.
# Call it at the start of {{initConnection()}} in {{{}HiveClient{}}},
{{PrestoClient}} and {{{}TrinoClient{}}}, before the driver is loaded and the
connection is opened. On ranger-2.9 and ranger-2.10, this also restores the
Hive call.
# Require the expected URL scheme for each client: {{{}jdbc:hive2:{}}},
{{{}jdbc:presto:{}}}, {{{}jdbc:trino:{}}}.
# Only allow these driver classes, and reject any other value before loading
it:
** Hive: {{{}org.apache.hive.jdbc.HiveDriver{}}},
{{org.apache.hadoop.hive.jdbc.HiveDriver}}
** Presto: {{{}io.prestosql.jdbc.PrestoDriver{}}},
{{com.facebook.presto.jdbc.PrestoDriver}}
** Trino: {{io.trino.jdbc.TrinoDriver}}
# Add unit tests for each client: an invalid URL, a URL with the wrong scheme,
and a driver class not on the list above must each fail with
{{HadoopException}} before {{DriverManager.getConnection}} is called.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)