Vyom Mani Tiwari created RANGER-5808:
----------------------------------------

             Summary: Validate JDBC connection configuration in Hive, Presto 
and Trino resource lookup clients
                 Key: RANGER-5808
                 URL: https://issues.apache.org/jira/browse/RANGER-5808
             Project: Ranger
          Issue Type: Bug
          Components: admin
            Reporter: Vyom Mani Tiwari
            Assignee: Vyom Mani Tiwari
             Fix For: 3.0.0


The Hive, Presto and Trino service clients ({{{}HiveClient{}}}, 
{{{}PrestoClient{}}}, {{{}TrinoClient{}}}) build their JDBC connection for 
test-connection and resource lookup directly from the {{jdbc.driverClassName}} 
and {{jdbc.url}} values in the service configuration. The validation is 
inconsistent across these clients:
 * {{HiveClient}} on master validates {{jdbc.url}} with 
{{{}JdbcUrlValidator{}}}, but {{PrestoClient}} and {{TrinoClient}} do not.
 * On ranger-2.9 and ranger-2.10, the {{JdbcUrlValidator.validate(url)}} call 
in {{HiveClient}} was lost during the RANGER-5513 backport, so the validator 
class and its tests are present but unused.
 * None of the three clients restrict {{jdbc.driverClassName}} to the expected 
driver. The configured class is loaded and instantiated as given.
 * The URL check doesn't restrict the URL scheme, so a URL meant for one 
service type can be handled by another JDBC driver on the Admin classpath.

Proposed changes:
 # Move {{JdbcUrlValidator}} from hive-agent to ranger-plugins-common, keeping 
the existing rules and tests.
 # Call it at the start of {{initConnection()}} in {{{}HiveClient{}}}, 
{{PrestoClient}} and {{{}TrinoClient{}}}, before the driver is loaded and the 
connection is opened. On ranger-2.9 and ranger-2.10, this also restores the 
Hive call.
 # Require the expected URL scheme for each client: {{{}jdbc:hive2:{}}}, 
{{{}jdbc:presto:{}}}, {{{}jdbc:trino:{}}}.
 # Only allow these driver classes, and reject any other value before loading 
it:
 ** Hive: {{{}org.apache.hive.jdbc.HiveDriver{}}}, 
{{org.apache.hadoop.hive.jdbc.HiveDriver}}
 ** Presto: {{{}io.prestosql.jdbc.PrestoDriver{}}}, 
{{com.facebook.presto.jdbc.PrestoDriver}}
 ** Trino: {{io.trino.jdbc.TrinoDriver}}
 # Add unit tests for each client: an invalid URL, a URL with the wrong scheme, 
and a driver class not on the list above must each fail with 
{{HadoopException}} before {{DriverManager.getConnection}} is called.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to