vyommani opened a new pull request, #1255:
URL: https://github.com/apache/ranger/pull/1255

   …nd Trino resource lookup clients
   
   ## What changes were proposed in this pull request?
   
   The Hive, Presto and Trino service clients build their JDBC connection for 
test-connection and resource lookup from the jdbc.driverClassName and jdbc.url 
values in the service config. The validation of those values was inconsistent: 
only HiveClient checked jdbc.url, and no client restricted the driver class or 
the URL scheme.
   
   This PR makes validation consistent across all three clients:
   
   Moves JdbcUrlValidator from hive-agent to ranger-plugins-common 
(org.apache.ranger.plugin.client) so all three clients can use it. The existing 
rules and tests move with it.
   URL scheme check: adds validate(url, allowedPrefixes). The URL must start 
with the expected prefix for its client:
   Hive: jdbc:hive2://
   Presto: jdbc:presto://
   Trino: jdbc:trino://
   Driver class allow-list: adds validateDriverClassName(name, allowed). The 
configured class must be one of:
   Hive: org.apache.hive.jdbc.HiveDriver
   Presto: io.prestosql.jdbc.PrestoDriver, com.facebook.presto.jdbc.PrestoDriver
   Trino: io.trino.jdbc.TrinoDriver
   Validation runs before the class is loaded.
   Percent-encoding: jdbc.url is also checked after one pass of 
percent-decoding, since drivers may decode parts of the URL before parsing 
parameters. URLs with malformed percent-encoding are rejected.
   HiveClient, PrestoClient, TrinoClient: initConnection() now runs both checks 
before loading the driver or opening a connection.
   
   Existing services that use the default driver classes and standard URLs are 
not affected.
   
   
   ## How was this patch tested?
   
   JdbcUrlValidatorTest (moved to agents-common). New cases cover:
   URLs with an allowed or disallowed scheme
   allowed and disallowed driver classes
   blocked parameters behind a percent-encoded separator
   single-pass decoding
   malformed percent-encoding
   TestHiveClient, TestPrestoClient, TestTrinoClient: new tests check that a 
URL with the wrong scheme, a driver class outside the allow-list, or a blocked 
parameter each fails with HadoopException. They also check that the driver 
class is never initialized and that DriverManager.registerDriver and 
getConnection are never called.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to