vyommani opened a new pull request, #1255: URL: https://github.com/apache/ranger/pull/1255
…nd Trino resource lookup clients ## What changes were proposed in this pull request? The Hive, Presto and Trino service clients build their JDBC connection for test-connection and resource lookup from the jdbc.driverClassName and jdbc.url values in the service config. The validation of those values was inconsistent: only HiveClient checked jdbc.url, and no client restricted the driver class or the URL scheme. This PR makes validation consistent across all three clients: Moves JdbcUrlValidator from hive-agent to ranger-plugins-common (org.apache.ranger.plugin.client) so all three clients can use it. The existing rules and tests move with it. URL scheme check: adds validate(url, allowedPrefixes). The URL must start with the expected prefix for its client: Hive: jdbc:hive2:// Presto: jdbc:presto:// Trino: jdbc:trino:// Driver class allow-list: adds validateDriverClassName(name, allowed). The configured class must be one of: Hive: org.apache.hive.jdbc.HiveDriver Presto: io.prestosql.jdbc.PrestoDriver, com.facebook.presto.jdbc.PrestoDriver Trino: io.trino.jdbc.TrinoDriver Validation runs before the class is loaded. Percent-encoding: jdbc.url is also checked after one pass of percent-decoding, since drivers may decode parts of the URL before parsing parameters. URLs with malformed percent-encoding are rejected. HiveClient, PrestoClient, TrinoClient: initConnection() now runs both checks before loading the driver or opening a connection. Existing services that use the default driver classes and standard URLs are not affected. ## How was this patch tested? JdbcUrlValidatorTest (moved to agents-common). New cases cover: URLs with an allowed or disallowed scheme allowed and disallowed driver classes blocked parameters behind a percent-encoded separator single-pass decoding malformed percent-encoding TestHiveClient, TestPrestoClient, TestTrinoClient: new tests check that a URL with the wrong scheme, a driver class outside the allow-list, or a blocked parameter each fails with HadoopException. They also check that the driver class is never initialized and that DriverManager.registerDriver and getConnection are never called. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
