aminghadersohi opened a new pull request, #44723: URL: https://github.com/apache/superset/pull/44723
### SUMMARY Make MySQL's SSL toggle and saved `ssl=1` URLs require TLS through driver-native options. Preserve schema selection, local-infile restrictions, and stronger verification settings; do not change MySQL-compatible engine subclasses. A local MySQL 8.4.11 run through database creation and SQL Lab reproduced an empty `Ssl_cipher` with mysqlclient 2.2.8 (`mysql://` and `mysql+mysqldb://`). Connector/Python 9.3.0 rejected the `ssl` keyword and PyMySQL 1.2.0 rejected its string value. Importantly, using `ssl_mode=REQUIRED` alone is insufficient: mysqlclient linked to MariaDB Connector/C 3.3.19 still falls back to cleartext when the server does not advertise TLS. Use `VERIFY_CA` (retaining `VERIFY_IDENTITY`) for mysqlclient, and `ssl_verify_cert=True` for Connector/Python/PyMySQL. A private CA and a valid server certificate may therefore be required. Reject incompatible overrides and older PyMySQL versions that permit fallback. Preserve PyMySQL CA options through SQLAlchemy's SSL-dictionary conversion. ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF Not applicable (connection transport behavior). ### TESTING INSTRUCTIONS `pytest tests/unit_tests/db_engine_specs/test_mysql.py`: 89 passed. Initial new regressions failed before the change. Changed-file pre-commit passed, including mypy and pylint. Live: run local MySQL 8 with TLS, then enable `require_secure_transport=ON`; test each of the four URI spellings with `ssl=1` and with the toggle-produced URI. Supply the test CA and execute `SHOW STATUS LIKE 'Ssl_cipher'` in SQL Lab. All 16 final cases negotiated `TLS_AES_256_GCM_SHA384`. Repeat against a server started with `--tls-version=`: all 8 connection attempts must fail with native TLS errors, not produce an empty cipher. The verification-mode behavior was checked with a locally signed server certificate valid for the loopback hostname/address. ### ADDITIONAL INFORMATION - [ ] Has associated issue: - [ ] Required feature flags: - [ ] Changes UI - [ ] Includes DB Migration - [ ] Introduces new feature or API - [ ] Removes existing feature or API -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
