aminghadersohi opened a new pull request, #44723:
URL: https://github.com/apache/superset/pull/44723

   ### SUMMARY
   
   Make MySQL's SSL toggle and saved `ssl=1` URLs require TLS through 
driver-native options. Preserve schema selection, local-infile restrictions, 
and stronger verification settings; do not change MySQL-compatible engine 
subclasses.
   
   A local MySQL 8.4.11 run through database creation and SQL Lab reproduced an 
empty `Ssl_cipher` with mysqlclient 2.2.8 (`mysql://` and `mysql+mysqldb://`). 
Connector/Python 9.3.0 rejected the `ssl` keyword and PyMySQL 1.2.0 rejected 
its string value.
   
   Importantly, using `ssl_mode=REQUIRED` alone is insufficient: mysqlclient 
linked to MariaDB Connector/C 3.3.19 still falls back to cleartext when the 
server does not advertise TLS. Use `VERIFY_CA` (retaining `VERIFY_IDENTITY`) 
for mysqlclient, and `ssl_verify_cert=True` for Connector/Python/PyMySQL. A 
private CA and a valid server certificate may therefore be required. Reject 
incompatible overrides and older PyMySQL versions that permit fallback. 
Preserve PyMySQL CA options through SQLAlchemy's SSL-dictionary conversion.
   
   ### BEFORE/AFTER SCREENSHOTS OR ANIMATED GIF
   
   Not applicable (connection transport behavior).
   
   ### TESTING INSTRUCTIONS
   
   `pytest tests/unit_tests/db_engine_specs/test_mysql.py`: 89 passed. Initial 
new regressions failed before the change. Changed-file pre-commit passed, 
including mypy and pylint.
   
   Live: run local MySQL 8 with TLS, then enable `require_secure_transport=ON`; 
test each of the four URI spellings with `ssl=1` and with the toggle-produced 
URI. Supply the test CA and execute `SHOW STATUS LIKE 'Ssl_cipher'` in SQL Lab. 
All 16 final cases negotiated `TLS_AES_256_GCM_SHA384`. Repeat against a server 
started with `--tls-version=`: all 8 connection attempts must fail with native 
TLS errors, not produce an empty cipher. The verification-mode behavior was 
checked with a locally signed server certificate valid for the loopback 
hostname/address.
   
   ### ADDITIONAL INFORMATION
   
   - [ ] Has associated issue:
   - [ ] Required feature flags:
   - [ ] Changes UI
   - [ ] Includes DB Migration
   - [ ] Introduces new feature or API
   - [ ] Removes existing feature or API
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to