aminghadersohi commented on code in PR #44723:
URL: https://github.com/apache/superset/pull/44723#discussion_r4129944076
##########
superset/db_engine_specs/mysql.py:
##########
@@ -78,6 +80,78 @@
)
+def _require_mysql_verified_tls(
+ driver: str, query: dict[str, Any], args: dict[str, Any]
+) -> None:
+ """Use required verification on drivers without an encryption-only mode."""
+ options = {**query, **args}
+ # Connector/Python has no REQUIRED mode: certificate verification is
+ # necessary to prevent its opportunistic fallback to cleartext.
+ if options.get("ssl_disabled"):
+ raise ValueError("MySQL SSL request conflicts with ssl_disabled")
Review Comment:
Fixed in 42404b91a6: `ssl_disabled` is now parsed with `asbool`, so
`false`/`0` is accepted and dropped (never reaching the driver as a truthy
string), while a true value still fails closed. Covered by
`test_ssl_request_drops_non_disabling_ssl_disabled` and
`test_ssl_request_rejects_url_ssl_disabled`.
##########
superset/db_engine_specs/mysql.py:
##########
@@ -445,6 +519,8 @@ def adjust_engine_params(
if schema:
uri = uri.set(database=parse.quote(schema, safe=""))
+ if cls.engine == "mysql":
+ return require_mysql_tls(uri, new_connect_args)
Review Comment:
Fixed in 42404b91a6: the `auroradataapi` driver now accepts the SSL toggle,
consuming the scalar `ssl` request without passing it to the HTTPS-only Data
API driver. Covered by `test_ssl_request_aurora_data_api_uses_https`.
##########
superset/db_engine_specs/mysql.py:
##########
@@ -78,6 +80,84 @@
)
+def _require_mysql_verified_tls(
+ driver: str, query: dict[str, Any], args: dict[str, Any]
+) -> None:
+ """Use required verification on drivers without an encryption-only mode."""
+ options = {**query, **args}
+ # Connector/Python has no REQUIRED mode: certificate verification is
+ # necessary to prevent its opportunistic fallback to cleartext.
+ if options.get("ssl_disabled"):
+ raise ValueError("MySQL SSL request conflicts with ssl_disabled")
+ if "ssl_verify_cert" in options and not asbool(options["ssl_verify_cert"]):
+ raise ValueError("MySQL SSL request requires ssl_verify_cert")
+ if driver == "pymysql":
+ pymysql = import_module("pymysql")
+
+ # Older releases silently fall back even with explicit SSL options.
+ if pymysql.VERSION[:2] < (1, 2):
+ raise ValueError("The MySQL SSL toggle requires PyMySQL >= 1.2")
+ # SQLAlchemy folds URL ssl_ca/cert/key into an ssl dictionary,
+ # but PyMySQL ignores that dictionary when ssl_verify_cert is set.
+ # Keep these as native connect_args so the CA is not discarded.
+ for key in ("ssl_ca", "ssl_cert", "ssl_key"):
+ if key in query:
+ args.setdefault(key, query.pop(key))
+ if "ssl_check_hostname" in query:
+ args.setdefault(
+ "ssl_verify_identity", asbool(query.pop("ssl_check_hostname"))
+ )
Review Comment:
Fixed both in 42404b91a6: blank boolean options are treated as unset before
`asbool` (`test_pymysql_blank_hostname_check_is_unset`), and an
`ssl_verify_identity` connect_arg that contradicts URL `ssl_check_hostname` is
now rejected instead of silently winning
(`test_pymysql_hostname_check_conflict_fails_closed`).
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]