bito-code-review[bot] commented on code in PR #44723:
URL: https://github.com/apache/superset/pull/44723#discussion_r4129945624


##########
superset/db_engine_specs/mysql.py:
##########
@@ -78,6 +80,84 @@
 )
 
 
+def _require_mysql_verified_tls(
+    driver: str, query: dict[str, Any], args: dict[str, Any]
+) -> None:
+    """Use required verification on drivers without an encryption-only mode."""
+    options = {**query, **args}
+    # Connector/Python has no REQUIRED mode: certificate verification is
+    # necessary to prevent its opportunistic fallback to cleartext.
+    if options.get("ssl_disabled"):
+        raise ValueError("MySQL SSL request conflicts with ssl_disabled")
+    if "ssl_verify_cert" in options and not asbool(options["ssl_verify_cert"]):
+        raise ValueError("MySQL SSL request requires ssl_verify_cert")
+    if driver == "pymysql":
+        pymysql = import_module("pymysql")
+
+        # Older releases silently fall back even with explicit SSL options.
+        if pymysql.VERSION[:2] < (1, 2):
+            raise ValueError("The MySQL SSL toggle requires PyMySQL >= 1.2")
+        # SQLAlchemy folds URL ssl_ca/cert/key into an ssl dictionary,
+        # but PyMySQL ignores that dictionary when ssl_verify_cert is set.
+        # Keep these as native connect_args so the CA is not discarded.
+        for key in ("ssl_ca", "ssl_cert", "ssl_key"):
+            if key in query:
+                args.setdefault(key, query.pop(key))
+        if "ssl_check_hostname" in query:
+            args.setdefault(
+                "ssl_verify_identity", asbool(query.pop("ssl_check_hostname"))
+            )

Review Comment:
   <!-- Bito Reply -->
   The changes in the provided code correctly address the identified issues. 
Handling empty strings before calling `asbool` prevents potential `ValueError` 
exceptions, and explicitly rejecting conflicting `ssl_verify_identity` 
arguments ensures that security settings are not silently overridden. These 
updates improve the robustness and security of the TLS verification logic.
   
   **superset/db_engine_specs/mysql.py**
   ```
   if "ssl_verify_cert" in options and not asbool(options["ssl_verify_cert"]):
           raise ValueError("MySQL SSL request requires ssl_verify_cert")
       if driver == "pymysql":
           pymysql = import_module("pymysql")
   
           # Older releases silently fall back even with explicit SSL options.
           if pymysql.VERSION[:2] < (1, 2):
               raise ValueError("The MySQL SSL toggle requires PyMySQL >= 1.2")
           # SQLAlchemy folds URL ssl_ca/cert/key into an ssl dictionary,
           # but PyMySQL ignores that dictionary when ssl_verify_cert is set.
           # Keep these as native connect_args so the CA is not discarded.
           for key in ("ssl_ca", "ssl_cert", "ssl_key"):
               if key in query:
                   args.setdefault(key, query.pop(key))
           if "ssl_check_hostname" in query:
               args.setdefault(
                   "ssl_verify_identity", 
asbool(query.pop("ssl_check_hostname"))
               )
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to