rusackas commented on PR #44718:
URL: https://github.com/apache/superset/pull/44718#issuecomment-5894490046

   One more, and this one's arguably more central than the MariaDB gap since it 
hits plain MySQL directly: `require_mysql_tls` only decides whether TLS was 
"requested" by checking the `ssl` key (`query.get("ssl")` / `args.get("ssl")`), 
it never looks at `ssl_mode`. So a MySQL database saved with a raw 
`mysql://...?ssl_mode=REQUIRED` URI (no `ssl=1`) skips the whole function via 
the early return and keeps the unverified `REQUIRED` mode, the exact MariaDB 
Connector/C cleartext-fallback this PR exists to close. 
`require_mysqlclient_tls` in `doris.py` actually already compensates for this 
(it synthesizes `ssl=1` whenever `ssl_mode` is already one of the required 
modes before calling `require_mysql_tls`), that logic just never made it into 
the shared function itself, so Doris ends up more protected than plain MySQL. 
Might be worth hoisting that synthesis into `require_mysql_tls` directly so 
every caller gets it for free.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to