rusackas commented on PR #44718:
URL: https://github.com/apache/superset/pull/44718#issuecomment-5894490046
One more, and this one's arguably more central than the MariaDB gap since it
hits plain MySQL directly: `require_mysql_tls` only decides whether TLS was
"requested" by checking the `ssl` key (`query.get("ssl")` / `args.get("ssl")`),
it never looks at `ssl_mode`. So a MySQL database saved with a raw
`mysql://...?ssl_mode=REQUIRED` URI (no `ssl=1`) skips the whole function via
the early return and keeps the unverified `REQUIRED` mode, the exact MariaDB
Connector/C cleartext-fallback this PR exists to close.
`require_mysqlclient_tls` in `doris.py` actually already compensates for this
(it synthesizes `ssl=1` whenever `ssl_mode` is already one of the required
modes before calling `require_mysql_tls`), that logic just never made it into
the shared function itself, so Doris ends up more protected than plain MySQL.
Might be worth hoisting that synthesis into `require_mysql_tls` directly so
every caller gets it for free.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]