Michael Smith has submitted this change and it was merged. ( http://gerrit.cloudera.org:8080/24775 )
Change subject: IMPALA-15219: Enforce strict validation for AI endpoint hostnames ...................................................................... IMPALA-15219: Enforce strict validation for AI endpoint hostnames The AiFunctions currently validates allowed AI endpoints using a simple substring match (gstrncasestr). This can allow improperly formatted or malicious URLs to pass validation if they contain the target domain string in the path. This commit makes the validation stricter and more robust by enforcing structural hostname matching: 1. Added a helper ExtractHost() to parse the URL and isolate the canonical hostname. 2. Added a helper IsHostMatch() to perform exact domain and strict subdomain matching against the allowed endpoint list. 3. Updated GetAiPlatformFromEndpoint() to evaluate the exact host using the new helper functions, ensuring malicious URLs are rejected as unsupported. Testing: Added test cases to AiFunctionsTest and AiFunctionsTestAdditionalSites to ensure that URLs with target domains hidden in paths are correctly rejected. Change-Id: I5481dec7d798dc6ca7273b0028b9317ab69c39f5 Reviewed-on: http://gerrit.cloudera.org:8080/24775 Reviewed-by: Joe McDonnell <[email protected]> Tested-by: Michael Smith <[email protected]> --- M be/src/exprs/ai-functions-ir.cc M be/src/exprs/expr-test.cc 2 files changed, 74 insertions(+), 17 deletions(-) Approvals: Joe McDonnell: Looks good to me, approved Michael Smith: Verified -- To view, visit http://gerrit.cloudera.org:8080/24775 To unsubscribe, visit http://gerrit.cloudera.org:8080/settings Gerrit-Project: Impala-ASF Gerrit-Branch: branch-4.5.2 Gerrit-MessageType: merged Gerrit-Change-Id: I5481dec7d798dc6ca7273b0028b9317ab69c39f5 Gerrit-Change-Number: 24775 Gerrit-PatchSet: 3 Gerrit-Owner: Michael Smith <[email protected]> Gerrit-Reviewer: Impala Public Jenkins <[email protected]> Gerrit-Reviewer: Joe McDonnell <[email protected]> Gerrit-Reviewer: Michael Smith <[email protected]> Gerrit-Reviewer: Steve Carlin <[email protected]>
