[coverage] Conformance findings: AUTH-012
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 45/100
- Issue-Typ
- Bug
- Klarheit
- Größtenteils klar
- Aktivitätsstatus
- Ruhig
- Tech-Stack
- node.js, typescript
- Bereich
- security
Rechercherichtung
Beginne mit den AUTH-012-xfail-Tests unter tests/ in Coverage-PR 1115 und vergleiche das beabsichtigte Verhalten mit Referenz-PR 463. Reproduziere die Thrift- und SEA-Fälle und verfolge anschließend die betroffenen Verbindungspfade. Die Aufgabe ist erledigt, wenn beide Protokolle das nicht vertrauenswürdige Zertifikat zurückweisen, ohne OpenSession oder CreateSession zu senden, einen zertifikats-/TLS-bezogenen Fehler melden und aussichtslose Wiederholungsversuche vermeiden.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-012 [thrift]: Thrift path accepts a server certificate that chains to nothing in its trust set: the connection succeeds and one OpenSession (carrying the bearer token) reaches the untrusted MITM endpoint, so server-certificate verification is not on by default on the proxied Thrift transport
- failing test:
server certificate validation is enabled by default [thrift] [xfail](see the coverage PR diff undertests/)
- failing test:
- AUTH-012 [sea]: SEA/kernel rejects the untrusted certificate (0 CreateSession on the wire) but surfaces only the opaque 'HTTP request failed after 5 attempts: error sending request for url (...)' with no certificate/TLS reason in the error or its cause chain, and retries the doomed handshake 5x
- failing test:
server certificate validation is enabled by default [sea] [xfail](see the coverage PR diff undertests/)
- failing test:
- AUTH-012: Thrift path accepts a server certificate that chains to nothing in its trust set: connecting through an interception proxy whose CA is absent from the trust configuration succeeds and sends OpenSession (with the bearer token) to the untrusted peer, so server-certificate verification is not enabled by default on the proxied Thrift transport
- AUTH-012: SEA/kernel correctly rejects an untrusted server certificate (no CreateSession is sent) but reports it as the opaque "HTTP request failed after 5 attempts: error sending request for url (...)" with no certificate/TLS reason in the error or its cause chain, and retries the doomed handshake 5 times, so callers cannot distinguish a TLS trust failure from a network outage
Reproduce & Expected
AUTH-012 — Verifies the driver is secure-by-default: with NO TLS options supplied, the driver performs full chain + hostname verification of the server certificate, and a server whose certificate does NOT chain…
Expected (per the shared spec):
- [thrift] exactly 0
OpenSessioncall(s) - [sea] exactly 0
CreateSessioncall(s) - full assertion contract:
result:
- error:
contains:
- certificate
- cert
- self-signed
- self signed
- unable to verify
- unable to get local issuer
- tls
- ssl
- handshake
protocol:
thrift:
- call_count:
method: OpenSession
expected: 0
sea:
- call_count:
operation: CreateSession
expected: 0
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-sql-nodejs/pull/463 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1115
- Vorherrschende Sprache
- TypeScript
- Sterne
- 37
- Forks
- 51
- Ø Merge
- 10 Std. 38 Min.
- Gemergte PRs (30 T.)
- 8
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus databricks/databricks-sql-nodejs
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
databricks/databricks-sql-nodejs#526 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
databricks/databricks-sql-nodejs#503 ·
Maintainer antworten meist innerhalb von 1 Tag
-
engineer-bot
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 64/100
databricks/databricks-sql-nodejs#274 · 1 Kommentar · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
databricks/databricks-sql-nodejs#540 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 55/100
databricks/databricks-sql-nodejs#539 ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in databricks/databricks-sql-nodejs
Ähnliche Issues
-
bot:ai-assisted status:untriaged
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
midnightntwrk/midnight-js#1424 ·
Maintainer antworten meist innerhalb von 1 Tag
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
mksglu/context-mode#1268 ·
Maintainer antworten meist innerhalb von 5 Tagen
-
[bug] Setup fails with "Cannot find matching keyid" when an older Node's corepack is on PATHEvtl. vergeben @EyalPoly hat das heute übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
MystenLabs/MemWal#1124 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Edit:Offencheck:failed streams:edit
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 60/100
iptv-org/iptv#54352 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag