Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[coverage] Conformance findings: AUTH-012,AUTH-015

Abierto
#892 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
45/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
python

Línea de trabajo

Comienza con el diff del PR de cobertura bajo tests/, centrándote en test_server_certificate_validation_enabled_by_default y test_mutual_tls_client_certificate_options_validated; después, sigue las rutas de conexión de Thrift y SEA que ejercitan. Se considera terminado cuando ambas rutas rechazan certificados de servidor no confiables y opciones de identidad del cliente incompletas o malformadas con errores de TLS o de clave del cliente que indiquen cómo actuar, sin realizar llamadas a OpenSession ni CreateSession.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.

Findings

  • AUTH-012 [sea]: kernel (SEA) rejects the untrusted server cert but the error drops rustls's UnknownIssuer cause, reporting only "http request failed after N attempts: error sending request for url (…)" — a TLS-trust misconfiguration is indistinguishable from a network outage
    • failing test: test_server_certificate_validation_enabled_by_default (see the coverage PR diff under tests/)
  • AUTH-015 [thrift]: mTLS client-identity options get no both-or-neither validation: an unpaired _tls_client_cert_file reaches SSLContext.load_cert_chain(certfile=…, keyfile=None) and surfaces OpenSSL's opaque "[SSL] PEM lib", naming neither the supplied option nor the missing private key
    • failing test: test_mutual_tls_client_certificate_options_validated (see the coverage PR diff under tests/)
  • AUTH-012: kernel (SEA) backend rejects an untrusted server certificate but its error drops the rustls cause, reporting only "http request failed after N attempts: error sending request for url (…)" — a TLS-trust misconfiguration is indistinguishable from a network outage
  • AUTH-015: mTLS client-identity options get no both-or-neither validation: an unpaired _tls_client_cert_file reaches load_cert_chain(certfile=…, keyfile=None) on the Thrift path and surfaces OpenSSL's opaque [SSL] PEM lib, naming neither the supplied option nor the missing private key

Reproduce & Expected

AUTH-012 — Verifies the driver is secure-by-default: with NO TLS options supplied, the driver performs full chain + hostname verification of the server certificate, and a server whose certificate does NOT chain…

Expected (per the shared spec):

  • [thrift] exactly 0 OpenSession call(s)
  • [sea] exactly 0 CreateSession call(s)
  • full assertion contract:
result:
- error:
    contains:
    - certificate
    - cert
    - self-signed
    - self signed
    - unable to verify
    - unable to get local issuer
    - tls
    - ssl
    - handshake
protocol:
  thrift:
  - call_count:
      method: OpenSession
      expected: 0
  sea:
  - call_count:
      operation: CreateSession
      expected: 0
AUTH-015 — Verifies that the mutual-TLS (mTLS) client-identity options are validated on the client side with clear, actionable errors instead of failing opaquely deep in the TLS handshake.

Expected (per the shared spec):

  • [thrift] exactly 0 OpenSession call(s)
  • [sea] exactly 0 CreateSession call(s)
  • full assertion contract:
result:
- label: both_or_neither
  error:
    contains:
    - client cert
    - clientcert
    - client key
    - clientkey
    - private key
    - mutual
    - mtls
    - both
- label: malformed_pem
  error:
    contains:
    - pem
    - certificate
    - client cert
    - clientcert
protocol:
  thrift:
  - call_count:
      method: OpenSession
      expected: 0
  sea:
  - call_count:
      operation: CreateSession
      expected: 0

Context

Lenguaje dominante
Python
Estrellas
233
Forks
152
Merge medio
21 h 5 min
PR fusionados (30 d)
10

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de databricks/databricks-sql-python

Todos los issues de databricks/databricks-sql-python

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.