Files
superset2/tests/unit_tests/db_engine_specs/test_impala.py
Shaitan 5fb13f102a fix(network): validate target hostname in outbound requests (#39301)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Evan Rusackas <evan@preset.io>
Co-authored-by: Arpit Jain <3242828+arpitjain099@users.noreply.github.com>
Co-authored-by: Mafi <matt.fitzgerald@gmail.com>
Co-authored-by: Matt Fitzgerald <matt.fitzgerald@preset.io>
Co-authored-by: Richard Fogaca Nienkotter <63572350+richardfogaca@users.noreply.github.com>
Co-authored-by: Superset Dev <dev@superset.apache.org>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: sadpandajoe <jcli38@gmail.com>
Co-authored-by: JUST.in DO IT <justin.park@airbnb.com>
Co-authored-by: Michael S. Molina <70410625+michael-s-molina@users.noreply.github.com>
Co-authored-by: sha174n <pedro.sousa@preset.io>
2026-06-13 20:26:58 +01:00

175 lines
5.6 KiB
Python

# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
from datetime import datetime
from typing import Optional
from unittest.mock import Mock, patch
import pytest
from superset.db_engine_specs.impala import ImpalaEngineSpec as spec # noqa: N813
from superset.models.core import Database
from superset.models.sql_lab import Query
from tests.unit_tests.db_engine_specs.utils import assert_convert_dttm
from tests.unit_tests.fixtures.common import dttm # noqa: F401
@pytest.mark.parametrize(
"target_type,expected_result",
[
("Date", "CAST('2019-01-02' AS DATE)"),
("TimeStamp", "CAST('2019-01-02T03:04:05.678900' AS TIMESTAMP)"),
("UnknownType", None),
],
)
def test_convert_dttm(
target_type: str,
expected_result: Optional[str],
dttm: datetime, # noqa: F811
) -> None:
assert_convert_dttm(spec, target_type, expected_result, dttm)
def test_get_cancel_query_id() -> None:
query = Query()
cursor_mock = Mock()
last_operation_mock = Mock()
cursor_mock._last_operation = last_operation_mock
guid = bytes(reversed(bytes.fromhex("9fbdba20000000006940643a2731718b")))
last_operation_mock.handle.operationId.guid = guid
assert (
spec.get_cancel_query_id(cursor_mock, query)
== "6940643a2731718b:9fbdba2000000000"
)
@patch("superset.db_engine_specs.impala.is_safe_host", return_value=True)
@patch("requests.post")
def test_cancel_query(post_mock: Mock, _safe_host: Mock) -> None: # noqa: PT019
query = Query()
database = Database(
database_name="test_impala",
sqlalchemy_uri="impala://impala.example.com:21050/default",
)
query.database = database
response_mock = Mock()
response_mock.status_code = 200
post_mock.return_value = response_mock
result = spec.cancel_query(None, query, "6940643a2731718b:9fbdba2000000000")
post_mock.assert_called_once_with(
"http://impala.example.com:25000/cancel_query?query_id=6940643a2731718b:9fbdba2000000000",
timeout=3,
allow_redirects=False,
)
assert result is True
@patch("superset.db_engine_specs.impala.is_safe_host", return_value=True)
@patch("requests.post")
def test_cancel_query_failed(post_mock: Mock, _safe_host: Mock) -> None: # noqa: PT019
query = Query()
database = Database(
database_name="test_impala",
sqlalchemy_uri="impala://impala.example.com:21050/default",
)
query.database = database
response_mock = Mock()
response_mock.status_code = 500
post_mock.return_value = response_mock
result = spec.cancel_query(None, query, "6940643a2731718b:9fbdba2000000000")
post_mock.assert_called_once_with(
"http://impala.example.com:25000/cancel_query?query_id=6940643a2731718b:9fbdba2000000000",
timeout=3,
allow_redirects=False,
)
assert result is False
@patch("superset.db_engine_specs.impala.is_safe_host", return_value=True)
@patch("requests.post")
def test_cancel_query_exception(post_mock: Mock, _safe_host: Mock) -> None: # noqa: PT019
query = Query()
database = Database(
database_name="test_impala",
sqlalchemy_uri="impala://impala.example.com:21050/default",
)
query.database = database
post_mock.side_effect = Exception("Network error")
result = spec.cancel_query(None, query, "6940643a2731718b:9fbdba2000000000")
assert result is False
@patch("requests.post")
def test_cancel_query_blocks_internal_host(post_mock: Mock, app_context: None) -> None:
"""A private/internal Impala host is refused by default (no HTTP call)."""
query = Query()
database = Database(
database_name="test_impala",
sqlalchemy_uri="impala://169.254.169.254:21050/default",
)
query.database = database
result = spec.cancel_query(None, query, "6940643a2731718b:9fbdba2000000000")
assert result is False
post_mock.assert_not_called()
@patch("requests.post")
def test_cancel_query_allows_internal_host_with_opt_out(
post_mock: Mock, app_context: None
) -> None:
"""IMPALA_CANCEL_QUERY_ALLOW_INTERNAL_HOSTS=True permits internal targets."""
from flask import current_app
query = Query()
database = Database(
database_name="test_impala",
sqlalchemy_uri="impala://10.0.0.5:21050/default",
)
query.database = database
response_mock = Mock()
response_mock.status_code = 200
post_mock.return_value = response_mock
original = current_app.config.get("IMPALA_CANCEL_QUERY_ALLOW_INTERNAL_HOSTS")
current_app.config["IMPALA_CANCEL_QUERY_ALLOW_INTERNAL_HOSTS"] = True
try:
result = spec.cancel_query(None, query, "6940643a2731718b:9fbdba2000000000")
finally:
current_app.config["IMPALA_CANCEL_QUERY_ALLOW_INTERNAL_HOSTS"] = original
post_mock.assert_called_once_with(
"http://10.0.0.5:25000/cancel_query?query_id=6940643a2731718b:9fbdba2000000000",
timeout=3,
allow_redirects=False,
)
assert result is True