[INLONG-12215][Manager] Filter sensitive JDBC URL params in OceanBase sink - #12216
Open
akashchamp wants to merge 1 commit into
Open
akashchamp wants to merge 1 commit into
akashchamp wants to merge 1 commit into
Conversation
… sink OceanBaseSinkDTO#getFromRequest never applied any sensitive-parameter filtering to the submitted JDBC URL, even though its @APinote says the config must be filtered before saving. The MySQL sink (INLONG-11731 / apache#11732) already filters autoDeserialize, allowLoadLocalInfile, allowUrlInLocalInfile and allowLoadLocalInfileInPath via MySQLSensitiveUrlUtils, but the OceanBase sink entry point never called it, so a raw autoDeserialize=true could be smuggled through the OceanBase sink config into OceanBaseLoadNode.tableOptions() and on to Connector/J, enabling unsafe Java deserialization. Apply the same MySQLSensitiveUrlUtils#filterSensitive(...) call used by MySQLSinkDTO#getFromRequest to OceanBaseSinkDTO#getFromRequest, since the OceanBase JDBC URL follows the same MySQL-protocol-compatible syntax. Add a filterSensitive(String) wrapper mirroring MySQLSinkDTO#filterSensitive for consistency and testability. Fixes apache#12215
akashchamp
force-pushed
the
fix/12215-oceanbase-sink-jdbc-url-sensitive-filter
branch
from
September 25, 2026 17:59
78afb61 to
1a4c6b3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #12215
Motivation
OceanBaseSinkDTO#getFromRequestpersists the submitted JDBC URL as-is,even though its own
@apiNotesays sensitive params must be filteredbefore saving:
The sibling MySQL sink DTO had exactly the same gap and was fixed in
#11732 (INLONG-11731) by calling
MySQLSensitiveUrlUtils.filterSensitive(...)on the URL before it is stored. That fix was never applied to the
OceanBase sink, so a tenant can still submit an OceanBase sink whose
JDBC URL carries
autoDeserialize=true(and the other paramsMySQLSensitiveUrlUtilsneutralizes:allowLoadLocalInfile,allowUrlInLocalInfile,allowLoadLocalInfileInPath). That raw URL isstored, then forwarded verbatim by
OceanBaseLoadNode.tableOptions()to the Flink JDBC connector / Connector-J, where
autoDeserialize=trueenables unsafe Java deserialization on
ResultSet.getObject().Note the OceanBase JDBC URL is already MySQL-protocol-compatible (the
class even defines
OCEANBASE_JDBC_PREFIX_CDC = "jdbc:mysql://"forthe CDC path), so reusing
MySQLSensitiveUrlUtilsdirectly — the sameutility
OceanBaseJdbcUtils(the Manager-side connectivity check) andStarRocksDataNodeDTOalready reuse — is consistent with the rest ofthe codebase, not a new dependency.
Modifications
OceanBaseSinkDTO#getFromRequest: filterrequest.getJdbcUrl()through
MySQLSensitiveUrlUtils#filterSensitivebefore it is storedon the DTO, mirroring
MySQLSinkDTO#getFromRequest.OceanBaseSinkDTO#filterSensitive(String), a thin wrapper aroundMySQLSensitiveUrlUtils#filterSensitive, mirroring the existingMySQLSinkDTO#filterSensitive(String)for consistency and testability.No behavior changes outside the OceanBase sink's
getFromRequestpath.Verifying this change
OceanBaseSinkDTOTest#testFilterSensitive, adapted from theexisting
MySQLSinkDTOTest#testFilterSensitivefor OceanBase URLs(plain params, percent-encoded params, parenthesized param lists).
OceanBaseSinkDTOTest#testGetFromRequestFiltersSensitiveParams,a regression test asserting
getFromRequest(...)on a request whosejdbcUrlcontainsautoDeserialize=true&allowLoadLocalInfile=trueproduces a DTO whose
jdbcUrlno longer containsautoDeserialize=true(it is replaced withautoDeserialize=false,etc.).
OceanBaseSinkDTOfixreverted (test file kept),
mvn testfails to compile the newtest —
cannot find symbol: method filterSensitive(String)—because the filtering method/call doesn't exist on
mainyet.mvn -pl inlong-manager/manager-pojo -am test(JDK 11, Maven 3.9.16) — full
manager-pojomodule suite:Tests run: 45, Failures: 0, Errors: 0, Skipped: 0,BUILD SUCCESS,including both new tests and the pre-existing
MySQLSinkDTOTest#testFilterSensitive(unaffected, still passing).mvn spotless:checkonmanager-pojo: no violations.Documentation