cgivre opened a new pull request, #3090: URL: https://github.com/apache/drill/pull/3090
Potential fix for [https://github.com/apache/drill/security/code-scanning/43](https://github.com/apache/drill/security/code-scanning/43) To fix this without changing intended behavior, enforce explicit hostname validation against the set of known Drillbit endpoints before constructing/sending the HTTP request. Best approach: - In `DrillRoot.shutdownDrillbitByName(...)`, validate `hostname` using `work.getContext().getAvailableBits()` and only proceed if there is an exact match. - Reject invalid hostnames with an exception (consistent with existing exception-driven flow). - Keep using `WebUtils.getDrillbitURL(...)` and `doHTTPRequest(...)` after validation so functionality remains unchanged for valid Drillbit hosts. This is a minimal, targeted fix in: - `exec/java-exec/src/main/java/org/apache/drill/exec/server/rest/DrillRoot.java` - Method: `shutdownDrillbitByName(...)` - Add a pre-check for null/empty and allowlist membership. No changes are required in `WebUtils.java` for this fix. _Suggested fixes powered by Copilot Autofix. Review carefully before merging._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
