ExportXMLWordPrintableJSON

    • 1
    • Hide

      DRIVERS-3632:
      Summary of necessary driver changes

      • Introduce custom callbacks
      • add an "allow-list" for `srvAllowedHostsSuffix`

      Commits for syncing spec/prose tests
      (and/or refer to an existing language POC if needed)

      Context for other referenced/linked tickets

      • see DRIVERS-3329 for more details on `srvAllowedHostsSuffix`
      Show
      DRIVERS-3632 : Summary of necessary driver changes Introduce custom callbacks add an "allow-list" for `srvAllowedHostsSuffix` Commits for syncing spec/prose tests (and/or refer to an existing language POC if needed) https://github.com/mongodb/specifications/commit/5036f26e816ed2c2f08f87726bd01f9f62087b3a   Context for other referenced/linked tickets see DRIVERS-3329 for more details on `srvAllowedHostsSuffix`
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      This ticket was split from DRIVERS-3632, please see that ticket for a detailed description.

       

      This task has to do with allowing user code to control DNS domain validation, as well as updating Node Driver’s logic to match the specifications.

      There are two DRIVERS spec changes that are tied to the DNS updates:

      • DRIVERS-3329
        • Adds support for `srvAllowedHostsSuffix`
        • Adds hostname normalization logic
        • Must go in first
      • DRIVERS-3632
        • Adds support for `srvHostValidator`
        • A validator that the user passes to us to determine if a hostname is allowed

      Since there is tight coupling between these two updates, we are going to roll those changes into one implementation ticket,

       
      There are 4 major changes:

      1. Normalize SRV host names and use the normalized form everywhere

      • Spec requires trailing-dot strip → A-label → ASCII lowercase on both sides of the comparison, and the normalized name must populate the seedlist.
      • Today Node strips the trailing dot only, inside the comparison helper, and seeds from the raw DNS name.
      • We would normalize in a single spot, use domainToASCII for some of this logic, then pass the normalized component to the various units that need them.
      • Add tests for the new normalization logic.
      • Fix broken tests that expect old standardization.

      2. Add srvAllowedHostsSuffix

      • New option being added to the client, complete with docs.
      • Update connection string parsing logic.
      • Add to userSpecifiedSrvOptions.
      • Thread the value through to topology.ts
      • Add connecting string unit tests
      • Add new prose tests
      • Resync srv-options data (json + yml)

      3. Add srvHostValidator

      • New option added to the client, complete with docs
      • Client-only option, not a URI option, need to throw if this is present in the string
      • Add validator call to the resolution logic
      • Thread through topology.ts
      • Add prose tests
      • Add unit tests
      • Add type test for the callback signature

      4. Documentation

      • Document this feature with a big WARNING
      • Update client docs
      • Regenerate mongodb.d.ts
         

      Acceptance Criteria

      Implementation Requirements

      • Normalize SRV host names
      • Add srvAllowsHostsSuffix
      • Add srvHostValidator
      • Add documentation

      Testing Requirements

      • Update spec tests
      • Update spec test data
      • Update any failing unit tests
      • Add type tests for the callback signature

      Documentation Requirements

      • Documentation for new options
      • Big warning for both new features (from specifications): WARNING: Modifying the default SRV domain name validation can create vulnerabilities

      Follow Up Requirements

      • additional tickets to file, required releases, etc
      • if node behavior differs/will differ from other drivers, confirm with dbx devs what standard to aim for and what plan, if any, exists to reconcile the diverging behavior moving forward

       

       

       

            Assignee:
            Pavel Safronov
            Reporter:
            TPM Jira Automations Bot
            None
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: