Skip to content

Commit 045720b

Browse files
fix: is_same_host returns False for bare hostnames (no scheme)
urlparse treats a string with no scheme as an opaque path, so urlparse("host.example.com").netloc is "" while urlparse("https://host.example.com").netloc is "host.example.com". is_same_host therefore returned False whenever one of its arguments lacked a scheme — for example a JWT iss claim stored as a bare hostname vs. self.hostname which is always normalized with https://. Fix: extract a nested helper _extract_host that re-parses with a dummy "https://" prefix when the initial parse yields an empty netloc, recovering the actual hostname in the bare-hostname case. Also normalises extracted hosts to lowercase for a consistent comparison. Add four new parametrize cases to test_is_same_host covering the previously failing mixed-scheme and bare-vs-bare comparisons. Signed-off-by: Shubham-Padkonde <shubhampadkonde12@gmail.com>
1 parent 70427d7 commit 045720b

2 files changed

Lines changed: 19 additions & 6 deletions

File tree

‎src/databricks/sql/auth/auth_utils.py‎

Lines changed: 13 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -36,12 +36,19 @@ def is_same_host(url1: str, url2: str) -> bool:
3636
True if hosts are the same, False otherwise
3737
"""
3838
try:
39-
host1 = urlparse(url1).netloc
40-
host2 = urlparse(url2).netloc
41-
# Handle port differences (e.g., example.com vs example.com:443)
42-
host1_without_port = host1.split(":")[0]
43-
host2_without_port = host2.split(":")[0]
44-
return host1_without_port == host2_without_port
39+
40+
def _extract_host(url: str) -> str:
41+
parsed = urlparse(url)
42+
netloc = parsed.netloc
43+
if not netloc:
44+
# Bare hostname with no scheme: urlparse puts the host in the
45+
# path component and leaves netloc empty. Add a dummy scheme so
46+
# the parser can identify the netloc correctly.
47+
netloc = urlparse(f"https://{url}").netloc
48+
# Strip port (e.g. example.com:443 -> example.com)
49+
return netloc.split(":")[0].lower()
50+
51+
return _extract_host(url1) == _extract_host(url2)
4552
except Exception as e:
4653
logger.debug("Failed to parse URLs: %s", e)
4754
return False

‎tests/unit/test_token_federation.py‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -322,6 +322,12 @@ def test_normalize_hostname(self, input_hostname, expected):
322322
("https://test.databricks.com", "https://test.databricks.com:443", True),
323323
("https://test1.databricks.com", "https://test2.databricks.com", False),
324324
("https://login.microsoftonline.com", "https://test.databricks.com", False),
325+
# Bare hostname (no scheme) — regression: urlparse("host").netloc == ""
326+
# caused these to incorrectly return False
327+
("test.databricks.com", "https://test.databricks.com", True),
328+
("https://test.databricks.com", "test.databricks.com", True),
329+
("test.databricks.com", "test.databricks.com", True),
330+
("other.example.com", "test.databricks.com", False),
325331
],
326332
)
327333
def test_is_same_host(self, url1, url2, expected):

0 commit comments

Comments
 (0)