Fix high-severity issues: implement SSL and warn on raw-SQL filter

SSL was wired through the UI and ConnectionProfile but never actually
applied in any driver or passed from the connection builder.

- main_window: pass ssl/ssl_ca/ssl_cert/ssl_key from profile into
  the driver config dict so drivers can act on them
- MySQL: add ssl={ca,cert,key} to pymysql connect kwargs when enabled
- PostgreSQL: set sslmode=verify-ca (with CA) or require, plus
  sslrootcert/sslcert/sslkey when provided
- MSSQL: switch Encrypt=yes + TrustServerCertificate=no when SSL is
  on; Encrypt=no + TrustServerCertificate=yes otherwise
- SQLite: no change needed (local file, no network layer)

WHERE filter: add tooltip explicitly labelling the input as raw SQL
so users understand arbitrary expressions are executed directly.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-05-21 16:07:02 -04:00
co-authored by Claude Sonnet 4.6
parent 724594d3f1
commit 4ccc81955e
5 changed files with 29 additions and 2 deletions
+9 -1
View File
@@ -34,12 +34,20 @@ class MSSQLDriver(BaseDriver):
installed = pyodbc.drivers() if PYODBC_AVAILABLE else []
driver = next((d for d in preferred if d in installed), preferred[0])
if self.config.get("ssl"):
encrypt = "yes"
trust_cert = "no"
else:
encrypt = "no"
trust_cert = "yes"
return (
f"DRIVER={{{driver}}};"
f"SERVER={host},{port};"
f"DATABASE={db};"
f"UID={user};PWD={pwd};"
f"TrustServerCertificate=yes;"
f"Encrypt={encrypt};"
f"TrustServerCertificate={trust_cert};"
f"Connection Timeout={self.config.get('connection_timeout', 30)};"
)