github snowflakedb/snowflake-connector-python v4.8.0
4.8.0

4 hours ago
  • OCSP certificate revocation checks are now off unless you opt in. Set ocsp_fail_open=True or ocsp_fail_open=False to enable OCSP. The stored default is None (unset); only an explicit True/False opts in, so forwarding DEFAULT_CONFIGURATION as kwargs does not turn OCSP on. disable_ocsp_checks=True (or insecure_mode=True) always turns OCSP off, including when ocsp_fail_open is also set. disable_ocsp_checks=False and insecure_mode=False are the stored defaults and are not an opt-in. Connection attribute ocsp_fail_open is no longer a report of whether OCSP is fail-open; it is the stored preference (None = unset, True = fail-open, False = fail-closed). Use _ocsp_mode() / disable_ocsp_checks to see whether checks are actually on. ocsp_response_cache_filename and ocsp_root_certs_dict_lock_timeout do not turn OCSP on; if they are set without an OCSP mode parameter they are ignored and a warning is logged. The SF_OCSP_FAIL_OPEN environment variable still only switches fail-open vs fail-closed after OCSP is already on. Login OCSP_MODE telemetry now reports DISABLE_OCSP_CHECKS by default. The process-global FEATURE_OCSP_MODE is updated by each constructed REST client, except that a later default (OCSP off) client does not overwrite a non-default already stored on the process, and a later FAIL_OPEN client does not overwrite FAIL_CLOSED.

  • Fixed external-browser (SSO) authentication to validate the Origin header on the local callback server, rejecting tokens delivered from unexpected origins. A trailing slash in the origin (e.g. https://account.snowflakecomputing.com/) is now accepted on par with the bare origin, matching JDBC and other driver behaviour. Preconnect probe connections (empty recv) no longer count against the retry budget and no longer abort the login flow.

  • Added the SNOWFLAKE_TLS_CIPHERS environment variable to restrict which TLS ciphers the connector offers. It takes a colon-separated list; names beginning with TLS_ are applied as TLS 1.3 cipher suites and the remainder as the cipher list for TLS 1.2 and below, so a single variable covers both. Leaving it unset keeps OpenSSL's defaults unchanged, and an unrecognized cipher name is rejected rather than silently ignored. The restriction covers Snowflake API traffic, cloud-storage (stage) transfers, OCSP/CRL fetches and IdP requests. Requests issued by the AWS and Azure SDKs, and asynchronous connections, are not covered — for TLS 1.3 suites specifically they cannot be, because the Python standard library exposes no API for restricting them.

  • Raised the minimum pyOpenSSL requirement to 25.3.0, the first version providing set_tls13_ciphersuites. This does not narrow the set of installable versions in practice: earlier releases cap cryptography below 46 and so were already uninstallable alongside the connector's own cryptography>=46.0.5 requirement.

  • Added the workload_identity_host connection option that overrides the STS host used by AWS Workload Identity Federation, for endpoints the driver cannot derive from the region (such as an interface VPC endpoint). The default STS host is now resolved via botocore so partitions that do not use amazonaws.com (ISO, European Sovereign Cloud, ...) get the correct hostname. A privately routed host cannot be reached by Snowflake on the default GetCallerIdentity path, so a VPC or PrivateLink STS endpoint also requires workload_identity_aws_use_outbound_token=True (SNOW-4017192).

  • Fixed MD5 computation for Azure clouds (SNOW-4168830).

Don't miss a new snowflake-connector-python release

NewReleases is sending notifications on new releases.