Epic: Interactive human-login OAuth for `confluent_sql`
Maintainers usually reply within 1 day
@jlrobins is already working on this.
Since Aug 10, 2026.
Assessment
This issue has not been assessed yet.
Description
This epic gives the driver a full interactive browser login: a three-hop Auth0 PKCE chain that mints Confluent's own control-plane and data-plane tokens, refreshed by a background daemon and shared process-wide. Unlike the sibling BYOIDC epic — where the caller supplies an external token good only for the Flink data plane — a Confluent-minted control-plane token reaches the whole surface: Flink plus Tableflow, Connect, and CMK. One human login collapses up to three API-key pairs into one credential.
The neighboring Java client (confluent-flink-plugin-private#399, squash 64b3b17, FTAB-97) shipped machine-to-machine OAuth — a static token or a refreshing client-credentials provider — but never an interactive browser login, the /api/sessions → /api/access_tokens control-plane chain, or a process-wide multi-Connection holder. Those are this epic's distinguishing work: the reach the plugin's Flink-data-plane-only scope never had to touch. (The plugin's BYOIDC modes are covered by the sibling #148 instead.)
This epic reuses the polymorphic _flink_auth slot and the connect() auth-mode selection point that #100 / PR #146 built (the first step of the BYOIDC epic). It does not depend on that epic's child 2; the two epics diverge past the shared seam and can proceed in parallel.
Alas, dbapi is synchronous/blocking python, so we have to resort to using threads / a short lived webserver thread to receive the success/failure oauth callback. A new markdown document in there repo (for reviewer / claude reference) describes how concurrency will be handled in the face of multiple Connections in multiple threads (a many-threaded dbt session kicking off) each racing to start up the oauth process.
Remember while implementing:
- We're using branch
oauth-epic-integrationas integration branch off of main for all of the child issues to base off of. When epic functionality is complete, we'll then merge into main, but we'll PR each reasonable piece at a time. - Read and review all child issues to gain context on where the current issue sits in the grand scheme of things to be sure to not do more than is needed in any individual child.
- Dominant language
- Python
- Stars
- 6
- Forks
- 1
- Avg merge
- 14h 58m
- Merged PRs (30d)
- 22
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from confluentinc/confluent-sql
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
confluentinc/confluent-sql#226 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
confluentinc/confluent-sql#224 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
confluentinc/confluent-sql#223 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
confluentinc/confluent-sql#125 ·
Maintainers usually reply within 1 day
-
List connectorsOpen
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
confluentinc/confluent-sql#124 ·
Maintainers usually reply within 1 day
All issues in confluentinc/confluent-sql
Similar issues
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 73/100
githubnext/gh-aw-workshop#4455 ·
Maintainers usually reply within 1 day
-
Triage 🩺
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day
-
[BUG] Container scenario crashes without expected_recovery_time, kube DNS example uses retry_waitOpenneeds-triage
Difficulty 2/5 1-3 hours Newbie friendliness 77/100
krkn-chaos/krkn#1627 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NousResearch/hermes-agent#136483 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day