Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Epic: Interactive human-login OAuth for `confluent_sql`

Open
#150 0 comments 0 reactions 1 assignee View on GitHub

Maintainers usually reply within 1 day

@jlrobins is already working on this.

Since Aug 10, 2026.

Assessment

This issue has not been assessed yet.

Description

This epic gives the driver a full interactive browser login: a three-hop Auth0 PKCE chain that mints Confluent's own control-plane and data-plane tokens, refreshed by a background daemon and shared process-wide. Unlike the sibling BYOIDC epic — where the caller supplies an external token good only for the Flink data plane — a Confluent-minted control-plane token reaches the whole surface: Flink plus Tableflow, Connect, and CMK. One human login collapses up to three API-key pairs into one credential.

The neighboring Java client (confluent-flink-plugin-private#399, squash 64b3b17, FTAB-97) shipped machine-to-machine OAuth — a static token or a refreshing client-credentials provider — but never an interactive browser login, the /api/sessions → /api/access_tokens control-plane chain, or a process-wide multi-Connection holder. Those are this epic's distinguishing work: the reach the plugin's Flink-data-plane-only scope never had to touch. (The plugin's BYOIDC modes are covered by the sibling #148 instead.)

This epic reuses the polymorphic _flink_auth slot and the connect() auth-mode selection point that #100 / PR #146 built (the first step of the BYOIDC epic). It does not depend on that epic's child 2; the two epics diverge past the shared seam and can proceed in parallel.

Alas, dbapi is synchronous/blocking python, so we have to resort to using threads / a short lived webserver thread to receive the success/failure oauth callback. A new markdown document in there repo (for reviewer / claude reference) describes how concurrency will be handled in the face of multiple Connections in multiple threads (a many-threaded dbt session kicking off) each racing to start up the oauth process.

Remember while implementing:

  • We're using branch oauth-epic-integration as integration branch off of main for all of the child issues to base off of. When epic functionality is complete, we'll then merge into main, but we'll PR each reasonable piece at a time.
  • Read and review all child issues to gain context on where the current issue sits in the grand scheme of things to be sure to not do more than is needed in any individual child.
Dominant language
Python
Stars
6
Forks
1
Avg merge
14h 58m
Merged PRs (30d)
22

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from confluentinc/confluent-sql

All issues in confluentinc/confluent-sql

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.