Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[coverage] Conformance findings: AUTH-017

Abierto
#540 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
55/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
node.js, typescript

Línea de trabajo

Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.

Findings

  • AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift] (see the coverage PR diff under tests/)
  • AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea] (see the coverage PR diff under tests/)
  • AUTH-017: OAuth client-secret M2M ignores the configured scope connection option and always sends scope=all-apis on the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate

Reproduce & Expected

AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…

Reproduce:

SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user

Expected (per the shared spec):

  • completes without an exception
  • result has exactly 1 row(s)
  • completes without an exception
  • result has exactly 1 row(s)
  • full assertion contract:
result:
- label: m2m_multi_scope
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - sql
    - offline_access
    exactly: true
- label: m2m_multi_scope
  no_exception: true
- label: m2m_multi_scope
  row_count: 1
- label: m2m_blank_default
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - all-apis
    exactly: true
- label: m2m_blank_default
  no_exception: true
- label: m2m_blank_default
  row_count: 1
- label: jwt_blank_omits
  oauth_token_request_scope:
    grant_type: client_credentials
    present: false
- label: u2m_blank_default
  oauth_token_request_scope:
    scopes:
    - sql
    - offline_access
    exactly: true

Context

Lenguaje dominante
TypeScript
Estrellas
37
Forks
52
Merge medio
1 d 47 min
PR fusionados (30 d)
10

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de databricks/databricks-sql-nodejs

Todos los issues de databricks/databricks-sql-nodejs

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.