[coverage] Conformance findings: AUTH-017
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- node.js, typescript
- Área
- authentication, backend
Línea de trabajo
Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift](see the coverage PR diff undertests/)
- failing test:
- AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea](see the coverage PR diff undertests/)
- failing test:
- AUTH-017: OAuth client-secret M2M ignores the configured
scopeconnection option and always sendsscope=all-apison the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate
Reproduce & Expected
AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…
Reproduce:
SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user
Expected (per the shared spec):
- completes without an exception
- result has exactly 1 row(s)
- completes without an exception
- result has exactly 1 row(s)
- full assertion contract:
result:
- label: m2m_multi_scope
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- sql
- offline_access
exactly: true
- label: m2m_multi_scope
no_exception: true
- label: m2m_multi_scope
row_count: 1
- label: m2m_blank_default
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- all-apis
exactly: true
- label: m2m_blank_default
no_exception: true
- label: m2m_blank_default
row_count: 1
- label: jwt_blank_omits
oauth_token_request_scope:
grant_type: client_credentials
present: false
- label: u2m_blank_default
oauth_token_request_scope:
scopes:
- sql
- offline_access
exactly: true
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-jdbc/pull/1707 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1742
- Lenguaje dominante
- TypeScript
- Estrellas
- 37
- Forks
- 52
- Merge medio
- 1 d 47 min
- PR fusionados (30 d)
- 10
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de databricks/databricks-sql-nodejs
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
databricks/databricks-sql-nodejs#541 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
databricks/databricks-sql-nodejs#526 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
databricks/databricks-sql-nodejs#503 ·
Los mantenedores suelen responder en 1 día
-
Docs folder deleted in 1.8.4Abiertoengineer-bot
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
databricks/databricks-sql-nodejs#274 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
databricks/databricks-sql-nodejs#539 ·
Los mantenedores suelen responder en 1 día
Todos los issues de databricks/databricks-sql-nodejs
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
rajbos/ai-engineering-fluency#2340 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
community documentation first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 70/100
lingdojo/kana-dojo#31864 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
zenstackhq/zenstack#2873 ·
Los mantenedores suelen responder en 1 día
-
CLI: TUI shows onboarding when the provider's API key is only in the environment (e.g. OPENROUTER_API_KEY)Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. AbiertoCLI
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
cline/cline#14923 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
paperclipai/paperclip#15490 ·
Los mantenedores suelen responder en 1 día