[coverage] Conformance findings: AUTH-017
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 55/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- node.js, typescript
調査の方向性
Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.
索引モデルが issue の本文から書いたものです。
説明
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift](see the coverage PR diff undertests/)
- failing test:
- AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea](see the coverage PR diff undertests/)
- failing test:
- AUTH-017: OAuth client-secret M2M ignores the configured
scopeconnection option and always sendsscope=all-apison the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate
Reproduce & Expected
AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…
Reproduce:
SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user
Expected (per the shared spec):
- completes without an exception
- result has exactly 1 row(s)
- completes without an exception
- result has exactly 1 row(s)
- full assertion contract:
result:
- label: m2m_multi_scope
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- sql
- offline_access
exactly: true
- label: m2m_multi_scope
no_exception: true
- label: m2m_multi_scope
row_count: 1
- label: m2m_blank_default
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- all-apis
exactly: true
- label: m2m_blank_default
no_exception: true
- label: m2m_blank_default
row_count: 1
- label: jwt_blank_omits
oauth_token_request_scope:
grant_type: client_credentials
present: false
- label: u2m_blank_default
oauth_token_request_scope:
scopes:
- sql
- offline_access
exactly: true
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-jdbc/pull/1707 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1742
- 主要言語
- TypeScript
- スター
- 37
- フォーク
- 52
- 平均マージ
- 1日 47分
- マージ済み PR(30日)
- 10
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
databricks/databricks-sql-nodejs のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
databricks/databricks-sql-nodejs#541 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
databricks/databricks-sql-nodejs#526 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
databricks/databricks-sql-nodejs#503 ·
メンテナーはふだん 1 日以内に返信
-
engineer-bot
難易度 2/5 1〜3時間 初心者へのやさしさ 64/100
databricks/databricks-sql-nodejs#274 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
databricks/databricks-sql-nodejs#539 ·
メンテナーはふだん 1 日以内に返信
databricks/databricks-sql-nodejs の issue をすべて見る
似ている issue
-
refactor
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
tomnewport/memprot-topo#55 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
WalletConnect/walletconnect-monorepo#7368 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
BU-Spark/se-chem-apll#47 ·
-
embed: handleTurboSignMessage header comment says the signing page posts to '*' (it never does)オープンdocumentation
難易度 2/5 1時間未満 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 半日 初心者へのやさしさ 70/100
udistrital/paginaweb_root#23 ·