Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[coverage] Conformance findings: AUTH-017

オープン
#540 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
55/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
node.js, typescript

調査の方向性

Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.

索引モデルが issue の本文から書いたものです。

説明

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.

Findings

  • AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift] (see the coverage PR diff under tests/)
  • AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea] (see the coverage PR diff under tests/)
  • AUTH-017: OAuth client-secret M2M ignores the configured scope connection option and always sends scope=all-apis on the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate

Reproduce & Expected

AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…

Reproduce:

SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user

Expected (per the shared spec):

  • completes without an exception
  • result has exactly 1 row(s)
  • completes without an exception
  • result has exactly 1 row(s)
  • full assertion contract:
result:
- label: m2m_multi_scope
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - sql
    - offline_access
    exactly: true
- label: m2m_multi_scope
  no_exception: true
- label: m2m_multi_scope
  row_count: 1
- label: m2m_blank_default
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - all-apis
    exactly: true
- label: m2m_blank_default
  no_exception: true
- label: m2m_blank_default
  row_count: 1
- label: jwt_blank_omits
  oauth_token_request_scope:
    grant_type: client_credentials
    present: false
- label: u2m_blank_default
  oauth_token_request_scope:
    scopes:
    - sql
    - offline_access
    exactly: true

Context

主要言語
TypeScript
スター
37
フォーク
52
平均マージ
1日 47分
マージ済み PR(30日)
10

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

databricks/databricks-sql-nodejs のほかの issue

databricks/databricks-sql-nodejs の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。