ActiveDirectoryServicePrincipalAccessToken: password/token not propagated to driver
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 静か
- 技術スタック
- azure, go
- 領域
- authentication, cli, security
調査の方向性
pkg/sqlcmd/connect.go のパスワード伝播ブランチから始め、そこに列挙されている認証方式と ActiveDirectoryServicePrincipalAccessToken を比較します。issue にある SQLCMDPASSWORD コマンドで再現し、その後トークンがドライバーに到達することを確認し、他の azuread メソッドにも同じ欠落がないか監査します。
索引モデルが issue の本文から書いたものです。
説明
sqlcmd advertises ActiveDirectoryServicePrincipalAccessToken via --authentication-method (see the help string in cmd/sqlcmd/sqlcmd.go around line 454), but the method does not actually work end-to-end.
Root cause
The go-mssqldb azuread connector for this method expects the pre-obtained bearer token to arrive in the connection string as the password. sqlcmd's pkg/sqlcmd/connect.go only attaches url.UserPassword(UserName, Password) to the URL for a specific set of methods (SqlPassword, ActiveDirectoryPassword, ActiveDirectoryServicePrincipal, ActiveDirectoryApplication, ActiveDirectoryClientAssertion). ActiveDirectoryServicePrincipalAccessToken is not in that list, so the value of -P / SQLCMDPASSWORD is silently dropped and the driver receives no token.
Repro
SQLCMDPASSWORD=<a valid AAD access token> sqlcmd -S <server> --authentication-method ActiveDirectoryServicePrincipalAccessToken -U <ignored>
Driver fails because no token was passed.
Suggested fix
Add ActiveDirectoryServicePrincipalAccessToken (and audit other azuread methods for the same gap) to the password-propagation branch in pkg/sqlcmd/connect.go.
Context
Surfaced in #639 while updating README docs to enumerate the supported --authentication-method values.
- 主要言語
- Go
- スター
- 601
- フォーク
- 91
- 平均マージ
- 9時間 35分
- マージ済み PR(30日)
- 1
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートなし
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/go-sqlcmd のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
microsoft/go-sqlcmd#733 · コメント 7 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
メンテナーはふだん 1 日以内に返信
-
-r discards the "Msg N, Level N, State N" error header — errors on stderr lose message number and line info再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
Go + tab is not understood.再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
メンテナーはふだん 1 日以内に返信
microsoft/go-sqlcmd の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
modelcontextprotocol/go-sdk#1340 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
MHSanaei/3x-ui#6731 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
seccomp: goToNative values for loong64 and mipsle have no matching nativeToSeccomp key対応中かも @ricardobranco777 が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
native-convergence self-host
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
JakeChampion/lang#11408 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
open-telemetry/opentelemetry-go-compile-instrumentation#1445 ·
メンテナーはふだん 2 日以内に返信