Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

[coverage] Conformance findings: AUTH-017

Aberta
#540 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
3/5
Tempo estimado
1-2 dias
Facilidade para iniciantes
55/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
node.js, typescript

Direção de pesquisa

Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.

Findings

  • AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift] (see the coverage PR diff under tests/)
  • AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured scope option and always sends scope=all-apis on the client_credentials token request, so a scoped service-principal secret cannot authenticate
    • failing test: AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea] (see the coverage PR diff under tests/)
  • AUTH-017: OAuth client-secret M2M ignores the configured scope connection option and always sends scope=all-apis on the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate

Reproduce & Expected

AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…

Reproduce:

SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user

Expected (per the shared spec):

  • completes without an exception
  • result has exactly 1 row(s)
  • completes without an exception
  • result has exactly 1 row(s)
  • full assertion contract:
result:
- label: m2m_multi_scope
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - sql
    - offline_access
    exactly: true
- label: m2m_multi_scope
  no_exception: true
- label: m2m_multi_scope
  row_count: 1
- label: m2m_blank_default
  oauth_token_request_scope:
    grant_type: client_credentials
    scopes:
    - all-apis
    exactly: true
- label: m2m_blank_default
  no_exception: true
- label: m2m_blank_default
  row_count: 1
- label: jwt_blank_omits
  oauth_token_request_scope:
    grant_type: client_credentials
    present: false
- label: u2m_blank_default
  oauth_token_request_scope:
    scopes:
    - sql
    - offline_access
    exactly: true

Context

Linguagem predominante
TypeScript
Estrelas
37
Forks
52
Merge médio
1d 47min
PRs com merge (30d)
10

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de databricks/databricks-sql-nodejs

Todas as issues de databricks/databricks-sql-nodejs

Issues semelhantes

Mais issues de TypeScript

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.