[coverage] Conformance findings: AUTH-017
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Facilidade para iniciantes
- 55/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- node.js, typescript
- Domínio
- authentication, backend
Direção de pesquisa
Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift](see the coverage PR diff undertests/)
- failing test:
- AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea](see the coverage PR diff undertests/)
- failing test:
- AUTH-017: OAuth client-secret M2M ignores the configured
scopeconnection option and always sendsscope=all-apison the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate
Reproduce & Expected
AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…
Reproduce:
SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user
Expected (per the shared spec):
- completes without an exception
- result has exactly 1 row(s)
- completes without an exception
- result has exactly 1 row(s)
- full assertion contract:
result:
- label: m2m_multi_scope
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- sql
- offline_access
exactly: true
- label: m2m_multi_scope
no_exception: true
- label: m2m_multi_scope
row_count: 1
- label: m2m_blank_default
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- all-apis
exactly: true
- label: m2m_blank_default
no_exception: true
- label: m2m_blank_default
row_count: 1
- label: jwt_blank_omits
oauth_token_request_scope:
grant_type: client_credentials
present: false
- label: u2m_blank_default
oauth_token_request_scope:
scopes:
- sql
- offline_access
exactly: true
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-jdbc/pull/1707 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1742
- Linguagem predominante
- TypeScript
- Estrelas
- 37
- Forks
- 52
- Merge médio
- 1d 47min
- PRs com merge (30d)
- 10
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de databricks/databricks-sql-nodejs
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
databricks/databricks-sql-nodejs#541 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
databricks/databricks-sql-nodejs#526 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
databricks/databricks-sql-nodejs#503 ·
Mantenedores costumam responder em até 1 dia
-
Docs folder deleted in 1.8.4Abertaengineer-bot
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 64/100
databricks/databricks-sql-nodejs#274 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 55/100
databricks/databricks-sql-nodejs#539 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de databricks/databricks-sql-nodejs
Issues semelhantes
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
yjh051108/dsh-routing-suite#216 ·
-
kind/bug priority/needs-triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia
-
Dependencies view: `getParent` loops forever on untitled documents, extension host runs out of memoryTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Abertabug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Mantenedores costumam responder em até 1 dia
-
enhancement good first issue
Dificuldade 2/5 Meio dia Facilidade para iniciantes 66/100
apache/fineract-consumer-facing#175 ·
Mantenedores costumam responder em até 1 dia
-
bug
Dificuldade 2/5 Menos de uma hora Facilidade para iniciantes 82/100
awslabs/visual-asset-management-system#413 ·
Mantenedores costumam responder em até 1 dia