[coverage] Conformance findings: AUTH-017
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- node.js, typescript
- Lĩnh vực
- authentication, backend
Hướng nghiên cứu
Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift](see the coverage PR diff undertests/)
- failing test:
- AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea](see the coverage PR diff undertests/)
- failing test:
- AUTH-017: OAuth client-secret M2M ignores the configured
scopeconnection option and always sendsscope=all-apison the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate
Reproduce & Expected
AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…
Reproduce:
SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user
Expected (per the shared spec):
- completes without an exception
- result has exactly 1 row(s)
- completes without an exception
- result has exactly 1 row(s)
- full assertion contract:
result:
- label: m2m_multi_scope
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- sql
- offline_access
exactly: true
- label: m2m_multi_scope
no_exception: true
- label: m2m_multi_scope
row_count: 1
- label: m2m_blank_default
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- all-apis
exactly: true
- label: m2m_blank_default
no_exception: true
- label: m2m_blank_default
row_count: 1
- label: jwt_blank_omits
oauth_token_request_scope:
grant_type: client_credentials
present: false
- label: u2m_blank_default
oauth_token_request_scope:
scopes:
- sql
- offline_access
exactly: true
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-jdbc/pull/1707 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1742
- Ngôn ngữ chính
- TypeScript
- Star
- 37
- Fork
- 52
- Merge trung bình
- 1 ngày 47 phút
- Pull request đã merge (30 ngày)
- 10
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của databricks/databricks-sql-nodejs
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
databricks/databricks-sql-nodejs#541 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
databricks/databricks-sql-nodejs#526 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
databricks/databricks-sql-nodejs#503 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Docs folder deleted in 1.8.4Đang mởengineer-bot
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
databricks/databricks-sql-nodejs#274 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 55/100
databricks/databricks-sql-nodejs#539 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của databricks/databricks-sql-nodejs
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
rajbos/ai-engineering-fluency#2340 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
community documentation first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 70/100
lingdojo/kana-dojo#31864 · 1 bình luận · 5 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
zenstackhq/zenstack#2873 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
CLI: TUI shows onboarding when the provider's API key is only in the environment (e.g. OPENROUTER_API_KEY)Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởCLI
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 67/100
cline/cline#14923 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
paperclipai/paperclip#15490 ·
Maintainer thường phản hồi trong vòng 1 ngày