Token federation: `_exchange_token` raises KeyError('access_token') on error responses, discarding the real failure reason
還沒有人認領這個 Issue。
評估
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 新手友好度
- 76/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 冷清
- 技術堆疊
- python
研究方向
從 src/databricks/sql/auth/token_federation.py 中 191-194 行附近的 _exchange_token 開始,接著追蹤 148 行附近的 handler,以及 src/databricks/sql/auth/auth.py:68 中包裝它的進入點。重現一個回傳 OAuth 錯誤本文的 exchange,並確認 warning 會揭露 endpoint 的錯誤原因,同時不記錄 token,而回退至外部 token 的行為維持不變。
由索引模型根據 Issue 內容生成。
描述
Summary
When token exchange fails, _exchange_token raises KeyError: 'access_token' instead of surfacing the error the endpoint actually returned. The caller catches it and logs the KeyError, so the log line reports the name of a missing dict key rather than why the exchange was rejected:
Token exchange failed, using external token: 'access_token'
There is no way to tell from that whether the exchange was misconfigured, unauthorized, or unsupported.
Versions
Reproduced on databricks-sql-connector==4.3.0. The relevant code is byte-identical in v4.4.0 and on main today, so this is not fixed in a later release.
Where
src/databricks/sql/auth/token_federation.py on main:
191: token_response = json.loads(response.data.decode())
192:
193: return Token(
194: token_response["access_token"], token_response.get("token_type", "Bearer")
195: )
token_type is read defensively with .get(); access_token is not. When the endpoint returns an OAuth error body ({"error": ..., "error_description": ...}) rather than a token, line 194 raises KeyError.
That propagates to the handler at line 148:
147: except Exception as e:
148: logger.warning("Token exchange failed, using external token: %s", e)
str(KeyError("access_token")) renders as 'access_token', which is what reaches the log. The error and error_description from the response body are never read and are lost.
Reproduction
- Connect using an OAuth access token issued by an identity provider whose
isshost differs from the workspace host — for example an Microsoft Entra ID token for the Azure Databricks resource (2ff814a6-3304-4ab8-85cb-cd0e6f879c1d). TokenFederationProviderwraps every provider unconditionally (src/databricks/sql/auth/auth.py:68, "Always wrap with token federation"), and_should_exchange_tokenreturnsTruebecause the issuer host does not match the workspace host, so an exchange is always attempted.- Against a workspace where that exchange is not accepted, every connection logs the message above.
Functionally this is harmless — the fallback to the external token works correctly and queries succeed. The problem is purely diagnostic: the warning fires on every connection and gives no actionable information.
Suggested fix
Read the response defensively and raise something that names the actual failure, without logging the token itself:
token_response = json.loads(response.data.decode())
if "access_token" not in token_response:
error = token_response.get("error", "unknown_error")
description = token_response.get("error_description", "")
raise RuntimeError(f"Token exchange rejected by {token_url}: {error} {description}".strip())
return Token(token_response["access_token"], token_response.get("token_type", "Bearer"))
The existing except Exception at line 147 would then log the endpoint's own reason, and the graceful fallback behaviour is unchanged.
A non-JSON or non-2xx response would also currently surface as a confusing JSONDecodeError; checking the status code before parsing would cover that case too.
- 主要語言
- Python
- 星號
- 233
- 分支
- 152
- 平均合併
- 21 小時 5 分鐘
- 30 天內合併 PR
- 10
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
databricks/databricks-sql-python 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 72/100
-
難度 2/5 1-3 小時 新手友好度 84/100
-
engineer-bot
難度 2/5 1-3 小時 新手友好度 76/100
databricks/databricks-sql-python#860 · 3 則留言 ·
查看 databricks/databricks-sql-python 的全部 Issue
相似的 Issue
-
bug confirmed issue
難度 2/5 1-3 小時 新手友好度 75/100
open-webui/open-webui#30750 · 1 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
-
enhancement
難度 2/5 1-3 小時 新手友好度 75/100
OpenwaterHealth/openmotion-bloodflow-app#604 · 1 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 70/100
-
good first issue
難度 1/5 1 小時以內 新手友好度 90/100