Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

[coverage] Conformance findings: AUTH-013

未關閉
#909 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
3/5
預估耗時
1-2 天
新手友好度
64/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
python

研究方向

從 auth.py 和 coverage PR 中失敗的測試 test_oauth_u2m_explicit_bundle_override 開始。在不完成登入的情況下,重現這兩種情況,同時觀察授權 URL 和 callback listener。符合以下條件即表示完成:保留提供的 client_id,完整 override 使用連接埠 8099 和 scope all-apis,而 client_id-only 回退到連接埠 8030,且不設定應用程式專用的 scope 固定項。

由索引模型根據 Issue 內容生成。

描述

engineer-bot

Summary

Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.

Findings

  • AUTH-013 [thrift]: U2M partial override: a caller-supplied oauth_client_id without oauth_redirect_port still gets the connector's own default app port 8020 (auth.py honours oauth_redirect_port only when paired with oauth_client_id, else falls back to PYSQL_OAUTH_REDIRECT_PORT_RANGE), so the foreign app's browser redirect fails with redirect_uri_mismatch (PECOBLR-4039)
    • failing test: test_oauth_u2m_explicit_bundle_override (see the coverage PR diff under tests/)

Reproduce & Expected

AUTH-013 — Verifies that a caller-supplied U2M OAuth identity is honoured verbatim, and that a caller who supplies their OWN client_id also OWNS the rest of the bundle - the driver must NOT pin its own default…

Reproduce:

  • Case 1 - begin a U2M connect supplying client_id test-custom-u2m-app,
    scopes ["all-apis"] and redirect_port 8099; capture the resolved bundle at the
    same observation point AUTH-012 uses (authorization URL / callback listener /
    proxied request). The interactive login is not completed.
  • Case 2 - repeat supplying ONLY client_id test-custom-u2m-app, leaving scopes
    and redirect_port unset.

Expected (per the shared spec):

  • The supplied client_id is sent unchanged - no default substitution, in both cases.
  • {'oauth_u2m_override_scopes_verbatim': {'values': ['all-apis'], 'description': "Case 1: the caller's scope set is forwarded verbatim, even when it differs from\nthe driver's default sql offline_access.\n"}}
  • Case 1: the localhost callback / redirect URI uses the caller's port 8099, not any driver default.
  • Case 2 (client_id only): the driver does NOT apply its own default app's app-specific pins. Concretely, a driver whose DEFAULT bundle uses databricks-sql-python + port 8020 must NOT redirect to 8020 here - with a foreign client_id the unsupplied port falls through to the base kernel default (8030). Likewise the scope set is not pinned to that binding's app-specific list.

Context

主要語言
Python
星號
233
分支
152
平均合併
21 小時 5 分鐘
30 天內合併 PR
10

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

databricks/databricks-sql-python 的其他 Issue

查看 databricks/databricks-sql-python 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。