[coverage] Conformance findings: AUTH-013
還沒有人認領這個 Issue。
評估
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 新手友好度
- 64/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 活躍
- 技術堆疊
- python
研究方向
從 auth.py 和 coverage PR 中失敗的測試 test_oauth_u2m_explicit_bundle_override 開始。在不完成登入的情況下,重現這兩種情況,同時觀察授權 URL 和 callback listener。符合以下條件即表示完成:保留提供的 client_id,完整 override 使用連接埠 8099 和 scope all-apis,而 client_id-only 回退到連接埠 8030,且不設定應用程式專用的 scope 固定項。
由索引模型根據 Issue 內容生成。
描述
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-python. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-python) is fixed, then flips green as a tripwire.
Findings
- AUTH-013 [thrift]: U2M partial override: a caller-supplied oauth_client_id without oauth_redirect_port still gets the connector's own default app port 8020 (auth.py honours oauth_redirect_port only when paired with oauth_client_id, else falls back to PYSQL_OAUTH_REDIRECT_PORT_RANGE), so the foreign app's browser redirect fails with redirect_uri_mismatch (PECOBLR-4039)
- failing test:
test_oauth_u2m_explicit_bundle_override(see the coverage PR diff undertests/)
- failing test:
Reproduce & Expected
AUTH-013 — Verifies that a caller-supplied U2M OAuth identity is honoured verbatim, and that a caller who supplies their OWN client_id also OWNS the rest of the bundle - the driver must NOT pin its own default…
Reproduce:
- Case 1 - begin a U2M connect supplying client_id
test-custom-u2m-app,
scopes["all-apis"]and redirect_port 8099; capture the resolved bundle at the
same observation point AUTH-012 uses (authorization URL / callback listener /
proxied request). The interactive login is not completed. - Case 2 - repeat supplying ONLY client_id
test-custom-u2m-app, leaving scopes
and redirect_port unset.
Expected (per the shared spec):
- The supplied client_id is sent unchanged - no default substitution, in both cases.
{'oauth_u2m_override_scopes_verbatim': {'values': ['all-apis'], 'description': "Case 1: the caller's scope set is forwarded verbatim, even when it differs from\nthe driver's defaultsql offline_access.\n"}}- Case 1: the localhost callback / redirect URI uses the caller's port 8099, not any driver default.
- Case 2 (client_id only): the driver does NOT apply its own default app's app-specific pins. Concretely, a driver whose DEFAULT bundle uses
databricks-sql-python+ port 8020 must NOT redirect to 8020 here - with a foreign client_id the unsupplied port falls through to the base kernel default (8030). Likewise the scope set is not pinned to that binding's app-specific list.
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-sql-kernel/pull/247 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-python; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1285
- 主要語言
- Python
- 星號
- 233
- 分支
- 152
- 平均合併
- 21 小時 5 分鐘
- 30 天內合併 PR
- 10
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
databricks/databricks-sql-python 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 76/100
-
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 72/100
-
難度 2/5 1-3 小時 新手友好度 84/100
查看 databricks/databricks-sql-python 的全部 Issue
相似的 Issue
-
enhancement
難度 2/5 1-3 小時 新手友好度 70/100
canonical/paas-charm#368 · 1 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
-
tech debt
難度 2/5 1-3 小時 新手友好度 75/100
-
難度 1/5 1 小時以內 新手友好度 90/100
StevenBlack/hosts#3256 ·
-
難度 1/5 1 小時以內 新手友好度 90/100
qualcomm/qai-appbuilder#275 ·