[coverage] Conformance findings: AUTH-017
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 55/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- node.js, typescript
调研方向
Start by reading the AUTH-017 expected-failure tests in the coverage PR diff under tests/ and the reference JDBC PR for the intended behavior. Trace the OAuth client-secret M2M token-request paths for both Thrift and SEA/kernel in this driver. Done means configured space-separated scopes reach both token requests as the exact scope set, while blank values retain the specified defaults.
由索引模型根据 Issue 内容生成。
描述
Summary
Surfaced by the multi-language coverage fan-out while conformance-testing these SPEC-IDs against databricks/databricks-sql-nodejs. Each finding is committed as an expected-failure (xfail) test in the coverage PR — the test asserts the CORRECT (post-fix) behavior and stays red until THIS driver (databricks/databricks-sql-nodejs) is fixed, then flips green as a tripwire.
Findings
- AUTH-017 [thrift]: OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [thrift](see the coverage PR diff undertests/)
- failing test:
- AUTH-017 [sea]: SEA/kernel OAuth client-secret M2M ignores the configured
scopeoption and always sendsscope=all-apison the client_credentials token request, so a scoped service-principal secret cannot authenticate- failing test:
AUTH-017 — configured multi-scope value reaches the client_credentials token request as that exact scope set [sea](see the coverage PR diff undertests/)
- failing test:
- AUTH-017: OAuth client-secret M2M ignores the configured
scopeconnection option and always sendsscope=all-apison the client_credentials token request (both Thrift and SEA/kernel), so a scoped service-principal secret cannot authenticate
Reproduce & Expected
AUTH-017 — Verifies that the configured OAuth scope property is honored on the OAuth client-secret machine-to-machine (M2M) flow: ONE property value holding space-separated scopes is parsed into the scope set t…
Reproduce:
SELECT CURRENT_USER() AS user
SELECT CURRENT_USER() AS user
Expected (per the shared spec):
- completes without an exception
- result has exactly 1 row(s)
- completes without an exception
- result has exactly 1 row(s)
- full assertion contract:
result:
- label: m2m_multi_scope
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- sql
- offline_access
exactly: true
- label: m2m_multi_scope
no_exception: true
- label: m2m_multi_scope
row_count: 1
- label: m2m_blank_default
oauth_token_request_scope:
grant_type: client_credentials
scopes:
- all-apis
exactly: true
- label: m2m_blank_default
no_exception: true
- label: m2m_blank_default
row_count: 1
- label: jwt_blank_omits
oauth_token_request_scope:
grant_type: client_credentials
present: false
- label: u2m_blank_default
oauth_token_request_scope:
scopes:
- sql
- offline_access
exactly: true
Context
- The behavior was first fixed in a DIFFERENT driver — reference PR: https://github.com/databricks/databricks-jdbc/pull/1707 — which seeded the shared language-neutral spec. This issue tracks the same conformance gap in databricks/databricks-sql-nodejs; the reference PR is for cross-referencing the intended behavior, NOT a change to this repo.
- Coverage PR carrying the reproducing xfail test(s): https://github.com/databricks/databricks-driver-test/pull/1742
- 主要语言
- TypeScript
- 星标
- 37
- 派生
- 52
- 平均合并
- 1 天 47 分钟
- 30 天内合并 PR
- 10
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
databricks/databricks-sql-nodejs 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 74/100
databricks/databricks-sql-nodejs#541 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
databricks/databricks-sql-nodejs#526 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
databricks/databricks-sql-nodejs#503 ·
维护者通常 1 天内回复
-
engineer-bot
难度 2/5 1-3 小时 新手友好度 64/100
databricks/databricks-sql-nodejs#274 · 1 条评论 · 1 个 reaction ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
databricks/databricks-sql-nodejs#539 ·
维护者通常 1 天内回复
查看 databricks/databricks-sql-nodejs 的全部 Issue
相似的 Issue
-
bug priority:low ready-for-dev
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
Automattic/data-liberation-agent#685 ·
维护者通常 1 天内回复
-
Business
难度 2/5 1-3 小时 新手友好度 66/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 83/100
txn2/mcp-data-platform#2063 ·
维护者通常 1 天内回复
-
bug
难度 1/5 1 小时以内 新手友好度 77/100
Crosstalk-Solutions/project-nomad#1427 ·
维护者通常 2 天内回复