ActiveDirectoryServicePrincipalAccessToken: password/token not propagated to driver
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 冷清
- 技术栈
- azure, go
- 领域
- authentication, cli, security
调研方向
从 pkg/sqlcmd/connect.go 中的密码传递分支开始,将其中列出的身份验证方法与 ActiveDirectoryServicePrincipalAccessToken 进行比较。使用 issue 中的 SQLCMDPASSWORD 命令复现,然后验证 token 是否到达 driver,并审查其他 azuread 方法是否存在同样的缺失。
由索引模型根据 Issue 内容生成。
描述
sqlcmd advertises ActiveDirectoryServicePrincipalAccessToken via --authentication-method (see the help string in cmd/sqlcmd/sqlcmd.go around line 454), but the method does not actually work end-to-end.
Root cause
The go-mssqldb azuread connector for this method expects the pre-obtained bearer token to arrive in the connection string as the password. sqlcmd's pkg/sqlcmd/connect.go only attaches url.UserPassword(UserName, Password) to the URL for a specific set of methods (SqlPassword, ActiveDirectoryPassword, ActiveDirectoryServicePrincipal, ActiveDirectoryApplication, ActiveDirectoryClientAssertion). ActiveDirectoryServicePrincipalAccessToken is not in that list, so the value of -P / SQLCMDPASSWORD is silently dropped and the driver receives no token.
Repro
SQLCMDPASSWORD=<a valid AAD access token> sqlcmd -S <server> --authentication-method ActiveDirectoryServicePrincipalAccessToken -U <ignored>
Driver fails because no token was passed.
Suggested fix
Add ActiveDirectoryServicePrincipalAccessToken (and audit other azuread methods for the same gap) to the password-propagation branch in pkg/sqlcmd/connect.go.
Context
Surfaced in #639 while updating README docs to enumerate the supported --authentication-method values.
- 主要语言
- Go
- 星标
- 601
- 派生
- 91
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/go-sqlcmd 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
-
难度 3/5 1-2 天 新手友好度 55/100
-
难度 3/5 1-2 天 新手友好度 65/100
-
-r discards the "Msg N, Level N, State N" error header — errors on stderr lose message number and line info可能重新可做 关联的 PR 已关闭且未合并。 未关闭
难度 3/5 1-2 天 新手友好度 76/100
-
Go + tab is not understood.可能重新可做 关联的 PR 已关闭且未合并。 未关闭
难度 3/5 1-2 天 新手友好度 58/100
查看 microsoft/go-sqlcmd 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
维护者通常 3 天内回复
-
Python 3.15 support可能已有人在做 @amnesiaof 今天认领。 未关闭L: python L: python:uv
难度 2/5 1-3 小时 新手友好度 72/100
dependabot/dependabot-core#16524 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
duplication
难度 2/5 1-3 小时 新手友好度 78/100
openvibely/openvibely#1443 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 60/100
canonical/service-mesh#845 ·
维护者通常 1 天内回复