Token federation: `_exchange_token` raises KeyError('access_token') on error responses, discarding the real failure reason
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 76/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Pouca atividade
- Stack de tecnologia
- python
- Domínio
- authentication
Direção de pesquisa
Comece em src/databricks/sql/auth/token_federation.py, em _exchange_token por volta das linhas 191-194; depois, acompanhe o handler por volta da linha 148 e o ponto de entrada que o envolve em src/databricks/sql/auth/auth.py:68. Reproduza uma troca que retorne um corpo de erro OAuth e verifique se o aviso expõe o motivo do erro do endpoint sem registrar tokens, enquanto o fallback para o token externo permanece inalterado.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Summary
When token exchange fails, _exchange_token raises KeyError: 'access_token' instead of surfacing the error the endpoint actually returned. The caller catches it and logs the KeyError, so the log line reports the name of a missing dict key rather than why the exchange was rejected:
Token exchange failed, using external token: 'access_token'
There is no way to tell from that whether the exchange was misconfigured, unauthorized, or unsupported.
Versions
Reproduced on databricks-sql-connector==4.3.0. The relevant code is byte-identical in v4.4.0 and on main today, so this is not fixed in a later release.
Where
src/databricks/sql/auth/token_federation.py on main:
191: token_response = json.loads(response.data.decode())
192:
193: return Token(
194: token_response["access_token"], token_response.get("token_type", "Bearer")
195: )
token_type is read defensively with .get(); access_token is not. When the endpoint returns an OAuth error body ({"error": ..., "error_description": ...}) rather than a token, line 194 raises KeyError.
That propagates to the handler at line 148:
147: except Exception as e:
148: logger.warning("Token exchange failed, using external token: %s", e)
str(KeyError("access_token")) renders as 'access_token', which is what reaches the log. The error and error_description from the response body are never read and are lost.
Reproduction
- Connect using an OAuth access token issued by an identity provider whose
isshost differs from the workspace host — for example an Microsoft Entra ID token for the Azure Databricks resource (2ff814a6-3304-4ab8-85cb-cd0e6f879c1d). TokenFederationProviderwraps every provider unconditionally (src/databricks/sql/auth/auth.py:68, "Always wrap with token federation"), and_should_exchange_tokenreturnsTruebecause the issuer host does not match the workspace host, so an exchange is always attempted.- Against a workspace where that exchange is not accepted, every connection logs the message above.
Functionally this is harmless — the fallback to the external token works correctly and queries succeed. The problem is purely diagnostic: the warning fires on every connection and gives no actionable information.
Suggested fix
Read the response defensively and raise something that names the actual failure, without logging the token itself:
token_response = json.loads(response.data.decode())
if "access_token" not in token_response:
error = token_response.get("error", "unknown_error")
description = token_response.get("error_description", "")
raise RuntimeError(f"Token exchange rejected by {token_url}: {error} {description}".strip())
return Token(token_response["access_token"], token_response.get("token_type", "Bearer"))
The existing except Exception at line 147 would then log the endpoint's own reason, and the graceful fallback behaviour is unchanged.
A non-JSON or non-2xx response would also currently surface as a confusing JSONDecodeError; checking the status code before parsing would cover that case too.
- Linguagem predominante
- Python
- Estrelas
- 233
- Forks
- 152
- Merge médio
- 21h 5min
- PRs com merge (30d)
- 10
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de databricks/databricks-sql-python
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
-
engineer-bot
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
databricks/databricks-sql-python#860 · 3 comentários ·
Todas as issues de databricks/databricks-sql-python
Issues semelhantes
-
fix: inaccuracy ⚠️
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
uabrc/uabrc.github.io#1255 · 1 comentário ·
-
docs
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 85/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
ethereum-optimism/factory#64 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 90/100
duckdb/duckdb-python#627 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100