Repository navigation
auth: add OIDC token auth - #1820
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. WalkthroughThis change adds OpenID Connect token configuration and authentication over driver-managed TLS. It checks server capabilities, rejects authentication switches, redacts tokens from server error messages, and adds tests and README guidance for configuration and token refresh. ChangesOpenID Connect authentication
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant Config
participant ConnectorConnect
participant MySQLServer
participant openIDConnectAuthPlugin
Config->>ConnectorConnect: Provide OIDC token
MySQLServer->>ConnectorConnect: Send greeting and capabilities
ConnectorConnect->>openIDConnectAuthPlugin: Initialize with token and TLS context
openIDConnectAuthPlugin->>ConnectorConnect: Return length-encoded token
ConnectorConnect->>MySQLServer: Send authentication response
Merge Risk: ⚪ Minimal · up to This change adds OIDC token authentication guarded by TLS and server-capability checks. No concrete merge-blocking risk was identified in the supplied context. The author has not reported test results, so normal CI should still run before merge. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to OIDC authentication is explicitly enabled and prevents plaintext fallback, server-selected authentication switches, and direct token echoes in authentication errors. Server identity verification and token refresh remain application responsibilities. No concrete bypass was established in the inspected flow, but production verification policies and token permissions were not available. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
thanks for picking this up. one question I'm not sure about though: why can't the token be supplied through the DSN when the password can? Without a DSN path, anything that reaches the driver through |
|
I think issuing a JWT in BeforeConnect is a reasonable design.
|
Description
This pull request adds OpenID Connect (OIDC) authentication support to the MySQL driver for Go, allowing applications to authenticate using OIDC tokens. It introduces a new configuration option, enforces proper TLS usage, and updates error handling to ensure security and clarity when using OIDC. The README is updated with documentation and usage examples.
OpenID Connect (OIDC) Authentication:
OIDCTokenoption in theConfigstruct and a newopenIDConnectAuthPluginfor handling OIDC tokens. [1] [2] [3]ErrOpenIDConnectTLSandErrOpenIDConnectToken. [1] [2]Connection and Authentication Flow:
Security Improvements:
Documentation:
README.mdwith a new section explaining OIDC authentication, including usage examples and security notes. [1] [2]Constants and Imports:
Checklist