You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e1764fe
Browse filesBrowse the repository at this point in the historyBrowse files
Reject credentials_provider with oauth_client_secret; document M2M options
- credentials_provider together with oauth_client_secret now raises
ValueError instead of silently using the provider, matching the kernel
auth bridge. azure-sp-m2m keeps ignoring oauth_* values.
- The missing-oauth_client_id check no longer fires for azure-sp-m2m.
- oauth_redirect_port is documented as U2M-only; oauth_client_id and
oauth_client_secret docs describe the M2M shape and its exclusions.
- CONNECTION_PARAMETERS.md: oauth_client_secret is supported on Thrift.
- Add changelog entries.
Signed-off-by: Amin Ghadersohi <amin.ghadersohi@gmail.com>
Copy file name to clipboardExpand all lines: CHANGELOG.md
+5Lines changed: 5 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,10 @@
1
1
# Release History
2
2
3
+
# Unreleased
4
+
- Support OAuth M2M (client credentials) for Databricks service principals on the default Thrift backend: `oauth_client_id` + `oauth_client_secret` now authenticate with tokens from the workspace `/oidc/v1/token` endpoint (scope `all-apis`), refreshed as they expire. Previously the secret was ignored and the connection started an interactive browser login.
5
+
- Reject an unsupported `auth_type` with `ValueError` instead of falling back to the interactive browser login, and reject `oauth_client_secret` together with `credentials_provider` or a U2M `auth_type`, as the kernel backend does.
6
+
- Fix: token responses with extra fields (such as `scope`) no longer fail in `ClientCredentialsTokenSource`.
7
+
3
8
# 4.6.0 (2026-09-24)
4
9
- Upgrade Databricks SQL Kernel to 1.1.0; the kernel dependency is now stable and no longer experimental.
5
10
- Transparently auto-recover Thrift connections to Reyden / Real-Time warehouses: when a warehouse rejects the default Thrift protocol (SQLSTATE `KP001`), the session is re-opened on the kernel backend and the warehouse is remembered so later connections skip Thrift. Applies only when no backend was chosen explicitly.
|`access_token` (PAT) |`str`| ✅ | ✅ |`None`| Personal Access Token / bearer token. When no auth signal is supplied, Thrift falls back to Databricks OAuth U2M; Kernel requires an explicit U2M `auth_type` or another supported credential flow. |
86
-
|`auth_type`|`str`| ✅ | ✅ |`None`|`databricks-oauth` (U2M), `azure-oauth` (Azure AD U2M), or `azure-sp-m2m` (Azure service-principal M2M). All three work on both backends. Thrift treats an otherwise credential-less `None` as Databricks OAuth; Kernel does not implicitly select U2M. On Kernel, `azure-oauth` uses the same workspace-federated browser flow as `databricks-oauth`. |
87
-
|`oauth_client_id` (OAuth) |`str`| ✅ | ✅ | built-in id for U2M | Custom U2M client id on both backends. Kernel also uses it with `oauth_client_secret`or the JWT options for M2M; those M2M flows have no built-in client-id default. |
88
-
|`oauth_redirect_port` (U2M) |`int`| ✅ | ✅ |`None`| Localhost redirect port for the browser flow. On **both** backends it is only honored when a custom `oauth_client_id` is also supplied — then that single port becomes the redirect URI. With the built-in client id (or when omitted) the connector uses the full registered range 8020–8024 and binds the first free port, so a bare `oauth_redirect_port` has no effect. (Thrift: `auth.py``oauth_redirect_port_range`; Kernel: same logic, forwarded as `redirect_ports`.) |
89
-
|`oauth_client_secret` (OAuth M2M) |`str`|❌| ✅ |`None`|**Kernel-only in practice.** The Thrift auth path never reads `oauth_client_secret`; use `credentials_provider` or an Azure service principal for M2M on Thrift. |
86
+
|`auth_type`|`str`| ✅ | ✅ |`None`|`databricks-oauth` (U2M), `azure-oauth` (Azure AD U2M), or `azure-sp-m2m` (Azure service-principal M2M). All three work on both backends. Thrift rejects any other value with `ValueError`. Thrift treats an otherwise credential-less `None` as Databricks OAuth; Kernel does not implicitly select U2M. On Kernel, `azure-oauth` uses the same workspace-federated browser flow as `databricks-oauth`. |
87
+
|`oauth_client_id` (OAuth) |`str`| ✅ | ✅ | built-in id for U2M | Custom U2M client id on both backends. Both backends also use it with `oauth_client_secret`for M2M, and Kernel with the JWT options; those M2M flows have no built-in client-id default. |
88
+
|`oauth_redirect_port` (U2M) |`int`| ✅ | ✅ |`None`| Localhost redirect port for the browser (U2M) flow; not used for M2M. On **both** backends it is only honored when a custom `oauth_client_id` is also supplied — then that single port becomes the redirect URI. With the built-in client id (or when omitted) the connector uses the full registered range 8020–8024 and binds the first free port, so a bare `oauth_redirect_port` has no effect. (Thrift: `auth.py``oauth_redirect_port_range`; Kernel: same logic, forwarded as `redirect_ports`.) |
89
+
|`oauth_client_secret` (OAuth M2M) |`str`|✅| ✅ |`None`|With `oauth_client_id`, selects OAuth M2M (client credentials) for a Databricks service principal on both backends. On Thrift the token comes from `https://<host>/oidc/v1/token` with scope `all-apis` and is refreshed as it expires. Rejected together with `credentials_provider` or `auth_type``databricks-oauth`/`azure-oauth`; ignored with `azure-sp-m2m`. |
90
90
|`oauth_jwt_key_file` (OAuth M2M, JWT private key) |`str`| ❌ | ✅ |`None`|**Kernel-only.** Path to the PEM private key for JWT private-key M2M (RFC 7523 client assertion). Supplying it selects the JWT flow: the kernel signs a short-lived assertion with the key instead of sending a client secret. Requires `oauth_client_id` + `oauth_jwt_kid`; mutually exclusive with `oauth_client_secret` / `credentials_provider`. |
91
91
|`oauth_jwt_kid` (OAuth M2M, JWT private key) |`str`| ❌ | ✅ |`None`|**Kernel-only.** Key id written into the JWT header so the IdP can select the registered public key. Required with `oauth_jwt_key_file`. (For Entra ID this is the certificate's `x5t` thumbprint.) |
92
92
|`oauth_jwt_passphrase` (OAuth M2M, JWT private key) |`str`| ❌ | ✅ |`None`|**Kernel-only.** Passphrase for an encrypted PKCS#8 private key; omit for an unencrypted key. |
0 commit comments