feat: Oauth2 contextual session - #3170
Open
DerGut wants to merge 6 commits into
Open
Conversation
Test init catalog session requirement Test session caching by id
Test no caching with 0 TTL
This was referenced Sep 7, 2026
DerGut
marked this pull request as ready for review
September 7, 2026 23:09
Contributor
Author
|
@plusplusjiajia would be great if I could get your eyes on this! 🙏 (the CI failure is unrelated, I'm looking into it) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue does this PR close?
This is based on token expiration from #3160 and the
AuthManager::contextual_sessionfrom #3081. It's adding adding a first implementation for contextual sessions with the OAuth2Manager. It also validates the API introduced by that PR.What changes are included in this PR?
The OAuth2Manager now derives contextual sessions from its catalog session. Contextual sessions are cached by their session ID (that's why the token expiration PR is required to merge first). The catalog session is now expected to be initialized only once.
Effectively, users will be able to use different client credentials per request in a multi-tenant setting that leverages OAuth2.
Are these changes tested?
Yes, added tests.
AI Disclosure
I used AI to help me with code, tests and documentation.