Emptying oauth_validator_libraries doesn't stop OAuth logins

From: Zsolt Parragi <zsolt(dot)parragi(at)percona(dot)com>
To: PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com>, Daniel Gustafsson <daniel(at)yesql(dot)se>
Subject: Emptying oauth_validator_libraries doesn't stop OAuth logins
Date: 2026-10-10 09:57:49
Message-ID: CAN4CZFNbWXwC=s4t9Xu1kitLsQvTe-EwpVtFCjixWCHBxRTraQ@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Hello

The docs for oauth_validator_libraries say "If set to an empty string
(the default), OAuth connections will be refused", but that's only
true for a freshly started server. On a running one, setting it to ''
and reloading leaves existing oauth HBA lines working.

LOG: parameter "oauth_validator_libraries" changed to ""
LOG: parameter "oauth_validator_libraries" must be set for
authentication method "oauth"
CONTEXT: line 2 of configuration file ".../pg_hba.conf"
LOG: pg_hba.conf was not reloaded

SHOW reports '', pg_hba_file_rules shows the error, but logins on the
oauth line still succeed.

The allowlist is only enforced by check_oauth_validator() while
pg_hba.conf is parsed. When the GUC change makes an oauth line
invalid, the whole HBA reload fails, and the postmaster keeps the
previously parsed lines, including the validator name that was
resolved against the old list. load_validator_library() never looks at
the current setting. The same happens if a line has an explicit
validator=foo and foo is removed from the list: the validator that is
"not permitted by oauth_validator_libraries" keeps authenticating
users.

The attached patch calls check_oauth_validator() again in
oauth_init(), before loading the library, and fails the authentication
if the validator isn't permitted anymore. Only logins on affected
oauth lines fail, everything else keeps working with the old HBA lines
as before.

The patch doesn't make the behavior stricter than what we already have
elsewhere:
* After a restart, the same configuration makes the postmaster refuse
to start (load_hba() fails at startup).
* With EXEC_BACKEND, every backend re-parses pg_hba.conf with the
current setting, so all new connections already fail with "could not
load pg_hba.conf", not only the oauth ones.

Attachment Content-Type Size
v1-0001-oauth-Recheck-oauth_validator_libraries-during-au.patch application/octet-stream 3.0 KB

Browse pgsql-hackers by date

  From Date Subject
Next Message Vadim Ponomarev 2026-10-10 10:02:29 Re: Reduce SyncRepLock contention on the commit path
Previous Message Zsolt Parragi 2026-10-10 09:47:11 Re: Do we want to solve reload/config races more generally? (was: Postmaster crashes on SIGHUP when oauth_validator_libraries holds only whitespace)