From d5bc7ea5dbf96ed016bfb1852b8e3857e55a64dc Mon Sep 17 00:00:00 2001 From: Zsolt Parragi Date: Sat, 10 Oct 2026 09:06:55 +0000 Subject: [PATCH v1] oauth: Recheck oauth_validator_libraries during authentication The validator allowlist is only enforced while parsing pg_hba.conf. If a change to oauth_validator_libraries makes an existing oauth line invalid, the HBA reload fails and the old lines stay in use, so a removed validator keeps authenticating users. In particular, setting the list to '' doesn't refuse OAuth connections, as documented. Check the HBA line against the current setting again before loading the validator. Backpatch-through: 18 --- src/backend/libpq/auth-oauth.c | 14 ++++++++++++++ src/test/modules/oauth_validator/t/001_server.pl | 11 +++++++++++ 2 files changed, 25 insertions(+) diff --git a/src/backend/libpq/auth-oauth.c b/src/backend/libpq/auth-oauth.c index fb830065fba..29a0b00ba1c 100644 --- a/src/backend/libpq/auth-oauth.c +++ b/src/backend/libpq/auth-oauth.c @@ -109,6 +109,7 @@ static void * oauth_init(Port *port, const char *selected_mech, const char *shadow_pass) { struct oauth_ctx *ctx; + char *err_msg; if (strcmp(selected_mech, OAUTHBEARER_NAME) != 0) ereport(ERROR, @@ -127,6 +128,19 @@ oauth_init(Port *port, const char *selected_mech, const char *shadow_pass) ctx->issuer = port->hba->oauth_issuer; ctx->scope = port->hba->oauth_scope; + /* + * The allowlist is otherwise only enforced when pg_hba.conf is parsed. If + * a change to oauth_validator_libraries caused the last reload to fail, + * we're still using the old HBA lines, and their validator may no longer + * be permitted. Check again before loading it. + */ + if (!check_oauth_validator(port->hba, LOG, &err_msg)) + ereport(ERROR, + errcode(ERRCODE_CONFIG_FILE_ERROR), + errmsg("OAuth validator \"%s\" is not permitted by \"%s\"", + port->hba->oauth_validator, + "oauth_validator_libraries")); + load_validator_library(port->hba->oauth_validator); return ctx; diff --git a/src/test/modules/oauth_validator/t/001_server.pl b/src/test/modules/oauth_validator/t/001_server.pl index 444de01ea5d..7cb8028f36b 100644 --- a/src/test/modules/oauth_validator/t/001_server.pl +++ b/src/test/modules/oauth_validator/t/001_server.pl @@ -143,6 +143,17 @@ $log_start = $node->wait_for_log( $log_start); $bgconn->query_safe('SELECT 1'); +# The failed reload leaves the old HBA lines in place, but their validator is +# no longer allowed. +$node->connect_fails( + "user=test dbname=postgres oauth_issuer=$issuer oauth_client_id=f02c6361-0635", + "validator removed from oauth_validator_libraries is not used", + expected_stderr => + qr/OAuth validator "validator" is not permitted by "oauth_validator_libraries"/, + log_like => [ + qr/parameter "oauth_validator_libraries" must be set for authentication method "oauth"/ + ]); + $node->append_conf('postgresql.conf', "oauth_validator_libraries = 'validator'"); $node->reload; -- 2.55.0