From 8996cf57c2b9aad2c43238e5c43e5ac5e6f789f3 Mon Sep 17 00:00:00 2001 From: Zsolt Parragi Date: Sat, 10 Oct 2026 09:08:11 +0000 Subject: [PATCH v1] oauth: Show validator.* options in pg_hba_file_rules b977bd308 added validator-specific HBA options, but get_hba_options() was never taught about them, so pg_hba_file_rules silently omitted them. Emit them, sizing the options array dynamically since their number is unbounded. Backpatch to 19, where validator.* options were introduced. Backpatch-through: 19 --- src/backend/utils/adt/hbafuncs.c | 17 +++++++++++++++-- .../modules/oauth_validator/t/001_server.pl | 11 +++++++++++ 2 files changed, 26 insertions(+), 2 deletions(-) diff --git a/src/backend/utils/adt/hbafuncs.c b/src/backend/utils/adt/hbafuncs.c index bd23eda3f79..8b4f4e510e3 100644 --- a/src/backend/utils/adt/hbafuncs.c +++ b/src/backend/utils/adt/hbafuncs.c @@ -54,8 +54,12 @@ static ArrayType * get_hba_options(HbaLine *hba) { int noptions; - Datum options[MAX_HBA_OPTIONS]; + int maxoptions; + Datum *options; + /* validator.* options are unbounded */ + maxoptions = MAX_HBA_OPTIONS + list_length(hba->oauth_opt_keys); + options = palloc_array(Datum, maxoptions); noptions = 0; if (hba->auth_method == uaGSS || hba->auth_method == uaSSPI) @@ -137,6 +141,9 @@ get_hba_options(HbaLine *hba) if (hba->auth_method == uaOAuth) { + ListCell *lck, + *lcv; + if (hba->oauth_issuer) options[noptions++] = CStringGetTextDatum(psprintf("issuer=%s", hba->oauth_issuer)); @@ -152,10 +159,16 @@ get_hba_options(HbaLine *hba) if (hba->oauth_skip_usermap) options[noptions++] = CStringGetTextDatum(psprintf("delegate_ident_mapping=true")); + + forboth(lck, hba->oauth_opt_keys, lcv, hba->oauth_opt_vals) + options[noptions++] = + CStringGetTextDatum(psprintf("validator.%s=%s", + (char *) lfirst(lck), + (char *) lfirst(lcv))); } /* If you add more options, consider increasing MAX_HBA_OPTIONS. */ - Assert(noptions <= MAX_HBA_OPTIONS); + Assert(noptions <= maxoptions); if (noptions > 0) return construct_array_builtin(options, noptions, TEXTOID); diff --git a/src/test/modules/oauth_validator/t/001_server.pl b/src/test/modules/oauth_validator/t/001_server.pl index 444de01ea5d..981a94a0ce2 100644 --- a/src/test/modules/oauth_validator/t/001_server.pl +++ b/src/test/modules/oauth_validator/t/001_server.pl @@ -752,12 +752,23 @@ $node->append_conf( local all test oauth issuer="$issuer" scope="openid postgres" delegate_ident_mapping=1 \\ validator.authn_id="ignored" validator.authn_id="other-identity" local all testalt oauth issuer="$issuer" scope="openid postgres" validator.log="testalt message" +local all all trust }); $node->reload; $log_start = $node->wait_for_log(qr/reloading configuration files/, $log_start); +is( $node->safe_psql( + 'postgres', + qq(SELECT rule_number, options + FROM pg_hba_file_rules + WHERE auth_method = 'oauth' + ORDER BY rule_number;)), + qq{1|\{issuer=$issuer,"scope=openid postgres",validator=validator,delegate_ident_mapping=true,validator.authn_id=ignored,validator.authn_id=other-identity\} +2|\{issuer=$issuer,"scope=openid postgres",validator=validator,"validator.log=testalt message"\}}, + "pg_hba_file_rules shows validator options"); + $node->connect_ok( "$common_connstr user=test", "custom HBA setting (test)", -- 2.55.0