oauth_issuer
The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .
当前阅读 PG 18·选择有来源记录的版本
此版本暂无所选语言的定义,以下显示原始英文内容。
- Client library
- libpq 18.6
- Manual definition
- Documented
- Source environment fallback
- None declared in the option table
- Compiled fallback expression
- NULL
- documented
- true
- environment
- 未知
- keyword
- oauth_issuer
- manual path
- libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER
- signature
- oauth_issuer
版本定义 PG 18
oauth_issuer-
The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the
issuersetting in the server's HBA configuration.As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the
oauth_issuer, and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of "mix-up attacks" on OAuth clients.You may also explicitly set
oauth_issuerto the/.well-known/URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:-
/.well-known/openid-configuration -
/.well-known/oauth-authorization-server
Warning
Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an
oauth_issuer. -
比较版本
完整来源事实
default evidence
You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:
precedence evidence
The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example., Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\postgresql\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR ., Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults.
source option
{"compiled_default_expression":"NULL","declaration":"\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)","environment":"","keyword":"oauth_issuer","source_notes":[]}来源引用
- 18.6 English manual · libpq-connect.html
- 18.6 libpq connection option declarations
- 18.6 English manual · libpq-envars.html
- 18.6 English manual · libpq-pgservice.html
- 固定 PostgreSQL 源码归档
定义来源
center · PostgreSQL 18 · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8
正文语言: en · ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8