Skip to content

Save auth login profiles with the account's primary (SPOG) URL - #6854

Open
Peter-Feng-32 wants to merge 9 commits into
mainfrom
spog-login-poll
Open

Peter-Feng-32 wants to merge 9 commits into
mainfrom
spog-login-poll

Conversation

@Peter-Feng-32

@Peter-Feng-32 Peter-Feng-32 commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

databricks auth login now saves profiles with the account's primary (SPOG) URL.

  • Account logins (classic accounts.* host, or choosing an account in the browser flow): after the token is minted, look up GET /api/2.0/accounts/{account_id}/provisioned-urls/primary and save the profile with that host. The token stays account-level.
  • Workspace logins behave exactly like a login to the workspace's own host: workspace OAuth and a workspace-scoped token. The only difference is that the profile is saved with the SPOG URL.
    • --host <workspace> and choosing a workspace in the browser flow log in at the workspace as before. The CLI then looks up primary_url via /.well-known/databricks-config?include_primary_url=true and switches the profile to it, once the SPOG host is confirmed to serve that workspace's OAuth from the workspace host.
    • --host <spog>?o=<id> or --host <spog> --workspace-id <id> logs in through the workspace's OAuth endpoints.

Workspace-scoped SPOG profiles record discovery_url = <spog>/oidc/.well-known/oauth-authorization-server?o=<workspace_id>. That URL serves the canonical workspace's OAuth endpoints, and auth uses workspace OAuth for profiles that have it. Profiles without it, including existing SPOG profiles created with the workspace picker, keep their account-level tokens. All lookups are best-effort: if one fails, the login keeps its original host and token type.

Testing

  • Unit tests for the lookups and the SPOG workspace discovery URL helpers.
  • ToOAuthArgument routing and workspace OAuth via a discovery URL (including refresh).
  • Login on each path: switching, not switching, ?o= / --workspace-id, re-login of account-level vs workspace-scoped profiles, and the browser flow.
  • go test ./cmd/... ./libs/... and the auth acceptance tests pass, except libs/dyn/jsonloader TestJsonLoaderMalformedArray, which is untouched by this PR and fails locally on a JSON error-message column.
  • Manually on staging with --host https://dogfood.staging.databricks.com/?o=<workspace-id>. The login opened the canonical workspace's authorize endpoint and saved the profile on the SPOG host with workspace_id and the ?o= discovery_url. The token is workspace-scoped (canonical workspace issuer, aud = workspace ID). current-user me through the SPOG host succeeds, and so does auth token --force-refresh followed by another API call.

This pull request and its description were written by Isaac.

`databricks auth login` now looks up the account's primary provisioned
URL (its SPOG host) by account ID via
GET /api/2.0/accounts/{account_id}/provisioned-urls/primary once the
OAuth token is minted, and saves the profile with that host. The lookup
is best-effort: failures are logged and leave the host unchanged.

Co-authored-by: Isaac <no-reply@databricks.com>
The best-effort lookup ran under the login context (default 1h timeout)
with no client-side timeout, so a hung provisioned-urls endpoint could
stall login. Give it its own 30s deadline.

Co-authored-by: Isaac <no-reply@databricks.com>
@eng-dev-ecosystem-bot

eng-dev-ecosystem-bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Integration test report

Commit: fb1b0f3

Run: 37711041155

Env ✅​pass 🙈​skip Time
✅​ aws linux 276 16 8:06
✅​ aws windows 278 14 7:01
✅​ azure linux 275 16 5:08
✅​ azure windows 277 14 3:48
✅​ gcp linux 276 16 5:25
✅​ gcp windows 278 14 3:24
Top 6 slowest tests (at least 2 minutes):
duration env testname
4:01 aws linux TestAccept
3:55 gcp linux TestAccept
3:50 azure linux TestAccept
3:46 azure windows TestAccept
3:22 gcp windows TestAccept
3:18 aws windows TestAccept

Peter Feng and others added 3 commits September 28, 2026 06:53
Extend the primary provisioned (SPOG) URL lookup to the
login.databricks.com discovery flow: when the user selects an account
(the discovered host is a classic account host) the profile is switched
to the account's primary provisioned URL, matching the --account-id
login path.

Token introspection backfills an account_id even for workspace
selections, so gate the lookup on the discovered host being a classic
account host to avoid rewriting a concrete workspace host. Extract the
shared, timeout-bounded, best-effort lookup into resolvePrimaryProvisionedURL
and reuse it from both flows.

Also realign the const block gofmt flagged after the timeout constant
was added.

Co-authored-by: Isaac <no-reply@databricks.com>
The direct (--host/--account-id) login path rewrote the host to the
account's primary provisioned URL whenever account_id was set, with no
host-type guard. account_id can also be set on a concrete workspace host
(--account-id or ?a=), so 'databricks auth login --host <workspace-url>
--account-id <id>' silently discarded the targeted workspace and saved
the account SPOG host instead.

Gate the rewrite on the host being a classic account host, mirroring the
discovery path, and extract the shared gate into shouldResolveProvisionedURL
so both flows use one tested condition.

Co-authored-by: Isaac <no-reply@databricks.com>
For workspace hosts, auth login now looks up the owning account's primary
URL via /.well-known/databricks-config?include_primary_url=true before the
OAuth challenge and, once discovery confirms it is a unified host, logs in
against it while keeping account_id and workspace_id. Best-effort: lookup
failures leave the workspace host unchanged.

Co-authored-by: Isaac <no-reply@databricks.com>
@Peter-Feng-32 Peter-Feng-32 changed the title Look up account primary provisioned (SPOG) URL during auth login Save auth login profiles with the account's primary (SPOG) URL Oct 7, 2026
Peter Feng and others added 4 commits October 7, 2026 21:42
When a workspace is selected in the login.databricks.com flow and its
account has a primary URL, run a second login against that URL and save
the profile with it. The discovery token was issued by the workspace's
OIDC, which the SPOG host won't refresh. Best-effort: if the second login
fails, the workspace profile and token are saved as before.

Co-authored-by: Isaac <no-reply@databricks.com>
Logging in to a SPOG workspace now behaves like logging in to the
workspace's own host, except that the profile is saved with the SPOG URL.
The profile records the workspace-level OAuth metadata URL on the SPOG
host (discovery_url = <spog>/oidc/.well-known/oauth-authorization-server?o=<id>),
which serves the canonical workspace's endpoints, and auth routes such
profiles to workspace OAuth instead of the account endpoint.

- --host <workspace> and the browser flow log in at the workspace as
  before, then save the SPOG URL once it is confirmed to serve that
  workspace's OAuth. This replaces the pre-login switch and the second
  browser login.
- --host <spog> with ?o= or --workspace-id logs in through the
  workspace's OAuth endpoints. Profiles without the marker, including
  existing SPOG profiles from the workspace picker, keep account-level
  tokens.

Co-authored-by: Isaac <no-reply@databricks.com>
auth token reuses login's host resolution, so ?o= on the host or
--workspace-id could route an account-level SPOG profile's refresh to
workspace OAuth, where its refresh token is rejected. Naming a workspace
now selects workspace OAuth only in auth login; every other path follows
the profile's discovery_url marker, including profiles that auth token
matches by --host.

Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants