Repository navigation
Save auth login profiles with the account's primary (SPOG) URL - #6854
Open
Peter-Feng-32 wants to merge 9 commits into
Open
Peter-Feng-32 wants to merge 9 commits into
Peter-Feng-32 wants to merge 9 commits into
Conversation
`databricks auth login` now looks up the account's primary provisioned
URL (its SPOG host) by account ID via
GET /api/2.0/accounts/{account_id}/provisioned-urls/primary once the
OAuth token is minted, and saves the profile with that host. The lookup
is best-effort: failures are logged and leave the host unchanged.
Co-authored-by: Isaac <no-reply@databricks.com>
Peter-Feng-32
force-pushed
the
spog-login-poll
branch
from
September 28, 2026 06:04
726dd30 to
3897e85
Compare
The best-effort lookup ran under the login context (default 1h timeout) with no client-side timeout, so a hung provisioned-urls endpoint could stall login. Give it its own 30s deadline. Co-authored-by: Isaac <no-reply@databricks.com>
Collaborator
Integration test reportCommit: fb1b0f3
Top 6 slowest tests (at least 2 minutes):
|
Extend the primary provisioned (SPOG) URL lookup to the login.databricks.com discovery flow: when the user selects an account (the discovered host is a classic account host) the profile is switched to the account's primary provisioned URL, matching the --account-id login path. Token introspection backfills an account_id even for workspace selections, so gate the lookup on the discovered host being a classic account host to avoid rewriting a concrete workspace host. Extract the shared, timeout-bounded, best-effort lookup into resolvePrimaryProvisionedURL and reuse it from both flows. Also realign the const block gofmt flagged after the timeout constant was added. Co-authored-by: Isaac <no-reply@databricks.com>
The direct (--host/--account-id) login path rewrote the host to the account's primary provisioned URL whenever account_id was set, with no host-type guard. account_id can also be set on a concrete workspace host (--account-id or ?a=), so 'databricks auth login --host <workspace-url> --account-id <id>' silently discarded the targeted workspace and saved the account SPOG host instead. Gate the rewrite on the host being a classic account host, mirroring the discovery path, and extract the shared gate into shouldResolveProvisionedURL so both flows use one tested condition. Co-authored-by: Isaac <no-reply@databricks.com>
For workspace hosts, auth login now looks up the owning account's primary URL via /.well-known/databricks-config?include_primary_url=true before the OAuth challenge and, once discovery confirms it is a unified host, logs in against it while keeping account_id and workspace_id. Best-effort: lookup failures leave the workspace host unchanged. Co-authored-by: Isaac <no-reply@databricks.com>
When a workspace is selected in the login.databricks.com flow and its account has a primary URL, run a second login against that URL and save the profile with it. The discovery token was issued by the workspace's OIDC, which the SPOG host won't refresh. Best-effort: if the second login fails, the workspace profile and token are saved as before. Co-authored-by: Isaac <no-reply@databricks.com>
Logging in to a SPOG workspace now behaves like logging in to the workspace's own host, except that the profile is saved with the SPOG URL. The profile records the workspace-level OAuth metadata URL on the SPOG host (discovery_url = <spog>/oidc/.well-known/oauth-authorization-server?o=<id>), which serves the canonical workspace's endpoints, and auth routes such profiles to workspace OAuth instead of the account endpoint. - --host <workspace> and the browser flow log in at the workspace as before, then save the SPOG URL once it is confirmed to serve that workspace's OAuth. This replaces the pre-login switch and the second browser login. - --host <spog> with ?o= or --workspace-id logs in through the workspace's OAuth endpoints. Profiles without the marker, including existing SPOG profiles from the workspace picker, keep account-level tokens. Co-authored-by: Isaac <no-reply@databricks.com>
auth token reuses login's host resolution, so ?o= on the host or --workspace-id could route an account-level SPOG profile's refresh to workspace OAuth, where its refresh token is rejected. Naming a workspace now selects workspace OAuth only in auth login; every other path follows the profile's discovery_url marker, including profiles that auth token matches by --host. Co-authored-by: Isaac <no-reply@databricks.com>
Co-authored-by: Isaac <no-reply@databricks.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
databricks auth loginnow saves profiles with the account's primary (SPOG) URL.accounts.*host, or choosing an account in the browser flow): after the token is minted, look upGET /api/2.0/accounts/{account_id}/provisioned-urls/primaryand save the profile with that host. The token stays account-level.--host <workspace>and choosing a workspace in the browser flow log in at the workspace as before. The CLI then looks upprimary_urlvia/.well-known/databricks-config?include_primary_url=trueand switches the profile to it, once the SPOG host is confirmed to serve that workspace's OAuth from the workspace host.--host <spog>?o=<id>or--host <spog> --workspace-id <id>logs in through the workspace's OAuth endpoints.Workspace-scoped SPOG profiles record
discovery_url = <spog>/oidc/.well-known/oauth-authorization-server?o=<workspace_id>. That URL serves the canonical workspace's OAuth endpoints, and auth uses workspace OAuth for profiles that have it. Profiles without it, including existing SPOG profiles created with the workspace picker, keep their account-level tokens. All lookups are best-effort: if one fails, the login keeps its original host and token type.Testing
ToOAuthArgumentrouting and workspace OAuth via a discovery URL (including refresh).?o=/--workspace-id, re-login of account-level vs workspace-scoped profiles, and the browser flow.go test ./cmd/... ./libs/...and the auth acceptance tests pass, exceptlibs/dyn/jsonloaderTestJsonLoaderMalformedArray, which is untouched by this PR and fails locally on a JSON error-message column.--host https://dogfood.staging.databricks.com/?o=<workspace-id>. The login opened the canonical workspace's authorize endpoint and saved the profile on the SPOG host withworkspace_idand the?o=discovery_url. The token is workspace-scoped (canonical workspace issuer,aud= workspace ID).current-user methrough the SPOG host succeeds, and so doesauth token --force-refreshfollowed by another API call.This pull request and its description were written by Isaac.