{"kind": "auth", "major": "18", "item": {"slug": "oauth", "name": "oauth", "name_zh": "", "category": "\u8eab\u4efd\u8ba4\u8bc1\u4e0e\u8bbf\u95ee\u63a7\u5236", "summary": "\u4f7f\u7528\u7b2c\u4e09\u65b9 OAuth 2.0 \u8eab\u4efd\u63d0\u4f9b\u65b9\u8fdb\u884c\u6388\u6743\uff0c\u5e76\u53ef\u9009\u5730\u5b8c\u6210\u8ba4\u8bc1\u3002\u8be6\u7ec6\u4fe1\u606f\u8bf7\u53c2\u89c1 \u7b2c 20.15 \u8282 \u3002", "aliases": [], "content_hash": "7c59163969000f80b39d98c6dca3af44b1b0c53ccb94a70178feb717db27c11f", "versions": {"18": {"facts": [{"label": "\u65b9\u6cd5", "value": "oauth"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09", "description": "\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528 \u7ec8\u7aef\u7528\u6237 \u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 psql \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002"}, {"name": "\u5ba2\u6237\u7aef", "description": "\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 psql \uff09\u5728\u8fde\u63a5 PostgreSQL \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002"}, {"name": "\u8d44\u6e90\u670d\u52a1\u5668", "description": "\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 PostgreSQL \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002"}, {"name": "\u63d0\u4f9b\u8005", "description": "\u4e3a\u7279\u5b9a\u5e94\u7528\u5f00\u53d1\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u5382\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u8005\u901a\u5e38\u91c7\u7528\u4e0d\u540c\u7684 OAuth \u5b9e\u73b0\u7ec6\u8282\uff0c\u56e0\u6b64\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u4e0d\u80fd\u4fdd\u8bc1\u8bbf\u95ee\u53e6\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u670d\u52a1\u5668\u3002\u8fd9\u79cd\u201c\u63d0\u4f9b\u8005\u201d\u7528\u6cd5\u4e0d\u662f\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u5b9e\u9645\u4ea4\u6d41\u4e2d\u5e7f\u6cdb\u4f7f\u7528\u3002\u8bf7\u52ff\u5c06\u5176\u4e0e OpenID \u4e2d\u7c7b\u4f3c\u7684\u201c\u8eab\u4efd\u63d0\u4f9b\u8005\uff08Identity Provider\uff09\u201d\u6df7\u6dc6\u3002PostgreSQL \u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u4f7f\u7528 OIDC\u3002"}, {"name": "\u6388\u6743\u670d\u52a1\u5668", "description": "\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002 PostgreSQL \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002"}, {"name": "\u7b7e\u53d1\u8005", "description": "\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 https:// URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002"}, {"name": "issuer", "description": "\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e \u7b7e\u53d1\u8005\u6807\u8bc6\u7b26 \uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002 \u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 /.well-known/openid-configuration \u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c issuer \u672c\u8eab\u5305\u542b /.well-known/ \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002 \u8b66\u544a libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684 oauth_issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002"}, {"name": "scope", "description": "\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1 \u7b2c 50 \u7ae0 \uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator", "description": "\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e oauth_validator_libraries \u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e oauth_validator_libraries \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002"}, {"name": "delegate_ident_mapping", "description": "\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002 \u5f53\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e pg_ident.conf \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002 \u6b64\u53c2\u6570\u4e0e map \u4e0d\u517c\u5bb9\u3002 \u8b66\u544a delegate_ident_mapping \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684 \u6807\u51c6\u68c0\u67e5 \uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/auth-oauth.html", "path": "auth-oauth.html", "label": "PostgreSQL 18 English manual", "sha256": "1e2e63530e79522cd93d2c34bc34a464927dbe46de9b01cdbf324648f1adda8d", "language": "en", "original_url": "/docs/18/auth-oauth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "oauth", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528\u7b2c\u4e09\u65b9 OAuth 2.0 \u8eab\u4efd\u63d0\u4f9b\u65b9\u8fdb\u884c\u6388\u6743\uff0c\u5e76\u53ef\u9009\u5730\u5b8c\u6210\u8ba4\u8bc1\u3002\u8be6\u7ec6\u4fe1\u606f\u8bf7\u53c2\u89c1 \u7b2c 20.15 \u8282 \u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-OAUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.15.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">OAuth 2.0 \u662f\u4e00\u4e2a\u884c\u4e1a\u6807\u51c6\u6846\u67b6\uff0c\u5b9a\u4e49\u89c1 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6749\" target=\"_top\">RFC 6749</a>\uff0c\u5b83\u5141\u8bb8\u7b2c\u4e09\u65b9\u5e94\u7528\u83b7\u5f97\u5bf9\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u53d7\u9650\u8bbf\u95ee\u3002\u5728\u6784\u5efa <span class=\"productname\">PostgreSQL</span> \u65f6\u5fc5\u987b\u542f\u7528 OAuth \u5ba2\u6237\u7aef\u652f\u6301\uff1b\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u672c\u6587\u6863\u5728\u8ba8\u8bba OAuth \u751f\u6001\u7cfb\u7edf\u65f6\u4f7f\u7528\u4e0b\u5217\u672f\u8bed\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt lang=\"zh\">\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528<span class=\"emphasis\"><em>\u7ec8\u7aef\u7528\u6237</em></span>\u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 <span class=\"application\">psql</span> \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u5ba2\u6237\u7aef</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 <span class=\"application\">psql</span>\uff09\u5728\u8fde\u63a5 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u8d44\u6e90\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u63d0\u4f9b\u8005</dt>\n<dd>\n<p lang=\"zh\">\u4e3a\u67d0\u4e2a\u5e94\u7528\u5f00\u53d1\u548c/\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u4f9b\u5e94\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u65b9\u901a\u5e38\u4f1a\u4e3a\u5404\u81ea\u7684 OAuth \u7cfb\u7edf\u9009\u62e9\u4e0d\u540c\u7684\u5b9e\u73b0\u7ec6\u8282\uff1b\u4e00\u4e2a\u63d0\u4f9b\u65b9\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u5e76\u4e0d\u80fd\u4fdd\u8bc1\u53ef\u4ee5\u8bbf\u95ee\u53e6\u4e00\u63d0\u4f9b\u65b9\u7684\u670d\u52a1\u5668\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u5bf9\u201c\u63d0\u4f9b\u65b9\u201d\u4e00\u8bcd\u7684\u4f7f\u7528\u5e76\u975e\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u53e3\u8bed\u4e2d\u4f3c\u4e4e\u5f88\u5e38\u89c1\u3002\uff08\u4e0d\u8981\u5c06\u5b83\u4e0e OpenID \u4e2d\u76f8\u8fd1\u7684\u672f\u8bed\u201cIdentity Provider\u201d\u6df7\u6dc6\u3002\u867d\u7136 <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u4fdd\u6301\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u5e76\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u5fc5\u987b\u4f7f\u7528 OIDC\u3002\uff09</p>\n</dd>\n<dt lang=\"zh\">\u6388\u6743\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002<span class=\"productname\">PostgreSQL</span> \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\"><span class=\"term\" id=\"AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005</span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 <code class=\"literal\">https://</code> URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\" lang=\"zh\">\u6ce8\u610f</h3>\n<p lang=\"zh\">\u5bf9\u4e8e\u5c0f\u578b\u90e8\u7f72\u6765\u8bf4\uff0c\u201c\u63d0\u4f9b\u65b9\u201d\u3001\u201c\u6388\u6743\u670d\u52a1\u5668\u201d\u548c\u201c\u7b7e\u53d1\u8005\u201d\u4e4b\u95f4\u53ef\u80fd\u5e76\u6ca1\u6709\u6709\u610f\u4e49\u7684\u533a\u522b\u3002\u7136\u800c\u5728\u66f4\u590d\u6742\u7684\u90e8\u7f72\u4e2d\uff0c\u5b83\u4eec\u4e4b\u95f4\u53ef\u80fd\u662f\u4e00\u4e2a\u5bf9\u591a\u4e2a\uff08\u751a\u81f3\u591a\u4e2a\u5bf9\u591a\u4e2a\uff09\u7684\u5173\u7cfb\uff1a\u67d0\u4e2a\u63d0\u4f9b\u65b9\u53ef\u80fd\u628a\u591a\u4e2a\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u79df\u7ed9\u4e0d\u540c\u79df\u6237\uff0c\u7136\u540e\u518d\u63d0\u4f9b\u591a\u4e2a\u6388\u6743\u670d\u52a1\u5668\u4e0e\u5176\u5ba2\u6237\u7aef\u4ea4\u4e92\uff0c\u800c\u8fd9\u4e9b\u6388\u6743\u670d\u52a1\u5668\u652f\u6301\u7684\u7279\u6027\u96c6\u5408\u4e5f\u53ef\u80fd\u5404\u4e0d\u76f8\u540c\u3002</p>\n</div>\n<p lang=\"zh\"><span class=\"productname\">PostgreSQL</span> \u652f\u6301\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6750\" target=\"_top\">RFC 6750</a> \u4e2d\u5b9a\u4e49\u7684 Bearer \u4ee4\u724c\uff0c\u8fd9\u662f\u4e00\u7c7b\u7528\u4e8e OAuth 2.0 \u7684\u8bbf\u95ee\u4ee4\u724c\uff0c\u5176\u672c\u4f53\u662f\u4e00\u4e2a\u4e0d\u900f\u660e\u5b57\u7b26\u4e32\u3002\u8bbf\u95ee\u4ee4\u724c\u7684\u683c\u5f0f\u53d6\u51b3\u4e8e\u5177\u4f53\u5b9e\u73b0\uff0c\u7531\u5404\u4e2a\u6388\u6743\u670d\u52a1\u5668\u81ea\u884c\u51b3\u5b9a\u3002</p>\n<p lang=\"zh\">OAuth \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">issuer</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e<a class=\"link\" href=\"/docs/18/auth-oauth.html#AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26</a>\uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n<p lang=\"zh\">\u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 <code class=\"literal\">/.well-known/openid-configuration</code>\u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c <code class=\"literal\">issuer</code> \u672c\u8eab\u5305\u542b <code class=\"literal\">/.well-known/</code> \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER\">oauth_issuer</a>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">scope</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1<a class=\"xref\" href=\"/docs/18/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u7b2c\u00a050\u00a0\u7ae0</a>\uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">validator</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-OAUTH-VALIDATOR-LIBRARIES\">oauth_validator_libraries</a>\u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e <code class=\"literal\">oauth_validator_libraries</code> \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\" id=\"AUTH-OAUTH-DELEGATE-IDENT-MAPPING\"><code class=\"literal\">delegate_ident_mapping</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002</p>\n<p lang=\"zh\">\u5f53\u8bbe\u7f6e\u4e3a <code class=\"literal\">1</code> \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e <code class=\"filename\">pg_ident.conf</code> \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002</p>\n<p lang=\"zh\">\u6b64\u53c2\u6570\u4e0e <code class=\"literal\">map</code> \u4e0d\u517c\u5bb9\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\"><code class=\"literal\">delegate_ident_mapping</code> \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684<a class=\"link\" href=\"/docs/18/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u6807\u51c6\u68c0\u67e5</a>\uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002</p>\n</div>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/18/auth-oauth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/auth-oauth.html", "method": "same-major semantic node", "sha256": "b43ffd0af2f515aa246019c63c5041fabafd740514ea91eeea7efc7eaec410fc", "language": "zh", "matched_nodes": ["#AUTH-OAUTH/div[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[11]", "#AUTH-OAUTH/div[4]/dl[0]/dd[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[3]", "#AUTH-OAUTH/div[4]/dl[0]/dd[5]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[9]", "#AUTH-OAUTH/div[4]/dl[0]/dt[10]", "#AUTH-OAUTH/div[5]/h3[0]", "#AUTH-OAUTH/div[5]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/h3[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[5]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/div[3]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[2]", "#AUTH-OAUTH/p[2]", "#AUTH-OAUTH/p[3]", "#AUTH-OAUTH/p[6]", "#AUTH-OAUTH/p[7]"]}, {"url": "/docs/18/auth-pg-hba-conf.html", "method": "same-major semantic node", "sha256": "e3184e306644bc82d642725babd6cd8053ae3c71d7590af05a805685dc88491b", "language": "zh", "matched_nodes": ["#AUTH-PG-HBA-CONF/div[12]/dl[0]/dd[21]/div[1]/dl[0]/dd[29]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.15 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/rows/0/name": "Resource Owner (or End User)", "/versions/18/tables/0/rows/1/name": "Client", "/versions/18/tables/0/rows/2/name": "Resource Server", "/versions/18/tables/0/rows/3/name": "Provider", "/versions/18/tables/0/rows/4/name": "Authorization Server", "/versions/18/tables/0/rows/5/name": "Issuer", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "The user or system who owns protected resources and can grant access to them. This documentation also uses the term end user when the resource owner is a person. When you use psql to connect to the database using OAuth, you are the resource owner/end user.", "/versions/18/tables/0/rows/1/description": "The system which accesses the protected resources using access tokens. Applications using libpq, such as psql , are the OAuth clients when connecting to a PostgreSQL cluster.", "/versions/18/tables/0/rows/2/description": "The system hosting the protected resources which are accessed by the client. The PostgreSQL cluster being connected to is the resource server.", "/versions/18/tables/0/rows/3/description": "The organization, product vendor, or other entity which develops and/or administers the OAuth authorization servers and clients for a given application. Different providers typically choose different implementation details for their OAuth systems; a client of one provider is not generally guaranteed to have access to the servers of another. This use of the term \"provider\" is not standard, but it seems to be in wide use colloquially. (It should not be confused with OpenID's similar term \"Identity Provider\". While the implementation of OAuth in PostgreSQL is intended to be interoperable and compatible with OpenID Connect/OIDC, it is not itself an OIDC client and does not require its use.)", "/versions/18/tables/0/rows/4/description": "The system which receives requests from, and issues access tokens to, the client after the authenticated resource owner has given approval. PostgreSQL does not provide an authorization server; it is the responsibility of the OAuth provider.", "/versions/18/tables/0/rows/5/description": "An identifier for an authorization server, printed as an https:// URL, which provides a trusted \"namespace\" for OAuth clients and applications. The issuer identifier allows a single authorization server to talk to the clients of mutually untrusting entities, as long as they maintain separate issuers.", "/versions/18/tables/0/rows/6/description": "An HTTPS URL which is either the exact issuer identifier of the authorization server, as defined by its discovery document, or a well-known URI that points directly to that discovery document. This parameter is required. When an OAuth client connects to the server, a URL for the discovery document will be constructed using the issuer identifier. By default, this URL uses the conventions of OpenID Connect Discovery: the path /.well-known/openid-configuration will be appended to the end of the issuer identifier. Alternatively, if the issuer contains a /.well-known/ path segment, that URL will be provided to the client as-is. Warning The OAuth client in libpq requires the server's issuer setting to exactly match the issuer identifier which is provided in the discovery document, which must in turn match the client's oauth_issuer setting. No variations in case or formatting are permitted.", "/versions/18/tables/0/rows/7/description": "A space-separated list of the OAuth scopes needed for the server to both authorize the client and authenticate the user. Appropriate values are determined by the authorization server and the OAuth validation module used (see Chapter 50 for more information on validators). This parameter is required.", "/versions/18/tables/0/rows/8/description": "The library to use for validating bearer tokens. If given, the name must exactly match one of the libraries listed in oauth_validator_libraries . This parameter is optional unless oauth_validator_libraries contains more than one library, in which case it is required.", "/versions/18/tables/0/rows/9/description": "Allows for mapping between OAuth identity provider and database user names. See Section 20.2 for details. If a map is not specified, the user name associated with the token (as determined by the OAuth validator) must exactly match the role name being requested. This parameter is optional.", "/versions/18/tables/0/rows/10/description": "An advanced option which is not intended for common use. When set to 1 , standard user mapping with pg_ident.conf is skipped, and the OAuth validator takes full responsibility for mapping end user identities to database roles. If the validator authorizes the token, the server trusts that the user is allowed to connect under the requested role, and the connection is allowed to proceed regardless of the authentication status of the user. This parameter is incompatible with map . Warning delegate_ident_mapping provides additional flexibility in the design of the authentication system, but it also requires careful implementation of the OAuth validator, which must determine whether the provided token carries sufficient end-user privileges in addition to the standard checks required of all validators. Use with caution."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "a1031c21e0762550677bc13421c0808cd18feb0ad3b8fa50b6272eadf6d9f8b8"}, "comparison_data": {"method": "oauth", "documented_option_names": ["Authorization Server", "Client", "Issuer", "Provider", "Resource Owner (or End User)", "Resource Server", "delegate_ident_mapping", "issuer", "map", "scope", "validator"]}, "comparison_hash": "614b1b99c2894fb23e3ddaf7706a1e06dd6cc3fd020965f4d8e18ed32ea3a772", "manual_language": "zh"}, "19": {"facts": [{"label": "\u65b9\u6cd5", "value": "oauth"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09", "description": "\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528 \u7ec8\u7aef\u7528\u6237 \u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 psql \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002"}, {"name": "\u5ba2\u6237\u7aef", "description": "\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 psql \uff09\u5728\u8fde\u63a5 PostgreSQL \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002"}, {"name": "\u8d44\u6e90\u670d\u52a1\u5668", "description": "\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 PostgreSQL \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002"}, {"name": "\u63d0\u4f9b\u8005", "description": "\u4e3a\u7279\u5b9a\u5e94\u7528\u5f00\u53d1\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u5382\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u8005\u901a\u5e38\u91c7\u7528\u4e0d\u540c\u7684 OAuth \u5b9e\u73b0\u7ec6\u8282\uff0c\u56e0\u6b64\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u4e0d\u80fd\u4fdd\u8bc1\u8bbf\u95ee\u53e6\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u670d\u52a1\u5668\u3002\u8fd9\u79cd\u201c\u63d0\u4f9b\u8005\u201d\u7528\u6cd5\u4e0d\u662f\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u5b9e\u9645\u4ea4\u6d41\u4e2d\u5e7f\u6cdb\u4f7f\u7528\u3002\u8bf7\u52ff\u5c06\u5176\u4e0e OpenID \u4e2d\u7c7b\u4f3c\u7684\u201c\u8eab\u4efd\u63d0\u4f9b\u8005\uff08Identity Provider\uff09\u201d\u6df7\u6dc6\u3002PostgreSQL \u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u4f7f\u7528 OIDC\u3002"}, {"name": "\u6388\u6743\u670d\u52a1\u5668", "description": "\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002 PostgreSQL \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002"}, {"name": "\u7b7e\u53d1\u8005", "description": "\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 https:// URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002"}, {"name": "issuer", "description": "\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e \u7b7e\u53d1\u8005\u6807\u8bc6\u7b26 \uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002 \u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 /.well-known/openid-configuration \u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c issuer \u672c\u8eab\u5305\u542b /.well-known/ \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002 \u8b66\u544a libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684 oauth_issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002"}, {"name": "scope", "description": "\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1 \u7b2c 50 \u7ae0 \uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator", "description": "\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e oauth_validator_libraries \u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e oauth_validator_libraries \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator. \u9009\u9879", "description": "\u9a8c\u8bc1\u5668\u6a21\u5757\u53ef\u4ee5 \u5b9a\u4e49 \u7528\u4e8e oauth HBA \u6761\u76ee\u7684\u989d\u5916\u914d\u7f6e\u9009\u9879\u3002\u8fd9\u4e9b\u9a8c\u8bc1\u5668\u4e13\u7528\u9009\u9879\u53ef\u901a\u8fc7 validator.* \u8fd9\u4e2a\u201c\u547d\u540d\u7a7a\u95f4\u201d\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u67d0\u4e2a\u6a21\u5757\u53ef\u4ee5\u6ce8\u518c validator.foo \u548c validator.bar \u9009\u9879\uff0c\u5e76\u5b9a\u4e49\u5b83\u4eec\u5bf9\u8ba4\u8bc1\u7684\u5f71\u54cd\u3002 \u6bcf\u4e2a option \u7684\u540d\u79f0\u3001\u8bed\u6cd5\u548c\u884c\u4e3a\u5e76\u4e0d\u7531 PostgreSQL \u51b3\u5b9a\uff1b\u8bf7\u67e5\u9605\u6240\u4f7f\u7528\u9a8c\u8bc1\u5668\u6a21\u5757\u7684\u6587\u6863\u3002 \u8b66\u544a \u5f53\u524d\u5b9e\u73b0\u7684\u4e00\u4e2a\u9650\u5236\u662f\uff0c\u65e0\u6cd5\u8bc6\u522b\u7684 option \u540d\u79f0\u8981\u5230\u8fde\u63a5\u65f6\u624d\u4f1a\u88ab\u53d1\u73b0\u3002 pg_ctl reload \u4f1a\u6210\u529f\uff0c\u4f46\u5339\u914d\u5230\u7684\u8fde\u63a5\u4f1a\u5931\u8d25\uff1a LOG: connection received: host=[local] WARNING: unrecognized authentication option name: \"validator.bad\" DETAIL: The installed validator module (\"my_validator\") did not define an option named \"bad\". HINT: All OAuth connections matching this line will fail. Correct the option and reload the server configuration. CONTEXT: line 2 of configuration file \"data/pg_hba.conf\" \u5728\u751f\u4ea7\u7cfb\u7edf\u4e2d\u4fee\u6539\u9a8c\u8bc1\u5668\u4e13\u7528\u7684 HBA \u9009\u9879\u65f6\u52a1\u5fc5\u8c28\u614e\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002"}, {"name": "delegate_ident_mapping", "description": "\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002 \u5f53\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e pg_ident.conf \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002 \u6b64\u53c2\u6570\u4e0e map \u4e0d\u517c\u5bb9\u3002 \u8b66\u544a delegate_ident_mapping \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684 \u6807\u51c6\u68c0\u67e5 \uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "revision": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86", "catalog_fingerprint": "62fbf1a3689dbe8bf7e6b3372cfe6fbf867581427b3858a94c8419b77a4d2d1d"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/auth-oauth.html", "path": "auth-oauth.html", "label": "PostgreSQL 19 English manual", "sha256": "1b6baa3b255cfb6afa3b8be6e0b882a75c241788e283754f10a3c22bc0707b75", "language": "en", "original_url": "/docs/19/auth-oauth.html"}, {"url": "https://pg.center/docs/19/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 19 English manual", "sha256": "d05e9155d5388148c2c680ff208b62c6b3b0b1c30f302ada5ab4befec36c19b7", "language": "en", "original_url": "/docs/19/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "oauth", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528\u7b2c\u4e09\u65b9 OAuth 2.0 \u8eab\u4efd\u63d0\u4f9b\u65b9\u8fdb\u884c\u6388\u6743\uff0c\u5e76\u53ef\u9009\u5730\u5b8c\u6210\u8ba4\u8bc1\u3002\u8be6\u7ec6\u4fe1\u606f\u8bf7\u53c2\u89c1 \u7b2c 20.14 \u8282 \u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-OAUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.14.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">OAuth 2.0 \u662f\u4e00\u4e2a\u884c\u4e1a\u6807\u51c6\u6846\u67b6\uff0c\u5b9a\u4e49\u89c1 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6749\" target=\"_top\">RFC 6749</a>\uff0c\u5b83\u5141\u8bb8\u7b2c\u4e09\u65b9\u5e94\u7528\u83b7\u5f97\u5bf9\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u53d7\u9650\u8bbf\u95ee\u3002\u5728\u6784\u5efa <span class=\"productname\">PostgreSQL</span> \u65f6\u5fc5\u987b\u542f\u7528 OAuth \u5ba2\u6237\u7aef\u652f\u6301\uff1b\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u672c\u6587\u6863\u5728\u8ba8\u8bba OAuth \u751f\u6001\u7cfb\u7edf\u65f6\u4f7f\u7528\u4e0b\u5217\u672f\u8bed\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt lang=\"zh\">\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528<span class=\"emphasis\"><em>\u7ec8\u7aef\u7528\u6237</em></span>\u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 <span class=\"application\">psql</span> \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u5ba2\u6237\u7aef</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 <span class=\"application\">psql</span>\uff09\u5728\u8fde\u63a5 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u8d44\u6e90\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u63d0\u4f9b\u8005</dt>\n<dd>\n<p lang=\"zh\">\u4e3a\u67d0\u4e2a\u5e94\u7528\u5f00\u53d1\u548c/\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u4f9b\u5e94\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u65b9\u901a\u5e38\u4f1a\u4e3a\u5404\u81ea\u7684 OAuth \u7cfb\u7edf\u9009\u62e9\u4e0d\u540c\u7684\u5b9e\u73b0\u7ec6\u8282\uff1b\u4e00\u4e2a\u63d0\u4f9b\u65b9\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u5e76\u4e0d\u80fd\u4fdd\u8bc1\u53ef\u4ee5\u8bbf\u95ee\u53e6\u4e00\u63d0\u4f9b\u65b9\u7684\u670d\u52a1\u5668\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u5bf9\u201c\u63d0\u4f9b\u65b9\u201d\u4e00\u8bcd\u7684\u4f7f\u7528\u5e76\u975e\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u53e3\u8bed\u4e2d\u4f3c\u4e4e\u5f88\u5e38\u89c1\u3002\uff08\u4e0d\u8981\u5c06\u5b83\u4e0e OpenID \u4e2d\u76f8\u8fd1\u7684\u672f\u8bed\u201cIdentity Provider\u201d\u6df7\u6dc6\u3002\u867d\u7136 <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u4fdd\u6301\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u5e76\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u5fc5\u987b\u4f7f\u7528 OIDC\u3002\uff09</p>\n</dd>\n<dt lang=\"zh\">\u6388\u6743\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002<span class=\"productname\">PostgreSQL</span> \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\"><span class=\"term\" id=\"AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005</span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 <code class=\"literal\">https://</code> URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\" lang=\"zh\">\u6ce8\u610f</h3>\n<p lang=\"zh\">\u5bf9\u4e8e\u5c0f\u578b\u90e8\u7f72\u6765\u8bf4\uff0c\u201c\u63d0\u4f9b\u65b9\u201d\u3001\u201c\u6388\u6743\u670d\u52a1\u5668\u201d\u548c\u201c\u7b7e\u53d1\u8005\u201d\u4e4b\u95f4\u53ef\u80fd\u5e76\u6ca1\u6709\u6709\u610f\u4e49\u7684\u533a\u522b\u3002\u7136\u800c\u5728\u66f4\u590d\u6742\u7684\u90e8\u7f72\u4e2d\uff0c\u5b83\u4eec\u4e4b\u95f4\u53ef\u80fd\u662f\u4e00\u4e2a\u5bf9\u591a\u4e2a\uff08\u751a\u81f3\u591a\u4e2a\u5bf9\u591a\u4e2a\uff09\u7684\u5173\u7cfb\uff1a\u67d0\u4e2a\u63d0\u4f9b\u65b9\u53ef\u80fd\u628a\u591a\u4e2a\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u79df\u7ed9\u4e0d\u540c\u79df\u6237\uff0c\u7136\u540e\u518d\u63d0\u4f9b\u591a\u4e2a\u6388\u6743\u670d\u52a1\u5668\u4e0e\u5176\u5ba2\u6237\u7aef\u4ea4\u4e92\uff0c\u800c\u8fd9\u4e9b\u6388\u6743\u670d\u52a1\u5668\u652f\u6301\u7684\u7279\u6027\u96c6\u5408\u4e5f\u53ef\u80fd\u5404\u4e0d\u76f8\u540c\u3002</p>\n</div>\n<p lang=\"zh\"><span class=\"productname\">PostgreSQL</span> \u652f\u6301\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6750\" target=\"_top\">RFC 6750</a> \u4e2d\u5b9a\u4e49\u7684 Bearer \u4ee4\u724c\uff0c\u8fd9\u662f\u4e00\u7c7b\u7528\u4e8e OAuth 2.0 \u7684\u8bbf\u95ee\u4ee4\u724c\uff0c\u5176\u672c\u4f53\u662f\u4e00\u4e2a\u4e0d\u900f\u660e\u5b57\u7b26\u4e32\u3002\u8bbf\u95ee\u4ee4\u724c\u7684\u683c\u5f0f\u53d6\u51b3\u4e8e\u5177\u4f53\u5b9e\u73b0\uff0c\u7531\u5404\u4e2a\u6388\u6743\u670d\u52a1\u5668\u81ea\u884c\u51b3\u5b9a\u3002</p>\n<p lang=\"zh\">OAuth \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">issuer</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e<a class=\"link\" href=\"/docs/19/auth-oauth.html#AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26</a>\uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n<p lang=\"zh\">\u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 <code class=\"literal\">/.well-known/openid-configuration</code>\u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c <code class=\"literal\">issuer</code> \u672c\u8eab\u5305\u542b <code class=\"literal\">/.well-known/</code> \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684<a class=\"xref\" href=\"/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER\">oauth_issuer</a>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">scope</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1<a class=\"xref\" href=\"/docs/19/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u7b2c\u00a050\u00a0\u7ae0</a>\uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">validator</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e<a class=\"xref\" href=\"/docs/19/runtime-config-connection.html#GUC-OAUTH-VALIDATOR-LIBRARIES\">oauth_validator_libraries</a>\u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e <code class=\"literal\">oauth_validator_libraries</code> \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">validator. \u9009\u9879</dt>\n<dd>\n<p lang=\"zh\">\u9a8c\u8bc1\u5668\u6a21\u5757\u53ef\u4ee5<a class=\"link\" href=\"/docs/19/oauth-validator-hba.html\" title=\"50.4.\u00a0\u81ea\u5b9a\u4e49 HBA \u9009\u9879\">\u5b9a\u4e49</a>\u7528\u4e8e <code class=\"literal\">oauth</code> HBA \u6761\u76ee\u7684\u989d\u5916\u914d\u7f6e\u9009\u9879\u3002\u8fd9\u4e9b\u9a8c\u8bc1\u5668\u4e13\u7528\u9009\u9879\u53ef\u901a\u8fc7 <code class=\"literal\">validator.*</code> \u8fd9\u4e2a\u201c\u547d\u540d\u7a7a\u95f4\u201d\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u67d0\u4e2a\u6a21\u5757\u53ef\u4ee5\u6ce8\u518c <code class=\"literal\">validator.foo</code> \u548c <code class=\"literal\">validator.bar</code> \u9009\u9879\uff0c\u5e76\u5b9a\u4e49\u5b83\u4eec\u5bf9\u8ba4\u8bc1\u7684\u5f71\u54cd\u3002</p>\n<p lang=\"zh\">\u6bcf\u4e2a <em class=\"replaceable\"><code>option</code></em> \u7684\u540d\u79f0\u3001\u8bed\u6cd5\u548c\u884c\u4e3a\u5e76\u4e0d\u7531 <span class=\"productname\">PostgreSQL</span> \u51b3\u5b9a\uff1b\u8bf7\u67e5\u9605\u6240\u4f7f\u7528\u9a8c\u8bc1\u5668\u6a21\u5757\u7684\u6587\u6863\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5f53\u524d\u5b9e\u73b0\u7684\u4e00\u4e2a\u9650\u5236\u662f\uff0c\u65e0\u6cd5\u8bc6\u522b\u7684 <em class=\"replaceable\"><code>option</code></em> \u540d\u79f0\u8981\u5230\u8fde\u63a5\u65f6\u624d\u4f1a\u88ab\u53d1\u73b0\u3002<code class=\"literal\">pg_ctl reload</code> \u4f1a\u6210\u529f\uff0c\u4f46\u5339\u914d\u5230\u7684\u8fde\u63a5\u4f1a\u5931\u8d25\uff1a</p>\n<pre class=\"programlisting\">LOG:  connection received: host=[local]\nWARNING:  unrecognized authentication option name: \"validator.bad\"\nDETAIL:  The installed validator module (\"my_validator\") did not define an option named \"bad\".\nHINT:  All OAuth connections matching this line will fail. Correct the option and reload the server configuration.\nCONTEXT:  line 2 of configuration file \"data/pg_hba.conf\"\n</pre>\n<p lang=\"zh\">\u5728\u751f\u4ea7\u7cfb\u7edf\u4e2d\u4fee\u6539\u9a8c\u8bc1\u5668\u4e13\u7528\u7684 HBA \u9009\u9879\u65f6\u52a1\u5fc5\u8c28\u614e\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/19/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\" id=\"AUTH-OAUTH-DELEGATE-IDENT-MAPPING\"><code class=\"literal\">delegate_ident_mapping</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002</p>\n<p lang=\"zh\">\u5f53\u8bbe\u7f6e\u4e3a <code class=\"literal\">1</code> \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e <code class=\"filename\">pg_ident.conf</code> \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002</p>\n<p lang=\"zh\">\u6b64\u53c2\u6570\u4e0e <code class=\"literal\">map</code> \u4e0d\u517c\u5bb9\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\"><code class=\"literal\">delegate_ident_mapping</code> \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684<a class=\"link\" href=\"/docs/19/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u6807\u51c6\u68c0\u67e5</a>\uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002</p>\n</div>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/19/auth-oauth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/19/auth-oauth.html", "method": "same-major semantic node", "sha256": "62c965dbf28435d8609f86cbd84a1331755426f5586dc8bb814657e3d6966c79", "language": "zh", "matched_nodes": ["#AUTH-OAUTH/div[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[11]", "#AUTH-OAUTH/div[4]/dl[0]/dd[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[3]", "#AUTH-OAUTH/div[4]/dl[0]/dd[5]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[9]", "#AUTH-OAUTH/div[4]/dl[0]/dt[10]", "#AUTH-OAUTH/div[5]/h3[0]", "#AUTH-OAUTH/div[5]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/div[3]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[2]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/h3[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[5]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/div[2]/p[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]", "#AUTH-OAUTH/p[2]", "#AUTH-OAUTH/p[3]", "#AUTH-OAUTH/p[6]", "#AUTH-OAUTH/p[7]"]}, {"url": "/docs/19/auth-pg-hba-conf.html", "method": "same-major semantic node", "sha256": "d25996d70bdcb8468c9e6b39f85df1a49ff773d4c13ae599c1da28d9e627d190", "language": "zh", "matched_nodes": ["#AUTH-PG-HBA-CONF/div[12]/dl[0]/dd[21]/div[1]/dl[0]/dd[27]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.14 for details.", "/versions/19/facts/0/label": "Method", "/versions/19/facts/1/label": "Configuration", "/versions/19/facts/2/label": "Inventory", "/versions/19/facts/2/value": "User-visible source authentication method", "/versions/19/tables/0/title": "Documented method options and alternatives", "/versions/19/tables/0/rows/0/name": "Resource Owner (or End User)", "/versions/19/tables/0/rows/1/name": "Client", "/versions/19/tables/0/rows/2/name": "Resource Server", "/versions/19/tables/0/rows/3/name": "Provider", "/versions/19/tables/0/rows/4/name": "Authorization Server", "/versions/19/tables/0/rows/5/name": "Issuer", "/versions/19/tables/0/rows/9/name": "validator. option", "/versions/19/tables/0/columns/0/label": "Option or term", "/versions/19/tables/0/columns/1/label": "Meaning", "/versions/19/tables/0/rows/0/description": "The user or system who owns protected resources and can grant access to them. This documentation also uses the term end user when the resource owner is a person. When you use psql to connect to the database using OAuth, you are the resource owner/end user.", "/versions/19/tables/0/rows/1/description": "The system which accesses the protected resources using access tokens. Applications using libpq, such as psql , are the OAuth clients when connecting to a PostgreSQL cluster.", "/versions/19/tables/0/rows/2/description": "The system hosting the protected resources which are accessed by the client. The PostgreSQL cluster being connected to is the resource server.", "/versions/19/tables/0/rows/3/description": "The organization, product vendor, or other entity which develops and/or administers the OAuth authorization servers and clients for a given application. Different providers typically choose different implementation details for their OAuth systems; a client of one provider is not generally guaranteed to have access to the servers of another. This use of the term \"provider\" is not standard, but it seems to be in wide use colloquially. (It should not be confused with OpenID's similar term \"Identity Provider\". While the implementation of OAuth in PostgreSQL is intended to be interoperable and compatible with OpenID Connect/OIDC, it is not itself an OIDC client and does not require its use.)", "/versions/19/tables/0/rows/4/description": "The system which receives requests from, and issues access tokens to, the client after the authenticated resource owner has given approval. PostgreSQL does not provide an authorization server; it is the responsibility of the OAuth provider.", "/versions/19/tables/0/rows/5/description": "An identifier for an authorization server, printed as an https:// URL, which provides a trusted \"namespace\" for OAuth clients and applications. The issuer identifier allows a single authorization server to talk to the clients of mutually untrusting entities, as long as they maintain separate issuers.", "/versions/19/tables/0/rows/6/description": "An HTTPS URL which is either the exact issuer identifier of the authorization server, as defined by its discovery document, or a well-known URI that points directly to that discovery document. This parameter is required. When an OAuth client connects to the server, a URL for the discovery document will be constructed using the issuer identifier. By default, this URL uses the conventions of OpenID Connect Discovery: the path /.well-known/openid-configuration will be appended to the end of the issuer identifier. Alternatively, if the issuer contains a /.well-known/ path segment, that URL will be provided to the client as-is. Warning The OAuth client in libpq requires the server's issuer setting to exactly match the issuer identifier which is provided in the discovery document, which must in turn match the client's oauth_issuer setting. No variations in case or formatting are permitted.", "/versions/19/tables/0/rows/7/description": "A space-separated list of the OAuth scopes needed for the server to both authorize the client and authenticate the user. Appropriate values are determined by the authorization server and the OAuth validation module used (see Chapter 50 for more information on validators). This parameter is required.", "/versions/19/tables/0/rows/8/description": "The library to use for validating bearer tokens. If given, the name must exactly match one of the libraries listed in oauth_validator_libraries . This parameter is optional unless oauth_validator_libraries contains more than one library, in which case it is required.", "/versions/19/tables/0/rows/9/description": "Validator modules may define additional configuration options for oauth HBA entries. These validator-specific options are accessible via the validator.* \"namespace\". For example, a module may register the validator.foo and validator.bar options and define their effects on authentication. The name, syntax, and behavior of each option are not determined by PostgreSQL ; consult the documentation for the validator module in use. Warning A limitation of the current implementation is that unrecognized option names will not be caught until connection time. A pg_ctl reload will succeed, but matching connections will fail: LOG: connection received: host=[local] WARNING: unrecognized authentication option name: \"validator.bad\" DETAIL: The installed validator module (\"my_validator\") did not define an option named \"bad\". HINT: All OAuth connections matching this line will fail. Correct the option and reload the server configuration. CONTEXT: line 2 of configuration file \"data/pg_hba.conf\" Use caution when making changes to validator-specific HBA options in production systems.", "/versions/19/tables/0/rows/10/description": "Allows for mapping between OAuth identity provider and database user names. See Section 20.2 for details. If a map is not specified, the user name associated with the token (as determined by the OAuth validator) must exactly match the role name being requested. This parameter is optional.", "/versions/19/tables/0/rows/11/description": "An advanced option which is not intended for common use. When set to 1 , standard user mapping with pg_ident.conf is skipped, and the OAuth validator takes full responsibility for mapping end user identities to database roles. If the validator authorizes the token, the server trusts that the user is allowed to connect under the requested role, and the connection is allowed to proceed regardless of the authentication status of the user. This parameter is incompatible with map . Warning delegate_ident_mapping provides additional flexibility in the design of the authentication system, but it also requires careful implementation of the OAuth validator, which must determine whether the provided token carries sufficient end-user privileges in addition to the standard checks required of all validators. Use with caution."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "e79de96ad00b8e1f9c0ac4466a1b6c2468e68251200206fe4a6de87c7922f7f4"}, "comparison_data": {"method": "oauth", "documented_option_names": ["Authorization Server", "Client", "Issuer", "Provider", "Resource Owner (or End User)", "Resource Server", "delegate_ident_mapping", "issuer", "map", "scope", "validator", "validator. option"]}, "comparison_hash": "3b323f2d0a9d74f2f79fea0f80ab66fdfab3c2168d5218d1323385179a5f579e", "manual_language": "zh"}, "20": {"facts": [{"label": "\u65b9\u6cd5", "value": "oauth"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09", "description": "\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528 \u7ec8\u7aef\u7528\u6237 \u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 psql \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002"}, {"name": "\u5ba2\u6237\u7aef", "description": "\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 psql \uff09\u5728\u8fde\u63a5 PostgreSQL \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002"}, {"name": "\u8d44\u6e90\u670d\u52a1\u5668", "description": "\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 PostgreSQL \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002"}, {"name": "\u63d0\u4f9b\u8005", "description": "\u4e3a\u7279\u5b9a\u5e94\u7528\u5f00\u53d1\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u5382\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u8005\u901a\u5e38\u91c7\u7528\u4e0d\u540c\u7684 OAuth \u5b9e\u73b0\u7ec6\u8282\uff0c\u56e0\u6b64\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u4e0d\u80fd\u4fdd\u8bc1\u8bbf\u95ee\u53e6\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u670d\u52a1\u5668\u3002\u8fd9\u79cd\u201c\u63d0\u4f9b\u8005\u201d\u7528\u6cd5\u4e0d\u662f\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u5b9e\u9645\u4ea4\u6d41\u4e2d\u5e7f\u6cdb\u4f7f\u7528\u3002\u8bf7\u52ff\u5c06\u5176\u4e0e OpenID \u4e2d\u7c7b\u4f3c\u7684\u201c\u8eab\u4efd\u63d0\u4f9b\u8005\uff08Identity Provider\uff09\u201d\u6df7\u6dc6\u3002PostgreSQL \u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u4f7f\u7528 OIDC\u3002"}, {"name": "\u6388\u6743\u670d\u52a1\u5668", "description": "\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002 PostgreSQL \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002"}, {"name": "\u7b7e\u53d1\u8005", "description": "\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 https:// URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002"}, {"name": "issuer", "description": "\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e \u7b7e\u53d1\u8005\u6807\u8bc6\u7b26 \uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002 \u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 /.well-known/openid-configuration \u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c issuer \u672c\u8eab\u5305\u542b /.well-known/ \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002 \u8b66\u544a libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684 oauth_issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002"}, {"name": "scope", "description": "\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1 \u7b2c 50 \u7ae0 \uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator", "description": "\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e oauth_validator_libraries \u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e oauth_validator_libraries \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator. \u9009\u9879", "description": "\u9a8c\u8bc1\u5668\u6a21\u5757\u53ef\u4ee5 \u5b9a\u4e49 \u7528\u4e8e oauth HBA \u6761\u76ee\u7684\u989d\u5916\u914d\u7f6e\u9009\u9879\u3002\u8fd9\u4e9b\u9a8c\u8bc1\u5668\u4e13\u7528\u9009\u9879\u53ef\u901a\u8fc7 validator.* \u8fd9\u4e2a\u201c\u547d\u540d\u7a7a\u95f4\u201d\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u67d0\u4e2a\u6a21\u5757\u53ef\u4ee5\u6ce8\u518c validator.foo \u548c validator.bar \u9009\u9879\uff0c\u5e76\u5b9a\u4e49\u5b83\u4eec\u5bf9\u8ba4\u8bc1\u7684\u5f71\u54cd\u3002 \u6bcf\u4e2a option \u7684\u540d\u79f0\u3001\u8bed\u6cd5\u548c\u884c\u4e3a\u5e76\u4e0d\u7531 PostgreSQL \u51b3\u5b9a\uff1b\u8bf7\u67e5\u9605\u6240\u4f7f\u7528\u9a8c\u8bc1\u5668\u6a21\u5757\u7684\u6587\u6863\u3002 \u8b66\u544a \u5f53\u524d\u5b9e\u73b0\u7684\u4e00\u4e2a\u9650\u5236\u662f\uff0c\u65e0\u6cd5\u8bc6\u522b\u7684 option \u540d\u79f0\u8981\u5230\u8fde\u63a5\u65f6\u624d\u4f1a\u88ab\u53d1\u73b0\u3002 pg_ctl reload \u4f1a\u6210\u529f\uff0c\u4f46\u5339\u914d\u5230\u7684\u8fde\u63a5\u4f1a\u5931\u8d25\uff1a LOG: connection received: host=[local] WARNING: unrecognized authentication option name: \"validator.bad\" DETAIL: The installed validator module (\"my_validator\") did not define an option named \"bad\". HINT: All OAuth connections matching this line will fail. Correct the option and reload the server configuration. CONTEXT: line 2 of configuration file \"data/pg_hba.conf\" \u5728\u751f\u4ea7\u7cfb\u7edf\u4e2d\u4fee\u6539\u9a8c\u8bc1\u5668\u4e13\u7528\u7684 HBA \u9009\u9879\u65f6\u52a1\u5fc5\u8c28\u614e\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002"}, {"name": "delegate_ident_mapping", "description": "\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002 \u5f53\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e pg_ident.conf \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002 \u6b64\u53c2\u6570\u4e0e map \u4e0d\u517c\u5bb9\u3002 \u8b66\u544a delegate_ident_mapping \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684 \u6807\u51c6\u68c0\u67e5 \uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "revision": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "catalog_fingerprint": "398fbb9f262264053c02fbf79f88be0a6770c1473faa6ecd5931d6ec41b8258b", "source_snapshot_utc": "26-Sep-2026 20:22"}, "sources": [{"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/auth-oauth.html", "path": "auth-oauth.html", "label": "PostgreSQL 20 English manual", "sha256": "1043a707d567a599ffe5de7f982ea85235fa85c7b6fb85854abc7d0f69b86e5c", "language": "en", "original_url": "/docs/devel/auth-oauth.html"}, {"url": "https://pg.center/docs/devel/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 20 English manual", "sha256": "cf2069461da3eec62f6fb4e3df8e46fd69ff4b3a2ad059eec355cee256d7996e", "language": "en", "original_url": "/docs/devel/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "oauth", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528\u7b2c\u4e09\u65b9 OAuth 2.0 \u8eab\u4efd\u63d0\u4f9b\u65b9\u8fdb\u884c\u6388\u6743\uff0c\u5e76\u53ef\u9009\u5730\u5b8c\u6210\u8ba4\u8bc1\u3002\u8be6\u7ec6\u4fe1\u606f\u8bf7\u53c2\u89c1 \u7b2c 20.14 \u8282 \u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-OAUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.14.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">OAuth 2.0 \u662f\u4e00\u4e2a\u884c\u4e1a\u6807\u51c6\u6846\u67b6\uff0c\u5b9a\u4e49\u89c1 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6749\" target=\"_top\">RFC 6749</a>\uff0c\u5b83\u5141\u8bb8\u7b2c\u4e09\u65b9\u5e94\u7528\u83b7\u5f97\u5bf9\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u53d7\u9650\u8bbf\u95ee\u3002\u5728\u6784\u5efa <span class=\"productname\">PostgreSQL</span> \u65f6\u5fc5\u987b\u542f\u7528 OAuth \u5ba2\u6237\u7aef\u652f\u6301\uff1b\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u672c\u6587\u6863\u5728\u8ba8\u8bba OAuth \u751f\u6001\u7cfb\u7edf\u65f6\u4f7f\u7528\u4e0b\u5217\u672f\u8bed\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt lang=\"zh\">\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528<span class=\"emphasis\"><em>\u7ec8\u7aef\u7528\u6237</em></span>\u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 <span class=\"application\">psql</span> \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u5ba2\u6237\u7aef</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 <span class=\"application\">psql</span>\uff09\u5728\u8fde\u63a5 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u8d44\u6e90\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u63d0\u4f9b\u8005</dt>\n<dd>\n<p lang=\"zh\">\u4e3a\u67d0\u4e2a\u5e94\u7528\u5f00\u53d1\u548c/\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u4f9b\u5e94\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u65b9\u901a\u5e38\u4f1a\u4e3a\u5404\u81ea\u7684 OAuth \u7cfb\u7edf\u9009\u62e9\u4e0d\u540c\u7684\u5b9e\u73b0\u7ec6\u8282\uff1b\u4e00\u4e2a\u63d0\u4f9b\u65b9\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u5e76\u4e0d\u80fd\u4fdd\u8bc1\u53ef\u4ee5\u8bbf\u95ee\u53e6\u4e00\u63d0\u4f9b\u65b9\u7684\u670d\u52a1\u5668\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u5bf9\u201c\u63d0\u4f9b\u65b9\u201d\u4e00\u8bcd\u7684\u4f7f\u7528\u5e76\u975e\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u53e3\u8bed\u4e2d\u4f3c\u4e4e\u5f88\u5e38\u89c1\u3002\uff08\u4e0d\u8981\u5c06\u5b83\u4e0e OpenID \u4e2d\u76f8\u8fd1\u7684\u672f\u8bed\u201cIdentity Provider\u201d\u6df7\u6dc6\u3002\u867d\u7136 <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u4fdd\u6301\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u5e76\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u5fc5\u987b\u4f7f\u7528 OIDC\u3002\uff09</p>\n</dd>\n<dt lang=\"zh\">\u6388\u6743\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002<span class=\"productname\">PostgreSQL</span> \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\"><span class=\"term\" id=\"AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005</span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 <code class=\"literal\">https://</code> URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\" lang=\"zh\">\u6ce8\u610f</h3>\n<p lang=\"zh\">\u5bf9\u4e8e\u5c0f\u578b\u90e8\u7f72\u6765\u8bf4\uff0c\u201c\u63d0\u4f9b\u65b9\u201d\u3001\u201c\u6388\u6743\u670d\u52a1\u5668\u201d\u548c\u201c\u7b7e\u53d1\u8005\u201d\u4e4b\u95f4\u53ef\u80fd\u5e76\u6ca1\u6709\u6709\u610f\u4e49\u7684\u533a\u522b\u3002\u7136\u800c\u5728\u66f4\u590d\u6742\u7684\u90e8\u7f72\u4e2d\uff0c\u5b83\u4eec\u4e4b\u95f4\u53ef\u80fd\u662f\u4e00\u4e2a\u5bf9\u591a\u4e2a\uff08\u751a\u81f3\u591a\u4e2a\u5bf9\u591a\u4e2a\uff09\u7684\u5173\u7cfb\uff1a\u67d0\u4e2a\u63d0\u4f9b\u65b9\u53ef\u80fd\u628a\u591a\u4e2a\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u79df\u7ed9\u4e0d\u540c\u79df\u6237\uff0c\u7136\u540e\u518d\u63d0\u4f9b\u591a\u4e2a\u6388\u6743\u670d\u52a1\u5668\u4e0e\u5176\u5ba2\u6237\u7aef\u4ea4\u4e92\uff0c\u800c\u8fd9\u4e9b\u6388\u6743\u670d\u52a1\u5668\u652f\u6301\u7684\u7279\u6027\u96c6\u5408\u4e5f\u53ef\u80fd\u5404\u4e0d\u76f8\u540c\u3002</p>\n</div>\n<p lang=\"zh\"><span class=\"productname\">PostgreSQL</span> \u652f\u6301\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6750\" target=\"_top\">RFC 6750</a> \u4e2d\u5b9a\u4e49\u7684 Bearer \u4ee4\u724c\uff0c\u8fd9\u662f\u4e00\u7c7b\u7528\u4e8e OAuth 2.0 \u7684\u8bbf\u95ee\u4ee4\u724c\uff0c\u5176\u672c\u4f53\u662f\u4e00\u4e2a\u4e0d\u900f\u660e\u5b57\u7b26\u4e32\u3002\u8bbf\u95ee\u4ee4\u724c\u7684\u683c\u5f0f\u53d6\u51b3\u4e8e\u5177\u4f53\u5b9e\u73b0\uff0c\u7531\u5404\u4e2a\u6388\u6743\u670d\u52a1\u5668\u81ea\u884c\u51b3\u5b9a\u3002</p>\n<p lang=\"zh\">OAuth \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">issuer</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e<a class=\"link\" href=\"/docs/devel/auth-oauth.html#AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26</a>\uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n<p lang=\"zh\">\u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 <code class=\"literal\">/.well-known/openid-configuration</code>\u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c <code class=\"literal\">issuer</code> \u672c\u8eab\u5305\u542b <code class=\"literal\">/.well-known/</code> \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684<a class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER\">oauth_issuer</a>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">scope</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1<a class=\"xref\" href=\"/docs/devel/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u7b2c\u00a050\u00a0\u7ae0</a>\uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">validator</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e<a class=\"xref\" href=\"/docs/devel/runtime-config-connection.html#GUC-OAUTH-VALIDATOR-LIBRARIES\">oauth_validator_libraries</a>\u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e <code class=\"literal\">oauth_validator_libraries</code> \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">validator. \u9009\u9879</dt>\n<dd>\n<p lang=\"zh\">\u9a8c\u8bc1\u5668\u6a21\u5757\u53ef\u4ee5<a class=\"link\" href=\"/docs/devel/oauth-validator-hba.html\" title=\"50.4.\u00a0\u81ea\u5b9a\u4e49 HBA \u9009\u9879\">\u5b9a\u4e49</a>\u7528\u4e8e <code class=\"literal\">oauth</code> HBA \u6761\u76ee\u7684\u989d\u5916\u914d\u7f6e\u9009\u9879\u3002\u8fd9\u4e9b\u9a8c\u8bc1\u5668\u4e13\u7528\u9009\u9879\u53ef\u901a\u8fc7 <code class=\"literal\">validator.*</code> \u8fd9\u4e2a\u201c\u547d\u540d\u7a7a\u95f4\u201d\u8bbf\u95ee\u3002\u4f8b\u5982\uff0c\u67d0\u4e2a\u6a21\u5757\u53ef\u4ee5\u6ce8\u518c <code class=\"literal\">validator.foo</code> \u548c <code class=\"literal\">validator.bar</code> \u9009\u9879\uff0c\u5e76\u5b9a\u4e49\u5b83\u4eec\u5bf9\u8ba4\u8bc1\u7684\u5f71\u54cd\u3002</p>\n<p lang=\"zh\">\u6bcf\u4e2a <em class=\"replaceable\"><code>option</code></em> \u7684\u540d\u79f0\u3001\u8bed\u6cd5\u548c\u884c\u4e3a\u5e76\u4e0d\u7531 <span class=\"productname\">PostgreSQL</span> \u51b3\u5b9a\uff1b\u8bf7\u67e5\u9605\u6240\u4f7f\u7528\u9a8c\u8bc1\u5668\u6a21\u5757\u7684\u6587\u6863\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5f53\u524d\u5b9e\u73b0\u7684\u4e00\u4e2a\u9650\u5236\u662f\uff0c\u65e0\u6cd5\u8bc6\u522b\u7684 <em class=\"replaceable\"><code>option</code></em> \u540d\u79f0\u8981\u5230\u8fde\u63a5\u65f6\u624d\u4f1a\u88ab\u53d1\u73b0\u3002<code class=\"literal\">pg_ctl reload</code> \u4f1a\u6210\u529f\uff0c\u4f46\u5339\u914d\u5230\u7684\u8fde\u63a5\u4f1a\u5931\u8d25\uff1a</p>\n<pre class=\"programlisting\">LOG:  connection received: host=[local]\nWARNING:  unrecognized authentication option name: \"validator.bad\"\nDETAIL:  The installed validator module (\"my_validator\") did not define an option named \"bad\".\nHINT:  All OAuth connections matching this line will fail. Correct the option and reload the server configuration.\nCONTEXT:  line 2 of configuration file \"data/pg_hba.conf\"\n</pre>\n<p lang=\"zh\">\u5728\u751f\u4ea7\u7cfb\u7edf\u4e2d\u4fee\u6539\u9a8c\u8bc1\u5668\u4e13\u7528\u7684 HBA \u9009\u9879\u65f6\u52a1\u5fc5\u8c28\u614e\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/devel/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\" id=\"AUTH-OAUTH-DELEGATE-IDENT-MAPPING\"><code class=\"literal\">delegate_ident_mapping</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002</p>\n<p lang=\"zh\">\u5f53\u8bbe\u7f6e\u4e3a <code class=\"literal\">1</code> \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e <code class=\"filename\">pg_ident.conf</code> \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002</p>\n<p lang=\"zh\">\u6b64\u53c2\u6570\u4e0e <code class=\"literal\">map</code> \u4e0d\u517c\u5bb9\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\"><code class=\"literal\">delegate_ident_mapping</code> \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684<a class=\"link\" href=\"/docs/devel/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u6807\u51c6\u68c0\u67e5</a>\uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002</p>\n</div>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/devel/auth-oauth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/auth-oauth.html", "method": "same-major semantic node", "sha256": "6753b7886aaed5e53fb94291da1a444b25f7b5f6b86b4928f37aa7c0f74be583", "language": "zh", "matched_nodes": ["#AUTH-OAUTH/div[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[11]", "#AUTH-OAUTH/div[4]/dl[0]/dd[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[3]", "#AUTH-OAUTH/div[4]/dl[0]/dd[5]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[9]", "#AUTH-OAUTH/div[4]/dl[0]/dt[10]", "#AUTH-OAUTH/div[5]/h3[0]", "#AUTH-OAUTH/div[5]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/div[3]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[11]/p[2]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/h3[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[5]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/div[2]/p[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]", "#AUTH-OAUTH/p[2]", "#AUTH-OAUTH/p[3]", "#AUTH-OAUTH/p[6]", "#AUTH-OAUTH/p[7]"]}, {"url": "/docs/devel/auth-pg-hba-conf.html", "method": "same-major semantic node", "sha256": "118eb69861b21d69aaab6c18fe17f8af8058c5ceb3b247bc80cbe2087c81eb01", "language": "zh", "matched_nodes": ["#AUTH-PG-HBA-CONF/div[12]/dl[0]/dd[21]/div[1]/dl[0]/dd[27]"]}], "language": "zh", "original_text": {"/summary": "Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.14 for details.", "/category": "Authentication and access control", "/versions/20/description/0": "Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.14 for details.", "/versions/20/facts/0/label": "Method", "/versions/20/facts/1/label": "Configuration", "/versions/20/facts/2/label": "Inventory", "/versions/20/facts/2/value": "User-visible source authentication method", "/versions/20/tables/0/title": "Documented method options and alternatives", "/versions/20/tables/0/rows/0/name": "Resource Owner (or End User)", "/versions/20/tables/0/rows/1/name": "Client", "/versions/20/tables/0/rows/2/name": "Resource Server", "/versions/20/tables/0/rows/3/name": "Provider", "/versions/20/tables/0/rows/4/name": "Authorization Server", "/versions/20/tables/0/rows/5/name": "Issuer", "/versions/20/tables/0/rows/9/name": "validator. option", "/versions/20/tables/0/columns/0/label": "Option or term", "/versions/20/tables/0/columns/1/label": "Meaning", "/versions/20/tables/0/rows/0/description": "The user or system who owns protected resources and can grant access to them. This documentation also uses the term end user when the resource owner is a person. When you use psql to connect to the database using OAuth, you are the resource owner/end user.", "/versions/20/tables/0/rows/1/description": "The system which accesses the protected resources using access tokens. Applications using libpq, such as psql , are the OAuth clients when connecting to a PostgreSQL cluster.", "/versions/20/tables/0/rows/2/description": "The system hosting the protected resources which are accessed by the client. The PostgreSQL cluster being connected to is the resource server.", "/versions/20/tables/0/rows/3/description": "The organization, product vendor, or other entity which develops and/or administers the OAuth authorization servers and clients for a given application. Different providers typically choose different implementation details for their OAuth systems; a client of one provider is not generally guaranteed to have access to the servers of another. This use of the term \"provider\" is not standard, but it seems to be in wide use colloquially. (It should not be confused with OpenID's similar term \"Identity Provider\". While the implementation of OAuth in PostgreSQL is intended to be interoperable and compatible with OpenID Connect/OIDC, it is not itself an OIDC client and does not require its use.)", "/versions/20/tables/0/rows/4/description": "The system which receives requests from, and issues access tokens to, the client after the authenticated resource owner has given approval. PostgreSQL does not provide an authorization server; it is the responsibility of the OAuth provider.", "/versions/20/tables/0/rows/5/description": "An identifier for an authorization server, printed as an https:// URL, which provides a trusted \"namespace\" for OAuth clients and applications. The issuer identifier allows a single authorization server to talk to the clients of mutually untrusting entities, as long as they maintain separate issuers.", "/versions/20/tables/0/rows/6/description": "An HTTPS URL which is either the exact issuer identifier of the authorization server, as defined by its discovery document, or a well-known URI that points directly to that discovery document. This parameter is required. When an OAuth client connects to the server, a URL for the discovery document will be constructed using the issuer identifier. By default, this URL uses the conventions of OpenID Connect Discovery: the path /.well-known/openid-configuration will be appended to the end of the issuer identifier. Alternatively, if the issuer contains a /.well-known/ path segment, that URL will be provided to the client as-is. Warning The OAuth client in libpq requires the server's issuer setting to exactly match the issuer identifier which is provided in the discovery document, which must in turn match the client's oauth_issuer setting. No variations in case or formatting are permitted.", "/versions/20/tables/0/rows/7/description": "A space-separated list of the OAuth scopes needed for the server to both authorize the client and authenticate the user. Appropriate values are determined by the authorization server and the OAuth validation module used (see Chapter 50 for more information on validators). This parameter is required.", "/versions/20/tables/0/rows/8/description": "The library to use for validating bearer tokens. If given, the name must exactly match one of the libraries listed in oauth_validator_libraries . This parameter is optional unless oauth_validator_libraries contains more than one library, in which case it is required.", "/versions/20/tables/0/rows/9/description": "Validator modules may define additional configuration options for oauth HBA entries. These validator-specific options are accessible via the validator.* \"namespace\". For example, a module may register the validator.foo and validator.bar options and define their effects on authentication. The name, syntax, and behavior of each option are not determined by PostgreSQL ; consult the documentation for the validator module in use. Warning A limitation of the current implementation is that unrecognized option names will not be caught until connection time. A pg_ctl reload will succeed, but matching connections will fail: LOG: connection received: host=[local] WARNING: unrecognized authentication option name: \"validator.bad\" DETAIL: The installed validator module (\"my_validator\") did not define an option named \"bad\". HINT: All OAuth connections matching this line will fail. Correct the option and reload the server configuration. CONTEXT: line 2 of configuration file \"data/pg_hba.conf\" Use caution when making changes to validator-specific HBA options in production systems.", "/versions/20/tables/0/rows/10/description": "Allows for mapping between OAuth identity provider and database user names. See Section 20.2 for details. If a map is not specified, the user name associated with the token (as determined by the OAuth validator) must exactly match the role name being requested. This parameter is optional.", "/versions/20/tables/0/rows/11/description": "An advanced option which is not intended for common use. When set to 1 , standard user mapping with pg_ident.conf is skipped, and the OAuth validator takes full responsibility for mapping end user identities to database roles. If the validator authorizes the token, the server trusts that the user is allowed to connect under the requested role, and the connection is allowed to proceed regardless of the authentication status of the user. This parameter is incompatible with map . Warning delegate_ident_mapping provides additional flexibility in the design of the authentication system, but it also requires careful implementation of the OAuth validator, which must determine whether the provided token carries sufficient end-user privileges in addition to the standard checks required of all validators. Use with caution."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "e9cba4e6c80ef6ef1be35596cc3ee0c88d6244a126f721828d7a33decfce472a"}, "comparison_data": {"method": "oauth", "documented_option_names": ["Authorization Server", "Client", "Issuer", "Provider", "Resource Owner (or End User)", "Resource Server", "delegate_ident_mapping", "issuer", "map", "scope", "validator", "validator. option"]}, "comparison_hash": "3b323f2d0a9d74f2f79fea0f80ab66fdfab3c2168d5218d1323385179a5f579e", "manual_language": "zh"}}}, "snapshot": {"facts": [{"label": "\u65b9\u6cd5", "value": "oauth"}, {"label": "\u914d\u7f6e", "value": "pg_hba.conf"}, {"label": "\u6e05\u5355", "value": "\u7528\u6237\u53ef\u89c1\u7684\u6e90\u7801\u8ba4\u8bc1\u65b9\u6cd5"}], "tables": [{"key": "method-options", "rows": [{"name": "\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09", "description": "\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528 \u7ec8\u7aef\u7528\u6237 \u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 psql \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002"}, {"name": "\u5ba2\u6237\u7aef", "description": "\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 psql \uff09\u5728\u8fde\u63a5 PostgreSQL \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002"}, {"name": "\u8d44\u6e90\u670d\u52a1\u5668", "description": "\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 PostgreSQL \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002"}, {"name": "\u63d0\u4f9b\u8005", "description": "\u4e3a\u7279\u5b9a\u5e94\u7528\u5f00\u53d1\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u5382\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u8005\u901a\u5e38\u91c7\u7528\u4e0d\u540c\u7684 OAuth \u5b9e\u73b0\u7ec6\u8282\uff0c\u56e0\u6b64\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u4e0d\u80fd\u4fdd\u8bc1\u8bbf\u95ee\u53e6\u4e00\u4e2a\u63d0\u4f9b\u8005\u7684\u670d\u52a1\u5668\u3002\u8fd9\u79cd\u201c\u63d0\u4f9b\u8005\u201d\u7528\u6cd5\u4e0d\u662f\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u5b9e\u9645\u4ea4\u6d41\u4e2d\u5e7f\u6cdb\u4f7f\u7528\u3002\u8bf7\u52ff\u5c06\u5176\u4e0e OpenID \u4e2d\u7c7b\u4f3c\u7684\u201c\u8eab\u4efd\u63d0\u4f9b\u8005\uff08Identity Provider\uff09\u201d\u6df7\u6dc6\u3002PostgreSQL \u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u4f7f\u7528 OIDC\u3002"}, {"name": "\u6388\u6743\u670d\u52a1\u5668", "description": "\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002 PostgreSQL \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002"}, {"name": "\u7b7e\u53d1\u8005", "description": "\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 https:// URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002"}, {"name": "issuer", "description": "\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e \u7b7e\u53d1\u8005\u6807\u8bc6\u7b26 \uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002 \u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 /.well-known/openid-configuration \u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c issuer \u672c\u8eab\u5305\u542b /.well-known/ \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002 \u8b66\u544a libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684 oauth_issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002"}, {"name": "scope", "description": "\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1 \u7b2c 50 \u7ae0 \uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "validator", "description": "\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e oauth_validator_libraries \u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e oauth_validator_libraries \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002"}, {"name": "map", "description": "\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1 \u7b2c 20.2 \u8282 \u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002"}, {"name": "delegate_ident_mapping", "description": "\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002 \u5f53\u8bbe\u7f6e\u4e3a 1 \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e pg_ident.conf \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002 \u6b64\u53c2\u6570\u4e0e map \u4e0d\u517c\u5bb9\u3002 \u8b66\u544a delegate_ident_mapping \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684 \u6807\u51c6\u68c0\u67e5 \uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002"}], "title": "\u624b\u518c\u4e2d\u7684\u65b9\u6cd5\u9009\u9879\u4e0e\u66ff\u4ee3\u65b9\u5f0f", "columns": [{"key": "name", "label": "\u9009\u9879\u6216\u672f\u8bed"}, {"key": "description", "label": "\u542b\u4e49"}]}], "aliases": [], "related": [], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "revision": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f", "catalog_fingerprint": "65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502"}, "sources": [{"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "Matching PostgreSQL source archive", "sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/auth-oauth.html", "path": "auth-oauth.html", "label": "PostgreSQL 18 English manual", "sha256": "1e2e63530e79522cd93d2c34bc34a464927dbe46de9b01cdbf324648f1adda8d", "language": "en", "original_url": "/docs/18/auth-oauth.html"}, {"url": "https://pg.center/docs/18/auth-pg-hba-conf.html", "path": "auth-pg-hba-conf.html", "label": "PostgreSQL 18 English manual", "sha256": "6340d4abea2e0a3482afc31bcd1599a0fa10dc28a6f1e05d79ba831e2dd0b4c9", "language": "en", "original_url": "/docs/18/auth-pg-hba-conf.html"}], "sections": [], "signature": "", "attributes": {"method": "oauth", "inventory": "User-visible source authentication method", "configuration": "pg_hba.conf"}, "description": ["\u4f7f\u7528\u7b2c\u4e09\u65b9 OAuth 2.0 \u8eab\u4efd\u63d0\u4f9b\u65b9\u8fdb\u884c\u6388\u6743\uff0c\u5e76\u53ef\u9009\u5730\u5b8c\u6210\u8ba4\u8bc1\u3002\u8be6\u7ec6\u4fe1\u606f\u8bf7\u53c2\u89c1 \u7b2c 20.15 \u8282 \u3002"], "manual_html": "<div class=\"sect1\" id=\"AUTH-OAUTH\">\n<div class=\"titlepage\">\n<div>\n<div>\n<h2 class=\"title\" lang=\"zh\">\n<div>\n<div>\n<h2 class=\"title\" style=\"clear: both\">20.15.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1 </h2>\n</div>\n</div>\n</h2>\n</div>\n</div>\n</div>\n<p lang=\"zh\">OAuth 2.0 \u662f\u4e00\u4e2a\u884c\u4e1a\u6807\u51c6\u6846\u67b6\uff0c\u5b9a\u4e49\u89c1 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6749\" target=\"_top\">RFC 6749</a>\uff0c\u5b83\u5141\u8bb8\u7b2c\u4e09\u65b9\u5e94\u7528\u83b7\u5f97\u5bf9\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u53d7\u9650\u8bbf\u95ee\u3002\u5728\u6784\u5efa <span class=\"productname\">PostgreSQL</span> \u65f6\u5fc5\u987b\u542f\u7528 OAuth \u5ba2\u6237\u7aef\u652f\u6301\uff1b\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/installation.html\" title=\"\u7b2c\u00a017\u00a0\u7ae0\u00a0\u4ece\u6e90\u4ee3\u7801\u5b89\u88c5\">\u7b2c\u00a017\u00a0\u7ae0</a>\u3002</p>\n<p lang=\"zh\">\u672c\u6587\u6863\u5728\u8ba8\u8bba OAuth \u751f\u6001\u7cfb\u7edf\u65f6\u4f7f\u7528\u4e0b\u5217\u672f\u8bed\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt lang=\"zh\">\u8d44\u6e90\u6240\u6709\u8005\uff08\u6216\u6700\u7ec8\u7528\u6237\uff09</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u62e5\u6709\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u80fd\u591f\u6388\u4e88\u8bbf\u95ee\u6743\u9650\u7684\u7528\u6237\u6216\u7cfb\u7edf\u3002\u5f53\u8d44\u6e90\u6240\u6709\u8005\u662f\u4eba\u65f6\uff0c\u672c\u6587\u6863\u4e5f\u4f7f\u7528<span class=\"emphasis\"><em>\u7ec8\u7aef\u7528\u6237</em></span>\u4e00\u8bcd\u3002\u5f53\u4f60\u4f7f\u7528 <span class=\"application\">psql</span> \u901a\u8fc7 OAuth \u8fde\u63a5\u6570\u636e\u5e93\u65f6\uff0c\u4f60\u5c31\u662f\u8d44\u6e90\u6240\u6709\u8005/\u7ec8\u7aef\u7528\u6237\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u5ba2\u6237\u7aef</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4f7f\u7528\u8bbf\u95ee\u4ee4\u724c\u8bbf\u95ee\u53d7\u4fdd\u62a4\u8d44\u6e90\u7684\u7cfb\u7edf\u3002\u4f7f\u7528 libpq \u7684\u5e94\u7528\uff08\u4f8b\u5982 <span class=\"application\">psql</span>\uff09\u5728\u8fde\u63a5 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u65f6\uff0c\u5c31\u662f OAuth \u5ba2\u6237\u7aef\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u8d44\u6e90\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6258\u7ba1\u53d7\u4fdd\u62a4\u8d44\u6e90\u5e76\u4f9b\u5ba2\u6237\u7aef\u8bbf\u95ee\u7684\u7cfb\u7edf\u3002\u88ab\u8fde\u63a5\u7684 <span class=\"productname\">PostgreSQL</span> \u96c6\u7c07\u5c31\u662f\u8d44\u6e90\u670d\u52a1\u5668\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\">\u63d0\u4f9b\u8005</dt>\n<dd>\n<p lang=\"zh\">\u4e3a\u67d0\u4e2a\u5e94\u7528\u5f00\u53d1\u548c/\u6216\u7ba1\u7406 OAuth \u6388\u6743\u670d\u52a1\u5668\u4e0e\u5ba2\u6237\u7aef\u7684\u7ec4\u7ec7\u3001\u4ea7\u54c1\u4f9b\u5e94\u5546\u6216\u5176\u4ed6\u5b9e\u4f53\u3002\u4e0d\u540c\u63d0\u4f9b\u65b9\u901a\u5e38\u4f1a\u4e3a\u5404\u81ea\u7684 OAuth \u7cfb\u7edf\u9009\u62e9\u4e0d\u540c\u7684\u5b9e\u73b0\u7ec6\u8282\uff1b\u4e00\u4e2a\u63d0\u4f9b\u65b9\u7684\u5ba2\u6237\u7aef\u901a\u5e38\u5e76\u4e0d\u80fd\u4fdd\u8bc1\u53ef\u4ee5\u8bbf\u95ee\u53e6\u4e00\u63d0\u4f9b\u65b9\u7684\u670d\u52a1\u5668\u3002</p>\n<p lang=\"zh\">\u8fd9\u91cc\u5bf9\u201c\u63d0\u4f9b\u65b9\u201d\u4e00\u8bcd\u7684\u4f7f\u7528\u5e76\u975e\u6807\u51c6\u672f\u8bed\uff0c\u4f46\u5728\u53e3\u8bed\u4e2d\u4f3c\u4e4e\u5f88\u5e38\u89c1\u3002\uff08\u4e0d\u8981\u5c06\u5b83\u4e0e OpenID \u4e2d\u76f8\u8fd1\u7684\u672f\u8bed\u201cIdentity Provider\u201d\u6df7\u6dc6\u3002\u867d\u7136 <span class=\"productname\">PostgreSQL</span> \u4e2d\u7684 OAuth \u5b9e\u73b0\u65e8\u5728\u4e0e OpenID Connect/OIDC \u4e92\u64cd\u4f5c\u5e76\u4fdd\u6301\u517c\u5bb9\uff0c\u4f46\u5b83\u672c\u8eab\u5e76\u4e0d\u662f OIDC \u5ba2\u6237\u7aef\uff0c\u4e5f\u4e0d\u8981\u6c42\u5fc5\u987b\u4f7f\u7528 OIDC\u3002\uff09</p>\n</dd>\n<dt lang=\"zh\">\u6388\u6743\u670d\u52a1\u5668</dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5728\u8d44\u6e90\u6240\u6709\u8005\u5b8c\u6210\u8ba4\u8bc1\u5e76\u7ed9\u51fa\u6279\u51c6\u4e4b\u540e\uff0c\u63a5\u6536\u5ba2\u6237\u7aef\u8bf7\u6c42\u5e76\u5411\u5176\u53d1\u653e\u8bbf\u95ee\u4ee4\u724c\u7684\u7cfb\u7edf\u3002<span class=\"productname\">PostgreSQL</span> \u4e0d\u63d0\u4f9b\u6388\u6743\u670d\u52a1\u5668\uff1b\u8fd9\u5c5e\u4e8e OAuth \u63d0\u4f9b\u65b9\u7684\u804c\u8d23\u3002</p>\n</p>\n</dd>\n<dt lang=\"zh\"><span class=\"term\" id=\"AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005</span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u6388\u6743\u670d\u52a1\u5668\u7684\u4e00\u4e2a\u6807\u8bc6\u7b26\uff0c\u4ee5 <code class=\"literal\">https://</code> URL \u5f62\u5f0f\u51fa\u73b0\uff0c\u4e3a OAuth \u5ba2\u6237\u7aef\u548c\u5e94\u7528\u63d0\u4f9b\u4e00\u4e2a\u53ef\u4fe1\u7684\u201c\u547d\u540d\u7a7a\u95f4\u201d\u3002\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u4f7f\u5f97\u5355\u4e2a\u6388\u6743\u670d\u52a1\u5668\u80fd\u591f\u540c\u65f6\u4e0e\u5f7c\u6b64\u4e92\u4e0d\u4fe1\u4efb\u7684\u5b9e\u4f53\u7684\u5ba2\u6237\u7aef\u901a\u4fe1\uff0c\u53ea\u8981\u8fd9\u4e9b\u5b9e\u4f53\u7ef4\u62a4\u5404\u81ea\u72ec\u7acb\u7684\u7b7e\u53d1\u8005\u5373\u53ef\u3002</p>\n</p>\n</dd>\n</dl>\n</div>\n<div class=\"note\">\n<h3 class=\"title\" lang=\"zh\">\u6ce8\u610f</h3>\n<p lang=\"zh\">\u5bf9\u4e8e\u5c0f\u578b\u90e8\u7f72\u6765\u8bf4\uff0c\u201c\u63d0\u4f9b\u65b9\u201d\u3001\u201c\u6388\u6743\u670d\u52a1\u5668\u201d\u548c\u201c\u7b7e\u53d1\u8005\u201d\u4e4b\u95f4\u53ef\u80fd\u5e76\u6ca1\u6709\u6709\u610f\u4e49\u7684\u533a\u522b\u3002\u7136\u800c\u5728\u66f4\u590d\u6742\u7684\u90e8\u7f72\u4e2d\uff0c\u5b83\u4eec\u4e4b\u95f4\u53ef\u80fd\u662f\u4e00\u4e2a\u5bf9\u591a\u4e2a\uff08\u751a\u81f3\u591a\u4e2a\u5bf9\u591a\u4e2a\uff09\u7684\u5173\u7cfb\uff1a\u67d0\u4e2a\u63d0\u4f9b\u65b9\u53ef\u80fd\u628a\u591a\u4e2a\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u79df\u7ed9\u4e0d\u540c\u79df\u6237\uff0c\u7136\u540e\u518d\u63d0\u4f9b\u591a\u4e2a\u6388\u6743\u670d\u52a1\u5668\u4e0e\u5176\u5ba2\u6237\u7aef\u4ea4\u4e92\uff0c\u800c\u8fd9\u4e9b\u6388\u6743\u670d\u52a1\u5668\u652f\u6301\u7684\u7279\u6027\u96c6\u5408\u4e5f\u53ef\u80fd\u5404\u4e0d\u76f8\u540c\u3002</p>\n</div>\n<p lang=\"zh\"><span class=\"productname\">PostgreSQL</span> \u652f\u6301\u5728 <a class=\"ulink\" href=\"https://datatracker.ietf.org/doc/html/rfc6750\" target=\"_top\">RFC 6750</a> \u4e2d\u5b9a\u4e49\u7684 Bearer \u4ee4\u724c\uff0c\u8fd9\u662f\u4e00\u7c7b\u7528\u4e8e OAuth 2.0 \u7684\u8bbf\u95ee\u4ee4\u724c\uff0c\u5176\u672c\u4f53\u662f\u4e00\u4e2a\u4e0d\u900f\u660e\u5b57\u7b26\u4e32\u3002\u8bbf\u95ee\u4ee4\u724c\u7684\u683c\u5f0f\u53d6\u51b3\u4e8e\u5177\u4f53\u5b9e\u73b0\uff0c\u7531\u5404\u4e2a\u6388\u6743\u670d\u52a1\u5668\u81ea\u884c\u51b3\u5b9a\u3002</p>\n<p lang=\"zh\">OAuth \u652f\u6301\u4e0b\u5217\u914d\u7f6e\u9009\u9879\uff1a</p>\n<div class=\"variablelist\">\n<dl class=\"variablelist\">\n<dt><span class=\"term\"><code class=\"literal\">issuer</code></span></dt>\n<dd>\n<p lang=\"zh\">\u4e00\u4e2a HTTPS URL\uff0c\u5b83\u8981\u4e48\u662f\u6388\u6743\u670d\u52a1\u5668\u53d1\u73b0\u6587\u6863\u6240\u5b9a\u4e49\u7684\u7cbe\u786e<a class=\"link\" href=\"/docs/18/auth-oauth.html#AUTH-OAUTH-ISSUER\">\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26</a>\uff0c\u8981\u4e48\u662f\u4e00\u4e2a\u76f4\u63a5\u6307\u5411\u8be5\u53d1\u73b0\u6587\u6863\u7684 well-known URI\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n<p lang=\"zh\">\u5f53 OAuth \u5ba2\u6237\u7aef\u8fde\u63a5\u5230\u670d\u52a1\u5668\u65f6\uff0c\u4f1a\u57fa\u4e8e\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u6784\u9020\u53d1\u73b0\u6587\u6863\u7684 URL\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8be5 URL \u91c7\u7528 OpenID Connect Discovery \u7684\u7ea6\u5b9a\uff1a\u4f1a\u5728\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u672b\u5c3e\u8ffd\u52a0\u8def\u5f84 <code class=\"literal\">/.well-known/openid-configuration</code>\u3002\u53e6\u4e00\u79cd\u60c5\u51b5\u662f\uff0c\u5982\u679c <code class=\"literal\">issuer</code> \u672c\u8eab\u5305\u542b <code class=\"literal\">/.well-known/</code> \u8def\u5f84\u6bb5\uff0c\u90a3\u4e48\u8be5 URL \u4f1a\u539f\u6837\u63d0\u4f9b\u7ed9\u5ba2\u6237\u7aef\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">libpq \u4e2d\u7684 OAuth \u5ba2\u6237\u7aef\u8981\u6c42\u670d\u52a1\u5668\u7684 issuer \u8bbe\u7f6e\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u4e2d\u63d0\u4f9b\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u800c\u8be5\u6807\u8bc6\u7b26\u53c8\u5fc5\u987b\u4e0e\u5ba2\u6237\u7aef\u7684<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER\">oauth_issuer</a>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002\u4e0d\u5141\u8bb8\u5927\u5c0f\u5199\u6216\u683c\u5f0f\u4e0a\u7684\u4efb\u4f55\u5dee\u5f02\u3002</p>\n</div>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">scope</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u4e00\u4e2a\u4ee5\u7a7a\u683c\u5206\u9694\u7684 OAuth \u6388\u6743\u8303\u56f4\u5217\u8868\uff0c\u670d\u52a1\u5668\u9700\u8981\u501f\u6b64\u65e2\u80fd\u6388\u6743\u5ba2\u6237\u7aef\uff0c\u53c8\u80fd\u8ba4\u8bc1\u7528\u6237\u3002\u5408\u9002\u7684\u53d6\u503c\u7531\u6388\u6743\u670d\u52a1\u5668\u4ee5\u53ca\u6240\u4f7f\u7528\u7684 OAuth \u9a8c\u8bc1\u6a21\u5757\u51b3\u5b9a\uff08\u5173\u4e8e\u9a8c\u8bc1\u5668\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u89c1<a class=\"xref\" href=\"/docs/18/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u7b2c\u00a050\u00a0\u7ae0</a>\uff09\u3002\u6b64\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">validator</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u7528\u4e8e\u9a8c\u8bc1 Bearer \u4ee4\u724c\u7684\u5e93\u3002\u5982\u679c\u6307\u5b9a\uff0c\u5176\u540d\u79f0\u5fc5\u987b\u4e0e<a class=\"xref\" href=\"/docs/18/runtime-config-connection.html#GUC-OAUTH-VALIDATOR-LIBRARIES\">oauth_validator_libraries</a>\u4e2d\u5217\u51fa\u7684\u67d0\u4e2a\u5e93\u5b8c\u5168\u5339\u914d\u3002\u9664\u975e <code class=\"literal\">oauth_validator_libraries</code> \u4e2d\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5426\u5219\u8be5\u53c2\u6570\u662f\u53ef\u9009\u7684\uff1b\u5982\u679c\u5305\u542b\u591a\u4e2a\u5e93\uff0c\u5219\u8be5\u53c2\u6570\u4e3a\u5fc5\u9700\u9879\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\"><code class=\"literal\">map</code></span></dt>\n<dd>\n<p lang=\"zh\">\n<p>\u5141\u8bb8\u5728 OAuth \u8eab\u4efd\u63d0\u4f9b\u65b9\u7528\u6237\u540d\u548c\u6570\u636e\u5e93\u7528\u6237\u540d\u4e4b\u95f4\u5efa\u7acb\u6620\u5c04\u3002\u8be6\u89c1<a class=\"xref\" href=\"/docs/18/auth-username-maps.html\" title=\"20.2.\u00a0\u7528\u6237\u540d\u6620\u5c04\">\u7b2c\u00a020.2\u00a0\u8282</a>\u3002\u5982\u679c\u672a\u6307\u5b9a\u6620\u5c04\uff0c\u5219\u4e0e\u4ee4\u724c\u5173\u8054\u7684\u7528\u6237\u540d\uff08\u7531 OAuth \u9a8c\u8bc1\u5668\u51b3\u5b9a\uff09\u5fc5\u987b\u4e0e\u8bf7\u6c42\u7684\u89d2\u8272\u540d\u5b8c\u5168\u4e00\u81f4\u3002\u6b64\u53c2\u6570\u662f\u53ef\u9009\u7684\u3002</p>\n</p>\n</dd>\n<dt><span class=\"term\" id=\"AUTH-OAUTH-DELEGATE-IDENT-MAPPING\"><code class=\"literal\">delegate_ident_mapping</code></span></dt>\n<dd>\n<p lang=\"zh\">\u8fd9\u662f\u4e00\u4e2a\u9ad8\u7ea7\u9009\u9879\uff0c\u4e0d\u9002\u5408\u5e38\u89c4\u4f7f\u7528\u3002</p>\n<p lang=\"zh\">\u5f53\u8bbe\u7f6e\u4e3a <code class=\"literal\">1</code> \u65f6\uff0c\u4f1a\u8df3\u8fc7\u57fa\u4e8e <code class=\"filename\">pg_ident.conf</code> \u7684\u6807\u51c6\u7528\u6237\u6620\u5c04\uff0c\u800c\u7531 OAuth \u9a8c\u8bc1\u5668\u5b8c\u5168\u8d1f\u8d23\u628a\u7ec8\u7aef\u7528\u6237\u8eab\u4efd\u6620\u5c04\u5230\u6570\u636e\u5e93\u89d2\u8272\u3002\u5982\u679c\u9a8c\u8bc1\u5668\u6388\u6743\u8be5\u4ee4\u724c\uff0c\u670d\u52a1\u5668\u5c31\u4f1a\u4fe1\u4efb\u8be5\u7528\u6237\u88ab\u5141\u8bb8\u4ee5\u8bf7\u6c42\u7684\u89d2\u8272\u8fdb\u884c\u8fde\u63a5\uff0c\u5e76\u4e14\u65e0\u8bba\u8be5\u7528\u6237\u81ea\u8eab\u7684\u8ba4\u8bc1\u72b6\u6001\u5982\u4f55\uff0c\u8fde\u63a5\u90fd\u5c06\u7ee7\u7eed\u8fdb\u884c\u3002</p>\n<p lang=\"zh\">\u6b64\u53c2\u6570\u4e0e <code class=\"literal\">map</code> \u4e0d\u517c\u5bb9\u3002</p>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\"><code class=\"literal\">delegate_ident_mapping</code> \u4e3a\u8ba4\u8bc1\u7cfb\u7edf\u8bbe\u8ba1\u5e26\u6765\u4e86\u989d\u5916\u7075\u6d3b\u6027\uff0c\u4f46\u4e5f\u8981\u6c42\u5bf9 OAuth \u9a8c\u8bc1\u5668\u8fdb\u884c\u8c28\u614e\u5b9e\u73b0\u3002\u9a8c\u8bc1\u5668\u4e0d\u4ec5\u5fc5\u987b\u6267\u884c\u6240\u6709\u9a8c\u8bc1\u5668\u90fd\u9700\u8981\u8fdb\u884c\u7684<a class=\"link\" href=\"/docs/18/oauth-validators.html\" title=\"\u7b2c\u00a050\u00a0\u7ae0\u00a0OAuth \u9a8c\u8bc1\u5668\u6a21\u5757\">\u6807\u51c6\u68c0\u67e5</a>\uff0c\u8fd8\u5fc5\u987b\u5224\u65ad\u6240\u63d0\u4f9b\u7684\u4ee4\u724c\u662f\u5426\u643a\u5e26\u4e86\u8db3\u591f\u7684\u7ec8\u7aef\u7528\u6237\u6743\u9650\u3002\u8bf7\u8c28\u614e\u4f7f\u7528\u3002</p>\n</div>\n</dd>\n</dl>\n</div>\n</div>", "manual_path": "/docs/18/auth-oauth.html", "localization": {"status": "complete", "sources": [{"url": "/docs/18/auth-oauth.html", "method": "same-major semantic node", "sha256": "b43ffd0af2f515aa246019c63c5041fabafd740514ea91eeea7efc7eaec410fc", "language": "zh", "matched_nodes": ["#AUTH-OAUTH/div[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[11]", "#AUTH-OAUTH/div[4]/dl[0]/dd[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[3]", "#AUTH-OAUTH/div[4]/dl[0]/dd[5]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[0]", "#AUTH-OAUTH/div[4]/dl[0]/dd[7]/p[1]", "#AUTH-OAUTH/div[4]/dl[0]/dd[9]", "#AUTH-OAUTH/div[4]/dl[0]/dt[10]", "#AUTH-OAUTH/div[5]/h3[0]", "#AUTH-OAUTH/div[5]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/h3[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/div[2]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[1]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[3]", "#AUTH-OAUTH/div[8]/dl[0]/dd[5]", "#AUTH-OAUTH/div[8]/dl[0]/dd[7]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/div[3]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[0]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[1]", "#AUTH-OAUTH/div[8]/dl[0]/dd[9]/p[2]", "#AUTH-OAUTH/p[2]", "#AUTH-OAUTH/p[3]", "#AUTH-OAUTH/p[6]", "#AUTH-OAUTH/p[7]"]}, {"url": "/docs/18/auth-pg-hba-conf.html", "method": "same-major semantic node", "sha256": "e3184e306644bc82d642725babd6cd8053ae3c71d7590af05a805685dc88491b", "language": "zh", "matched_nodes": ["#AUTH-PG-HBA-CONF/div[12]/dl[0]/dd[21]/div[1]/dl[0]/dd[29]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "Authorize and optionally authenticate using a third-party OAuth 2.0 identity provider. See Section 20.15 for details.", "/versions/18/facts/0/label": "Method", "/versions/18/facts/1/label": "Configuration", "/versions/18/facts/2/label": "Inventory", "/versions/18/facts/2/value": "User-visible source authentication method", "/versions/18/tables/0/title": "Documented method options and alternatives", "/versions/18/tables/0/rows/0/name": "Resource Owner (or End User)", "/versions/18/tables/0/rows/1/name": "Client", "/versions/18/tables/0/rows/2/name": "Resource Server", "/versions/18/tables/0/rows/3/name": "Provider", "/versions/18/tables/0/rows/4/name": "Authorization Server", "/versions/18/tables/0/rows/5/name": "Issuer", "/versions/18/tables/0/columns/0/label": "Option or term", "/versions/18/tables/0/columns/1/label": "Meaning", "/versions/18/tables/0/rows/0/description": "The user or system who owns protected resources and can grant access to them. This documentation also uses the term end user when the resource owner is a person. When you use psql to connect to the database using OAuth, you are the resource owner/end user.", "/versions/18/tables/0/rows/1/description": "The system which accesses the protected resources using access tokens. Applications using libpq, such as psql , are the OAuth clients when connecting to a PostgreSQL cluster.", "/versions/18/tables/0/rows/2/description": "The system hosting the protected resources which are accessed by the client. The PostgreSQL cluster being connected to is the resource server.", "/versions/18/tables/0/rows/3/description": "The organization, product vendor, or other entity which develops and/or administers the OAuth authorization servers and clients for a given application. Different providers typically choose different implementation details for their OAuth systems; a client of one provider is not generally guaranteed to have access to the servers of another. This use of the term \"provider\" is not standard, but it seems to be in wide use colloquially. (It should not be confused with OpenID's similar term \"Identity Provider\". While the implementation of OAuth in PostgreSQL is intended to be interoperable and compatible with OpenID Connect/OIDC, it is not itself an OIDC client and does not require its use.)", "/versions/18/tables/0/rows/4/description": "The system which receives requests from, and issues access tokens to, the client after the authenticated resource owner has given approval. PostgreSQL does not provide an authorization server; it is the responsibility of the OAuth provider.", "/versions/18/tables/0/rows/5/description": "An identifier for an authorization server, printed as an https:// URL, which provides a trusted \"namespace\" for OAuth clients and applications. The issuer identifier allows a single authorization server to talk to the clients of mutually untrusting entities, as long as they maintain separate issuers.", "/versions/18/tables/0/rows/6/description": "An HTTPS URL which is either the exact issuer identifier of the authorization server, as defined by its discovery document, or a well-known URI that points directly to that discovery document. This parameter is required. When an OAuth client connects to the server, a URL for the discovery document will be constructed using the issuer identifier. By default, this URL uses the conventions of OpenID Connect Discovery: the path /.well-known/openid-configuration will be appended to the end of the issuer identifier. Alternatively, if the issuer contains a /.well-known/ path segment, that URL will be provided to the client as-is. Warning The OAuth client in libpq requires the server's issuer setting to exactly match the issuer identifier which is provided in the discovery document, which must in turn match the client's oauth_issuer setting. No variations in case or formatting are permitted.", "/versions/18/tables/0/rows/7/description": "A space-separated list of the OAuth scopes needed for the server to both authorize the client and authenticate the user. Appropriate values are determined by the authorization server and the OAuth validation module used (see Chapter 50 for more information on validators). This parameter is required.", "/versions/18/tables/0/rows/8/description": "The library to use for validating bearer tokens. If given, the name must exactly match one of the libraries listed in oauth_validator_libraries . This parameter is optional unless oauth_validator_libraries contains more than one library, in which case it is required.", "/versions/18/tables/0/rows/9/description": "Allows for mapping between OAuth identity provider and database user names. See Section 20.2 for details. If a map is not specified, the user name associated with the token (as determined by the OAuth validator) must exactly match the role name being requested. This parameter is optional.", "/versions/18/tables/0/rows/10/description": "An advanced option which is not intended for common use. When set to 1 , standard user mapping with pg_ident.conf is skipped, and the OAuth validator takes full responsibility for mapping end user identities to database roles. If the validator authorizes the token, the server trusts that the user is allowed to connect under the requested role, and the connection is allowed to proceed regardless of the authentication status of the user. This parameter is incompatible with map . Warning delegate_ident_mapping provides additional flexibility in the design of the authentication system, but it also requires careful implementation of the OAuth validator, which must determine whether the provided token carries sufficient end-user privileges in addition to the standard checks required of all validators. Use with caution."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "a1031c21e0762550677bc13421c0808cd18feb0ad3b8fa50b6272eadf6d9f8b8"}, "comparison_data": {"method": "oauth", "documented_option_names": ["Authorization Server", "Client", "Issuer", "Provider", "Resource Owner (or End User)", "Resource Server", "delegate_ident_mapping", "issuer", "map", "scope", "validator"]}, "comparison_hash": "614b1b99c2894fb23e3ddaf7706a1e06dd6cc3fd020965f4d8e18ed32ea3a772", "manual_language": "zh"}, "comparison": {"left": "17", "right": "18", "status": "added", "diff": "--- PostgreSQL 17\n+++ PostgreSQL 18\n@@ -1 +1,16 @@\n-\u8be5\u7248\u672a\u6536\u5f55\n+{\n+  \"documented_option_names\": [\n+    \"Authorization Server\",\n+    \"Client\",\n+    \"Issuer\",\n+    \"Provider\",\n+    \"Resource Owner (or End User)\",\n+    \"Resource Server\",\n+    \"delegate_ident_mapping\",\n+    \"issuer\",\n+    \"map\",\n+    \"scope\",\n+    \"validator\"\n+  ],\n+  \"method\": \"oauth\"\n+}"}}