↑↓ 选择 ↵ 打开 ⌫ 改范围 完整检索页

pgsql.cc 提供对 postgresql.org 官网内容的中文翻译,由 Pigsty 团队维护。

百科 / 连接参数 / 身份认证

oauth_issuer

如果服务器为该连接请求 OAuth 令牌,要联系的受信任签发者的 HTTPS URL。所有 OAuth 连接都必须设置此参数;它应当与 服务器 HBA 配置 中的 issuer 设置完全一致。

当前查看 PostgreSQL 18.6。

说明

如果服务器为该连接请求 OAuth 令牌,要联系的受信任签发者的 HTTPS URL。所有 OAuth 连接都必须设置此参数;它应当与 服务器 HBA 配置 中的 issuer 设置完全一致。

客户端库
libpq 18.6
手册定义
手册已记载
源码中的环境变量回退
选项表中未声明
编译时回退表达式
NULL

用法

oauth_issuer

默认值解析与服务文件优先级

以下环境变量可用于选择连接参数的默认值,供 PQconnectdb 、 PQsetdbLogin 和 PQsetdb 在调用代码未直接指定参数值时使用。例如,这样可以避免在简单的客户端应用程序中硬编码数据库连接信息。

服务名称可以在每个用户的服务文件或系统范围的文件中定义。如果同一个服务名称存在于用户文件和系统文件中,则用户文件优先。默认情况下,每个用户的服务文件名为 ~/.pg_service.conf 。在Microsoft Windows上,它的名称为 %APPDATA%\postgresql\.pg_service.conf (其中 %APPDATA% 指用户配置文件夹中的应用数据子目录)。可以通过设置环境变量 PGSERVICEFILE 来指定不同的文件名。系统范围的文件名为 pg_service.conf 。默认情况下,在 PostgreSQL 安装的 etc 目录中寻找(使用 pg_config --sysconfdir 来准确识别此目录)。可以通过设置环境变量 PGSYSCONFDIR 来指定另一个目录,但不能指定不同的文件名。

从服务文件中获取的连接参数会与其他来源的参数合并。服务文件中的设置会覆盖相应的环境变量,而连接字符串中直接给出的值又会覆盖服务文件中的设置。例如,使用上述服务文件时,连接字符串 service=mydb port=5434 将使用主机 somehost 、端口 5434 、用户 admin ,以及由环境变量或内置默认值设置的其他参数。

环境变量证据

手册定义

oauth_issuer

如果服务器为该连接请求 OAuth 令牌,要联系的受信任签发者的 HTTPS URL。所有 OAuth 连接都必须设置此参数;它应当与服务器 HBA 配置中的issuer设置完全一致。

作为标准认证握手的一部分,libpq会向服务器请求一个发现文档,也就是一个提供一组 OAuth 配置参数的 URL。服务器必须提供一个可由oauth_issuer的各组成部分直接构造出来的 URL,并且该值必须与发现文档自身声明的签发者标识符完全一致,否则连接会失败。这是为了防止 OAuth 客户端遭受一类“混淆攻击(mix-up attacks)”。

你也可以显式把oauth_issuer设置为 OAuth 发现所使用的/.well-known/ URI。在这种情况下,如果服务器要求使用不同的 URL,连接就会失败;不过,自定义 OAuth 流程也许能够通过使用先前缓存的令牌来加速标准握手。(此时也建议设置oauth_scope,因为客户端将没有机会向服务器询问正确的授权范围设置,而令牌的默认授权范围可能不足以完成连接。)libpq当前支持以下 well-known 端点:

  • /.well-known/openid-configuration

  • /.well-known/oauth-authorization-server

警告

在 OAuth 连接握手期间,签发者拥有极高的权限。经验法则是:如果你不会信任某个 URL 的运营者来处理你对服务器的访问,或者不会信任其直接冒充你,那么这个 URL 就不应被信任为oauth_issuer。

相关条目

文档与源码

来源构建
版本
18.6
构建
https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
来源指纹
ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8

版本比较

PostgreSQL 17 → 18: 新增收录。

以下差异保留原始字段名与英文源描述。

--- PostgreSQL 17
+++ PostgreSQL 18
@@ -1 +1,10 @@
-该版未收录
+{
+  "compiled_default_expression": "NULL",
+  "default_evidence": [
+    "You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"
+  ],
+  "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .",
+  "documented": true,
+  "environment": "",
+  "keyword": "oauth_issuer"
+}

比较已记录的接口与属性,排除来源指纹和构建元数据。某个样本中没有记录,不能据此判断实际引入或移除的版本。

相关条目

导出 JSON · 返回连接参数 · 收录范围为 PostgreSQL 18 至 20;最早采样版本不一定是实际引入版本。