{"kind": "conn", "major": "18", "item": {"slug": "oauth-issuer", "name": "oauth_issuer", "name_zh": "", "category": "\u8eab\u4efd\u8ba4\u8bc1", "summary": "\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e \u670d\u52a1\u5668 HBA \u914d\u7f6e \u4e2d\u7684 issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002", "aliases": ["oauth_issuer"], "content_hash": "e0b28ca91e8dbc44b964467b993eb9ac9fa198c4cea6b2879e28ab6ef970450b", "versions": {"18": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "\u9009\u9879\u8868\u4e2d\u672a\u58f0\u660e"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e \u670d\u52a1\u5668 HBA \u914d\u7f6e \u4e2d\u7684 issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002"], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p lang=\"zh\">\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e<a class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1\">\u670d\u52a1\u5668 HBA \u914d\u7f6e</a>\u4e2d\u7684<code class=\"literal\">issuer</code>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002</p>\n<p lang=\"zh\">\u4f5c\u4e3a\u6807\u51c6\u8ba4\u8bc1\u63e1\u624b\u7684\u4e00\u90e8\u5206\uff0c<span class=\"application\">libpq</span>\u4f1a\u5411\u670d\u52a1\u5668\u8bf7\u6c42\u4e00\u4e2a<span class=\"emphasis\"><em>\u53d1\u73b0\u6587\u6863</em></span>\uff0c\u4e5f\u5c31\u662f\u4e00\u4e2a\u63d0\u4f9b\u4e00\u7ec4 OAuth \u914d\u7f6e\u53c2\u6570\u7684 URL\u3002\u670d\u52a1\u5668\u5fc5\u987b\u63d0\u4f9b\u4e00\u4e2a\u53ef\u7531<code class=\"literal\">oauth_issuer</code>\u7684\u5404\u7ec4\u6210\u90e8\u5206\u76f4\u63a5\u6784\u9020\u51fa\u6765\u7684 URL\uff0c\u5e76\u4e14\u8be5\u503c\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u81ea\u8eab\u58f0\u660e\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u5426\u5219\u8fde\u63a5\u4f1a\u5931\u8d25\u3002\u8fd9\u662f\u4e3a\u4e86\u9632\u6b62 OAuth \u5ba2\u6237\u7aef\u906d\u53d7\u4e00\u7c7b<a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\" target=\"_top\">\u201c\u6df7\u6dc6\u653b\u51fb\uff08mix-up attacks\uff09\u201d</a>\u3002</p>\n<p lang=\"zh\">\u4f60\u4e5f\u53ef\u4ee5\u663e\u5f0f\u628a<code class=\"literal\">oauth_issuer</code>\u8bbe\u7f6e\u4e3a OAuth \u53d1\u73b0\u6240\u4f7f\u7528\u7684<code class=\"literal\">/.well-known/</code> URI\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5982\u679c\u670d\u52a1\u5668\u8981\u6c42\u4f7f\u7528\u4e0d\u540c\u7684 URL\uff0c\u8fde\u63a5\u5c31\u4f1a\u5931\u8d25\uff1b\u4e0d\u8fc7\uff0c<a class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata \u94a9\u5b50\">\u81ea\u5b9a\u4e49 OAuth \u6d41\u7a0b</a>\u4e5f\u8bb8\u80fd\u591f\u901a\u8fc7\u4f7f\u7528\u5148\u524d\u7f13\u5b58\u7684\u4ee4\u724c\u6765\u52a0\u901f\u6807\u51c6\u63e1\u624b\u3002\uff08\u6b64\u65f6\u4e5f\u5efa\u8bae\u8bbe\u7f6e<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a>\uff0c\u56e0\u4e3a\u5ba2\u6237\u7aef\u5c06\u6ca1\u6709\u673a\u4f1a\u5411\u670d\u52a1\u5668\u8be2\u95ee\u6b63\u786e\u7684\u6388\u6743\u8303\u56f4\u8bbe\u7f6e\uff0c\u800c\u4ee4\u724c\u7684\u9ed8\u8ba4\u6388\u6743\u8303\u56f4\u53ef\u80fd\u4e0d\u8db3\u4ee5\u5b8c\u6210\u8fde\u63a5\u3002\uff09<span class=\"application\">libpq</span>\u5f53\u524d\u652f\u6301\u4ee5\u4e0b well-known \u7aef\u70b9\uff1a</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5728 OAuth \u8fde\u63a5\u63e1\u624b\u671f\u95f4\uff0c\u7b7e\u53d1\u8005\u62e5\u6709\u6781\u9ad8\u7684\u6743\u9650\u3002\u7ecf\u9a8c\u6cd5\u5219\u662f\uff1a\u5982\u679c\u4f60\u4e0d\u4f1a\u4fe1\u4efb\u67d0\u4e2a URL \u7684\u8fd0\u8425\u8005\u6765\u5904\u7406\u4f60\u5bf9\u670d\u52a1\u5668\u7684\u8bbf\u95ee\uff0c\u6216\u8005\u4e0d\u4f1a\u4fe1\u4efb\u5176\u76f4\u63a5\u5192\u5145\u4f60\uff0c\u90a3\u4e48\u8fd9\u4e2a URL \u5c31\u4e0d\u5e94\u88ab\u4fe1\u4efb\u4e3a<code class=\"literal\">oauth_issuer</code>\u3002</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[3]/h3[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/div[4]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[2]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/2/value": "None declared in the option table", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "50de12c3f8e068f00fb0a217910fa822f65d650540a0ac40545953d4f095fde1"}, "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "manual_language": "zh", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "19": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 19beta4"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "\u9009\u9879\u8868\u4e2d\u672a\u58f0\u660e"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/19/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/19/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/19/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "label": "19beta4", "major": "19", "channel": "preview", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/19/postgresql-19-A4.pdf", "bytes": 16064841, "pages": 3052, "sha256": "4dd099e4125c591128fc5f3ebd02178dc24781f9e5ae629f96d67c4c8547427b", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/19/postgresql-19-US.pdf", "bytes": 15974616, "pages": 3225, "sha256": "61971fa857f0956d47341a0388fa6af9ae10acf691d4b2fc009007d384b0342b", "built_at": "2026-09-26"}}, "tree": "19", "index": "index.html", "major": "19", "pages": 1155, "release": "19beta4", "source_url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "svg_assets": 5, "source_mode": "en SGML built with pinned official archive", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "revision": "1bbbbf4133d426f0e4304010688d2984c30fb67df0cc3a61b3e37eb3f6f37833", "evidence_kind": "English manual and source declarations", "source_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, "sources": [{"url": "https://pg.center/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "19beta4 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "14917417235a95d969bf3642c347dea7ae548c5f73b0dd00991a580ebcfbb47e", "language": "en", "original_url": "/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"}, {"url": "https://ftp.postgresql.org/pub/source/v19beta4/postgresql-19beta4.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "19beta4 libpq connection option declarations", "sha256": "ae8005372c570ff47a4922c942238653a034f01f9db40c9e0f57cb48915ffd98", "archive_sha256": "83157ee9c599d03b2f7a3d73ef3a56ec24e0e79cc2b3501a64d1364f56398c86"}, {"url": "https://pg.center/docs/19/libpq-envars.html", "file": "libpq-envars.html", "label": "19beta4 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d8f0afee19bae6323942ea5415649fbd66e3880fe8c8415350fcf3915f7c7047", "language": "en", "original_url": "/docs/19/libpq-envars.html"}, {"url": "https://pg.center/docs/19/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "19beta4 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "4c858fe55701d703cc00e7adf55eeac09cafcfdc37929b8e23ccf8ba42af9f98", "language": "en", "original_url": "/docs/19/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e \u670d\u52a1\u5668 HBA \u914d\u7f6e \u4e2d\u7684 issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002"], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p lang=\"zh\">\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e<a class=\"link\" href=\"/docs/19/auth-oauth.html\" title=\"20.14.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1\">\u670d\u52a1\u5668 HBA \u914d\u7f6e</a>\u4e2d\u7684<code class=\"literal\">issuer</code>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002</p>\n<p lang=\"zh\">\u4f5c\u4e3a\u6807\u51c6\u8ba4\u8bc1\u63e1\u624b\u7684\u4e00\u90e8\u5206\uff0c<span class=\"application\">libpq</span>\u4f1a\u5411\u670d\u52a1\u5668\u8bf7\u6c42\u4e00\u4e2a<span class=\"emphasis\"><em>\u53d1\u73b0\u6587\u6863</em></span>\uff0c\u4e5f\u5c31\u662f\u4e00\u4e2a\u63d0\u4f9b\u4e00\u7ec4 OAuth \u914d\u7f6e\u53c2\u6570\u7684 URL\u3002\u670d\u52a1\u5668\u5fc5\u987b\u63d0\u4f9b\u4e00\u4e2a\u53ef\u7531<code class=\"literal\">oauth_issuer</code>\u7684\u5404\u7ec4\u6210\u90e8\u5206\u76f4\u63a5\u6784\u9020\u51fa\u6765\u7684 URL\uff0c\u5e76\u4e14\u8be5\u503c\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u81ea\u8eab\u58f0\u660e\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u5426\u5219\u8fde\u63a5\u4f1a\u5931\u8d25\u3002\u8fd9\u662f\u4e3a\u4e86\u9632\u6b62 OAuth \u5ba2\u6237\u7aef\u906d\u53d7\u4e00\u7c7b<a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\" target=\"_top\">\u201c\u6df7\u6dc6\u653b\u51fb\uff08mix-up attacks\uff09\u201d</a>\u3002</p>\n<p lang=\"zh\">\u4f60\u4e5f\u53ef\u4ee5\u663e\u5f0f\u628a<code class=\"literal\">oauth_issuer</code>\u8bbe\u7f6e\u4e3a OAuth \u53d1\u73b0\u6240\u4f7f\u7528\u7684<code class=\"literal\">/.well-known/</code> URI\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5982\u679c\u670d\u52a1\u5668\u8981\u6c42\u4f7f\u7528\u4e0d\u540c\u7684 URL\uff0c\u8fde\u63a5\u5c31\u4f1a\u5931\u8d25\uff1b\u4e0d\u8fc7\uff0c<a class=\"link\" href=\"/docs/19/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata \u94a9\u5b50\">\u81ea\u5b9a\u4e49 OAuth \u6d41\u7a0b</a>\u4e5f\u8bb8\u80fd\u591f\u901a\u8fc7\u4f7f\u7528\u5148\u524d\u7f13\u5b58\u7684\u4ee4\u724c\u6765\u52a0\u901f\u6807\u51c6\u63e1\u624b\u3002\uff08\u6b64\u65f6\u4e5f\u5efa\u8bae\u8bbe\u7f6e<a class=\"xref\" href=\"/docs/19/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a>\uff0c\u56e0\u4e3a\u5ba2\u6237\u7aef\u5c06\u6ca1\u6709\u673a\u4f1a\u5411\u670d\u52a1\u5668\u8be2\u95ee\u6b63\u786e\u7684\u6388\u6743\u8303\u56f4\u8bbe\u7f6e\uff0c\u800c\u4ee4\u724c\u7684\u9ed8\u8ba4\u6388\u6743\u8303\u56f4\u53ef\u80fd\u4e0d\u8db3\u4ee5\u5b8c\u6210\u8fde\u63a5\u3002\uff09<span class=\"application\">libpq</span>\u5f53\u524d\u652f\u6301\u4ee5\u4e0b well-known \u7aef\u70b9\uff1a</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5728 OAuth \u8fde\u63a5\u63e1\u624b\u671f\u95f4\uff0c\u7b7e\u53d1\u8005\u62e5\u6709\u6781\u9ad8\u7684\u6743\u9650\u3002\u7ecf\u9a8c\u6cd5\u5219\u662f\uff1a\u5982\u679c\u4f60\u4e0d\u4f1a\u4fe1\u4efb\u67d0\u4e2a URL \u7684\u8fd0\u8425\u8005\u6765\u5904\u7406\u4f60\u5bf9\u670d\u52a1\u5668\u7684\u8bbf\u95ee\uff0c\u6216\u8005\u4e0d\u4f1a\u4fe1\u4efb\u5176\u76f4\u63a5\u5192\u5145\u4f60\uff0c\u90a3\u4e48\u8fd9\u4e2a URL \u5c31\u4e0d\u5e94\u88ab\u4fe1\u4efb\u4e3a<code class=\"literal\">oauth_issuer</code>\u3002</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "localization": {"status": "complete", "sources": [{"url": "/docs/19/libpq-connect.html", "method": "same-major semantic node", "sha256": "8a146554e35097ee5bd56228b90d2a83442c7bd6ca303bdd01de148d06928cd3", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[3]/h3[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/div[4]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[2]"]}, {"url": "/docs/19/libpq-envars.html", "method": "same-major semantic node", "sha256": "1c8f71428ae8cd8acf564cb581b51a0bce2bf0102680e44c1ced261aa3ec55f7", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/19/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "ed80600a221e79a10c683341a2d8b9fa12c84e00c638b7969a72feb8b3c467d3", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/19/description/0": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "/versions/19/facts/0/label": "Client library", "/versions/19/facts/1/label": "Manual definition", "/versions/19/facts/1/value": "Documented", "/versions/19/facts/2/label": "Source environment fallback", "/versions/19/facts/2/value": "None declared in the option table", "/versions/19/facts/3/label": "Compiled fallback expression", "/versions/19/related/0/label": "Connection service file", "/versions/19/related/1/label": "Password file", "/versions/19/related/2/label": "All libpq environment variables", "/versions/19/sections/0/title": "Default resolution and service-file precedence", "/versions/19/sections/1/title": "Environment variable evidence", "/versions/19/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/19/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/19/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "9b92853fa467a18587760ad1970fcd349ba34f8e18bc2ebe097c9fb1d800a514"}, "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "manual_language": "zh", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "20": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 20devel"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "\u9009\u9879\u8868\u4e2d\u672a\u58f0\u660e"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/devel/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/devel/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/devel/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "label": "20devel", "major": "20", "channel": "devel", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/20/postgresql-20-A4.pdf", "bytes": 16030631, "pages": 3052, "sha256": "bd5d82c0ce38fc18f92a0447818a91a193a261776bca1c37564bf9a683e177d0", "built_at": "2026-09-28"}, "US": {"url": "/files/documentation/pdf/20/postgresql-20-US.pdf", "bytes": 15936613, "pages": 3223, "sha256": "d97d9e0db479a02f4234b175f50fcad70c3661619afc8d6df9b9437882e3c299", "built_at": "2026-09-28"}}, "tree": "0", "index": "index.html", "major": "20", "pages": 1156, "release": "20devel", "source_url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "svg_assets": 6, "source_mode": "en SGML built with pinned official archive", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41", "source_snapshot_utc": "26-Sep-2026 20:22"}, "revision": "2eba5e0fd4c3bffb2803247b6cd537878e9d6ee5a6dfbe3c50ece8b421b80918", "evidence_kind": "English manual and source declarations", "source_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, "sources": [{"url": "https://pg.center/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "20devel English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "eeb28ce798c0f99c3581400b4baaae7687ee5d4176fcb9f5d2fd28809282d48f", "language": "en", "original_url": "/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"}, {"url": "https://ftp.postgresql.org/pub/snapshot/dev/postgresql-snapshot.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "20devel libpq connection option declarations", "sha256": "d6eab6e2f37054b32a7ee7039b53beae603316f8ec3f0a14716061e042fc4aa1", "archive_sha256": "4d3346909b201ac1648232cf290462a7070c119326f56196f1f0253ed80fae41"}, {"url": "https://pg.center/docs/devel/libpq-envars.html", "file": "libpq-envars.html", "label": "20devel English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "7c49cf204e26ea86654491db5ea06c4f558c670e2e60a60b1dbf708ce682accc", "language": "en", "original_url": "/docs/devel/libpq-envars.html"}, {"url": "https://pg.center/docs/devel/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "20devel English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "a1ccd63a6e307a5541d58eabd57be5b467dff2480770838ec9b6a59a3ef110dc", "language": "en", "original_url": "/docs/devel/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u5728 libpq \u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u4f7f\u7528 servicefile \u5173\u952e\u5b57\uff0c\u6216\u8005\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e \u670d\u52a1\u5668 HBA \u914d\u7f6e \u4e2d\u7684 issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002"], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p lang=\"zh\">\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e<a class=\"link\" href=\"/docs/devel/auth-oauth.html\" title=\"20.14.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1\">\u670d\u52a1\u5668 HBA \u914d\u7f6e</a>\u4e2d\u7684<code class=\"literal\">issuer</code>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002</p>\n<p lang=\"zh\">\u4f5c\u4e3a\u6807\u51c6\u8ba4\u8bc1\u63e1\u624b\u7684\u4e00\u90e8\u5206\uff0c<span class=\"application\">libpq</span>\u4f1a\u5411\u670d\u52a1\u5668\u8bf7\u6c42\u4e00\u4e2a<span class=\"emphasis\"><em>\u53d1\u73b0\u6587\u6863</em></span>\uff0c\u4e5f\u5c31\u662f\u4e00\u4e2a\u63d0\u4f9b\u4e00\u7ec4 OAuth \u914d\u7f6e\u53c2\u6570\u7684 URL\u3002\u670d\u52a1\u5668\u5fc5\u987b\u63d0\u4f9b\u4e00\u4e2a\u53ef\u7531<code class=\"literal\">oauth_issuer</code>\u7684\u5404\u7ec4\u6210\u90e8\u5206\u76f4\u63a5\u6784\u9020\u51fa\u6765\u7684 URL\uff0c\u5e76\u4e14\u8be5\u503c\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u81ea\u8eab\u58f0\u660e\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u5426\u5219\u8fde\u63a5\u4f1a\u5931\u8d25\u3002\u8fd9\u662f\u4e3a\u4e86\u9632\u6b62 OAuth \u5ba2\u6237\u7aef\u906d\u53d7\u4e00\u7c7b<a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\" target=\"_top\">\u201c\u6df7\u6dc6\u653b\u51fb\uff08mix-up attacks\uff09\u201d</a>\u3002</p>\n<p lang=\"zh\">\u4f60\u4e5f\u53ef\u4ee5\u663e\u5f0f\u628a<code class=\"literal\">oauth_issuer</code>\u8bbe\u7f6e\u4e3a OAuth \u53d1\u73b0\u6240\u4f7f\u7528\u7684<code class=\"literal\">/.well-known/</code> URI\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5982\u679c\u670d\u52a1\u5668\u8981\u6c42\u4f7f\u7528\u4e0d\u540c\u7684 URL\uff0c\u8fde\u63a5\u5c31\u4f1a\u5931\u8d25\uff1b\u4e0d\u8fc7\uff0c<a class=\"link\" href=\"/docs/devel/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.19.1.\u00a0Authdata \u94a9\u5b50\">\u81ea\u5b9a\u4e49 OAuth \u6d41\u7a0b</a>\u4e5f\u8bb8\u80fd\u591f\u901a\u8fc7\u4f7f\u7528\u5148\u524d\u7f13\u5b58\u7684\u4ee4\u724c\u6765\u52a0\u901f\u6807\u51c6\u63e1\u624b\u3002\uff08\u6b64\u65f6\u4e5f\u5efa\u8bae\u8bbe\u7f6e<a class=\"xref\" href=\"/docs/devel/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a>\uff0c\u56e0\u4e3a\u5ba2\u6237\u7aef\u5c06\u6ca1\u6709\u673a\u4f1a\u5411\u670d\u52a1\u5668\u8be2\u95ee\u6b63\u786e\u7684\u6388\u6743\u8303\u56f4\u8bbe\u7f6e\uff0c\u800c\u4ee4\u724c\u7684\u9ed8\u8ba4\u6388\u6743\u8303\u56f4\u53ef\u80fd\u4e0d\u8db3\u4ee5\u5b8c\u6210\u8fde\u63a5\u3002\uff09<span class=\"application\">libpq</span>\u5f53\u524d\u652f\u6301\u4ee5\u4e0b well-known \u7aef\u70b9\uff1a</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5728 OAuth \u8fde\u63a5\u63e1\u624b\u671f\u95f4\uff0c\u7b7e\u53d1\u8005\u62e5\u6709\u6781\u9ad8\u7684\u6743\u9650\u3002\u7ecf\u9a8c\u6cd5\u5219\u662f\uff1a\u5982\u679c\u4f60\u4e0d\u4f1a\u4fe1\u4efb\u67d0\u4e2a URL \u7684\u8fd0\u8425\u8005\u6765\u5904\u7406\u4f60\u5bf9\u670d\u52a1\u5668\u7684\u8bbf\u95ee\uff0c\u6216\u8005\u4e0d\u4f1a\u4fe1\u4efb\u5176\u76f4\u63a5\u5192\u5145\u4f60\uff0c\u90a3\u4e48\u8fd9\u4e2a URL \u5c31\u4e0d\u5e94\u88ab\u4fe1\u4efb\u4e3a<code class=\"literal\">oauth_issuer</code>\u3002</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "localization": {"status": "complete", "sources": [{"url": "/docs/devel/libpq-connect.html", "method": "same-major semantic node", "sha256": "80a1ddba976c7228bb9d179e08545f0a6328ffc9b880481df17a53fdebf42bb5", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[3]/h3[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/div[4]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[97]/p[2]"]}, {"url": "/docs/devel/libpq-envars.html", "method": "same-major semantic node", "sha256": "b4afd6d100d2be289d48e1a6f6fb9804dd0b684798b7dabf8bae7d3db074117f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/devel/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "acea589bbba517979fe815bd3bff32cd6d5e6323e1d5b4f395d7864338868b26", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/summary": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "/category": "Authentication", "/versions/20/description/0": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "/versions/20/facts/0/label": "Client library", "/versions/20/facts/1/label": "Manual definition", "/versions/20/facts/1/value": "Documented", "/versions/20/facts/2/label": "Source environment fallback", "/versions/20/facts/2/value": "None declared in the option table", "/versions/20/facts/3/label": "Compiled fallback expression", "/versions/20/related/0/label": "Connection service file", "/versions/20/related/1/label": "Password file", "/versions/20/related/2/label": "All libpq environment variables", "/versions/20/sections/0/title": "Default resolution and service-file precedence", "/versions/20/sections/1/title": "Environment variable evidence", "/versions/20/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/20/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/20/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "c499d0540f59ecae43d81ab4c2f249a6415efc2cfb40fc8bc793823fca64bc07"}, "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "manual_language": "zh", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified using the servicefile key word in a libpq connection string or by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}}}, "snapshot": {"facts": [{"label": "\u5ba2\u6237\u7aef\u5e93", "value": "libpq 18.6"}, {"label": "\u624b\u518c\u5b9a\u4e49", "value": "\u624b\u518c\u5df2\u8bb0\u8f7d"}, {"label": "\u6e90\u7801\u4e2d\u7684\u73af\u5883\u53d8\u91cf\u56de\u9000", "value": "\u9009\u9879\u8868\u4e2d\u672a\u58f0\u660e"}, {"label": "\u7f16\u8bd1\u65f6\u56de\u9000\u8868\u8fbe\u5f0f", "value": "NULL"}], "tables": [], "keyword": "oauth_issuer", "related": [{"url": "/docs/18/libpq-pgservice.html", "label": "\u8fde\u63a5\u670d\u52a1\u6587\u4ef6"}, {"url": "/docs/18/libpq-pgpass.html", "label": "\u53e3\u4ee4\u6587\u4ef6"}, {"url": "/docs/18/libpq-envars.html", "label": "\u6240\u6709 libpq \u73af\u5883\u53d8\u91cf"}], "release": {"ref": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "label": "18.6", "major": "18", "channel": "stable", "manifest": {"pdf": {"A4": {"url": "/files/documentation/pdf/18/postgresql-18-A4.pdf", "bytes": 15865106, "pages": 3154, "sha256": "19512c405da53f9f7fcf0abba359223aa65f021be025bf3411381918f92e3190", "built_at": "2026-09-26"}, "US": {"url": "/files/documentation/pdf/18/postgresql-18-US.pdf", "bytes": 15748059, "pages": 3328, "sha256": "facbe6c229e598b872d3d98bef53308f46e06746006fa4590de9a7de9dd46319", "built_at": "2026-09-26"}}, "tree": "18", "index": "index.html", "major": "18", "pages": 1148, "release": "18.6", "source_url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "svg_assets": 3, "source_mode": "en SGML built with pinned official archive", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "revision": "ee8d1a3612338fd9adf250730cb640fcc5233b5491337cc00a316a44e3a0b9f8", "evidence_kind": "English manual and source declarations", "source_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, "sources": [{"url": "https://pg.center/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "file": "libpq-connect.html", "label": "18.6 English manual \u00b7 libpq-connect.html", "anchor": "LIBPQ-CONNECT-OAUTH-ISSUER", "sha256": "c26a7fc3dcda6066cfe540641ae2690faf3d3c03277f30b4dfc2328ab45c212f", "language": "en", "original_url": "/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER"}, {"url": "https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2", "file": "src/interfaces/libpq/fe-connect.c", "label": "18.6 libpq connection option declarations", "sha256": "44a6e386cbfd67ebe768d6ef5493098119c2e6b4796239d53e5ed7b122b206a5", "archive_sha256": "555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"}, {"url": "https://pg.center/docs/18/libpq-envars.html", "file": "libpq-envars.html", "label": "18.6 English manual \u00b7 libpq-envars.html", "anchor": "", "sha256": "d64db73f3d48127bb984a5f775e77b7bcca2ba4bd218333cf24a45fcdd7c4363", "language": "en", "original_url": "/docs/18/libpq-envars.html"}, {"url": "https://pg.center/docs/18/libpq-pgservice.html", "file": "libpq-pgservice.html", "label": "18.6 English manual \u00b7 libpq-pgservice.html", "anchor": "", "sha256": "6035a3f0ee1d0fd80db5bf58834390b884eecd23206659bdf6f07560deea5aa7", "language": "en", "original_url": "/docs/18/libpq-pgservice.html"}], "sections": [{"title": "\u9ed8\u8ba4\u503c\u89e3\u6790\u4e0e\u670d\u52a1\u6587\u4ef6\u4f18\u5148\u7ea7", "paragraphs": ["\u4ee5\u4e0b\u73af\u5883\u53d8\u91cf\u53ef\u7528\u4e8e\u9009\u62e9\u8fde\u63a5\u53c2\u6570\u7684\u9ed8\u8ba4\u503c\uff0c\u4f9b PQconnectdb \u3001 PQsetdbLogin \u548c PQsetdb \u5728\u8c03\u7528\u4ee3\u7801\u672a\u76f4\u63a5\u6307\u5b9a\u53c2\u6570\u503c\u65f6\u4f7f\u7528\u3002\u4f8b\u5982\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u5728\u7b80\u5355\u7684\u5ba2\u6237\u7aef\u5e94\u7528\u7a0b\u5e8f\u4e2d\u786c\u7f16\u7801\u6570\u636e\u5e93\u8fde\u63a5\u4fe1\u606f\u3002", "\u670d\u52a1\u540d\u79f0\u53ef\u4ee5\u5728\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u6216\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u4e2d\u5b9a\u4e49\u3002\u5982\u679c\u540c\u4e00\u4e2a\u670d\u52a1\u540d\u79f0\u5b58\u5728\u4e8e\u7528\u6237\u6587\u4ef6\u548c\u7cfb\u7edf\u6587\u4ef6\u4e2d\uff0c\u5219\u7528\u6237\u6587\u4ef6\u4f18\u5148\u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u7528\u6237\u7684\u670d\u52a1\u6587\u4ef6\u540d\u4e3a ~/.pg_service.conf \u3002\u5728Microsoft Windows\u4e0a\uff0c\u5b83\u7684\u540d\u79f0\u4e3a %APPDATA%\\postgresql\\.pg_service.conf \uff08\u5176\u4e2d %APPDATA% \u6307\u7528\u6237\u914d\u7f6e\u6587\u4ef6\u5939\u4e2d\u7684\u5e94\u7528\u6570\u636e\u5b50\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSERVICEFILE \u6765\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002\u7cfb\u7edf\u8303\u56f4\u7684\u6587\u4ef6\u540d\u4e3a pg_service.conf \u3002\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u5728 PostgreSQL \u5b89\u88c5\u7684 etc \u76ee\u5f55\u4e2d\u5bfb\u627e\uff08\u4f7f\u7528 pg_config --sysconfdir \u6765\u51c6\u786e\u8bc6\u522b\u6b64\u76ee\u5f55\uff09\u3002\u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u73af\u5883\u53d8\u91cf PGSYSCONFDIR \u6765\u6307\u5b9a\u53e6\u4e00\u4e2a\u76ee\u5f55\uff0c\u4f46\u4e0d\u80fd\u6307\u5b9a\u4e0d\u540c\u7684\u6587\u4ef6\u540d\u3002", "\u4ece\u670d\u52a1\u6587\u4ef6\u4e2d\u83b7\u53d6\u7684\u8fde\u63a5\u53c2\u6570\u4f1a\u4e0e\u5176\u4ed6\u6765\u6e90\u7684\u53c2\u6570\u5408\u5e76\u3002\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u4f1a\u8986\u76d6\u76f8\u5e94\u7684\u73af\u5883\u53d8\u91cf\uff0c\u800c\u8fde\u63a5\u5b57\u7b26\u4e32\u4e2d\u76f4\u63a5\u7ed9\u51fa\u7684\u503c\u53c8\u4f1a\u8986\u76d6\u670d\u52a1\u6587\u4ef6\u4e2d\u7684\u8bbe\u7f6e\u3002\u4f8b\u5982\uff0c\u4f7f\u7528\u4e0a\u8ff0\u670d\u52a1\u6587\u4ef6\u65f6\uff0c\u8fde\u63a5\u5b57\u7b26\u4e32 service=mydb port=5434 \u5c06\u4f7f\u7528\u4e3b\u673a somehost \u3001\u7aef\u53e3 5434 \u3001\u7528\u6237 admin \uff0c\u4ee5\u53ca\u7531\u73af\u5883\u53d8\u91cf\u6216\u5185\u7f6e\u9ed8\u8ba4\u503c\u8bbe\u7f6e\u7684\u5176\u4ed6\u53c2\u6570\u3002"]}, {"title": "\u73af\u5883\u53d8\u91cf\u8bc1\u636e", "paragraphs": []}], "signature": "oauth_issuer", "documented": true, "description": ["\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e \u670d\u52a1\u5668 HBA \u914d\u7f6e \u4e2d\u7684 issuer \u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002"], "environment": [], "manual_html": "<div><dl class=\"variablelist\"><dt id=\"LIBPQ-CONNECT-OAUTH-ISSUER\"><span class=\"term\"><code class=\"literal\">oauth_issuer</code></span> </dt><dd>\n<p lang=\"zh\">\u5982\u679c\u670d\u52a1\u5668\u4e3a\u8be5\u8fde\u63a5\u8bf7\u6c42 OAuth \u4ee4\u724c\uff0c\u8981\u8054\u7cfb\u7684\u53d7\u4fe1\u4efb\u7b7e\u53d1\u8005\u7684 HTTPS URL\u3002\u6240\u6709 OAuth \u8fde\u63a5\u90fd\u5fc5\u987b\u8bbe\u7f6e\u6b64\u53c2\u6570\uff1b\u5b83\u5e94\u5f53\u4e0e<a class=\"link\" href=\"/docs/18/auth-oauth.html\" title=\"20.15.\u00a0OAuth \u6388\u6743/\u8ba4\u8bc1\">\u670d\u52a1\u5668 HBA \u914d\u7f6e</a>\u4e2d\u7684<code class=\"literal\">issuer</code>\u8bbe\u7f6e\u5b8c\u5168\u4e00\u81f4\u3002</p>\n<p lang=\"zh\">\u4f5c\u4e3a\u6807\u51c6\u8ba4\u8bc1\u63e1\u624b\u7684\u4e00\u90e8\u5206\uff0c<span class=\"application\">libpq</span>\u4f1a\u5411\u670d\u52a1\u5668\u8bf7\u6c42\u4e00\u4e2a<span class=\"emphasis\"><em>\u53d1\u73b0\u6587\u6863</em></span>\uff0c\u4e5f\u5c31\u662f\u4e00\u4e2a\u63d0\u4f9b\u4e00\u7ec4 OAuth \u914d\u7f6e\u53c2\u6570\u7684 URL\u3002\u670d\u52a1\u5668\u5fc5\u987b\u63d0\u4f9b\u4e00\u4e2a\u53ef\u7531<code class=\"literal\">oauth_issuer</code>\u7684\u5404\u7ec4\u6210\u90e8\u5206\u76f4\u63a5\u6784\u9020\u51fa\u6765\u7684 URL\uff0c\u5e76\u4e14\u8be5\u503c\u5fc5\u987b\u4e0e\u53d1\u73b0\u6587\u6863\u81ea\u8eab\u58f0\u660e\u7684\u7b7e\u53d1\u8005\u6807\u8bc6\u7b26\u5b8c\u5168\u4e00\u81f4\uff0c\u5426\u5219\u8fde\u63a5\u4f1a\u5931\u8d25\u3002\u8fd9\u662f\u4e3a\u4e86\u9632\u6b62 OAuth \u5ba2\u6237\u7aef\u906d\u53d7\u4e00\u7c7b<a class=\"ulink\" href=\"https://mailarchive.ietf.org/arch/msg/oauth/JIVxFBGsJBVtm7ljwJhPUm3Fr-w/\" target=\"_top\">\u201c\u6df7\u6dc6\u653b\u51fb\uff08mix-up attacks\uff09\u201d</a>\u3002</p>\n<p lang=\"zh\">\u4f60\u4e5f\u53ef\u4ee5\u663e\u5f0f\u628a<code class=\"literal\">oauth_issuer</code>\u8bbe\u7f6e\u4e3a OAuth \u53d1\u73b0\u6240\u4f7f\u7528\u7684<code class=\"literal\">/.well-known/</code> URI\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5982\u679c\u670d\u52a1\u5668\u8981\u6c42\u4f7f\u7528\u4e0d\u540c\u7684 URL\uff0c\u8fde\u63a5\u5c31\u4f1a\u5931\u8d25\uff1b\u4e0d\u8fc7\uff0c<a class=\"link\" href=\"/docs/18/libpq-oauth.html#LIBPQ-OAUTH-AUTHDATA-HOOKS\" title=\"32.20.1.\u00a0Authdata \u94a9\u5b50\">\u81ea\u5b9a\u4e49 OAuth \u6d41\u7a0b</a>\u4e5f\u8bb8\u80fd\u591f\u901a\u8fc7\u4f7f\u7528\u5148\u524d\u7f13\u5b58\u7684\u4ee4\u724c\u6765\u52a0\u901f\u6807\u51c6\u63e1\u624b\u3002\uff08\u6b64\u65f6\u4e5f\u5efa\u8bae\u8bbe\u7f6e<a class=\"xref\" href=\"/docs/18/libpq-connect.html#LIBPQ-CONNECT-OAUTH-SCOPE\">oauth_scope</a>\uff0c\u56e0\u4e3a\u5ba2\u6237\u7aef\u5c06\u6ca1\u6709\u673a\u4f1a\u5411\u670d\u52a1\u5668\u8be2\u95ee\u6b63\u786e\u7684\u6388\u6743\u8303\u56f4\u8bbe\u7f6e\uff0c\u800c\u4ee4\u724c\u7684\u9ed8\u8ba4\u6388\u6743\u8303\u56f4\u53ef\u80fd\u4e0d\u8db3\u4ee5\u5b8c\u6210\u8fde\u63a5\u3002\uff09<span class=\"application\">libpq</span>\u5f53\u524d\u652f\u6301\u4ee5\u4e0b well-known \u7aef\u70b9\uff1a</p>\n<div class=\"itemizedlist\">\n<ul class=\"itemizedlist compact\">\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/openid-configuration</code></p>\n</li>\n<li class=\"listitem\">\n<p><code class=\"literal\">/.well-known/oauth-authorization-server</code></p>\n</li>\n</ul>\n</div>\n<div class=\"warning\">\n<h3 class=\"title\" lang=\"zh\">\u8b66\u544a</h3>\n<p lang=\"zh\">\u5728 OAuth \u8fde\u63a5\u63e1\u624b\u671f\u95f4\uff0c\u7b7e\u53d1\u8005\u62e5\u6709\u6781\u9ad8\u7684\u6743\u9650\u3002\u7ecf\u9a8c\u6cd5\u5219\u662f\uff1a\u5982\u679c\u4f60\u4e0d\u4f1a\u4fe1\u4efb\u67d0\u4e2a URL \u7684\u8fd0\u8425\u8005\u6765\u5904\u7406\u4f60\u5bf9\u670d\u52a1\u5668\u7684\u8bbf\u95ee\uff0c\u6216\u8005\u4e0d\u4f1a\u4fe1\u4efb\u5176\u76f4\u63a5\u5192\u5145\u4f60\uff0c\u90a3\u4e48\u8fd9\u4e2a URL \u5c31\u4e0d\u5e94\u88ab\u4fe1\u4efb\u4e3a<code class=\"literal\">oauth_issuer</code>\u3002</p>\n</div>\n</dd></dl></div>", "manual_path": "libpq-connect.html#LIBPQ-CONNECT-OAUTH-ISSUER", "localization": {"status": "complete", "sources": [{"url": "/docs/18/libpq-connect.html", "method": "same-major semantic node", "sha256": "bae58c13a65be235aa0408ef12f8bcc7e48f2908cd71080a7dedec225a74c083", "language": "zh", "matched_nodes": ["#LIBPQ-CONNECT/div[3]/h3[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/div[4]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[0]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[1]", "#LIBPQ-CONNECT/div[7]/div[2]/dl[0]/dd[95]/p[2]"]}, {"url": "/docs/18/libpq-envars.html", "method": "same-major semantic node", "sha256": "8423affb67ef7d4f700d7ccc8c0ef66629341568c8d72530a0c765f3d155da2f", "language": "zh", "matched_nodes": ["#LIBPQ-ENVARS/p[2]"]}, {"url": "/docs/18/libpq-pgservice.html", "method": "same-major semantic node", "sha256": "a06dfcdffbbdf6bd55987cade2d9ff1db6cbfd9f75eb80c7866e8792cd70463e", "language": "zh", "matched_nodes": ["#LIBPQ-PGSERVICE/p[5]", "#LIBPQ-PGSERVICE/p[9]"]}], "language": "zh", "original_text": {"/versions/18/description/0": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .", "/versions/18/facts/0/label": "Client library", "/versions/18/facts/1/label": "Manual definition", "/versions/18/facts/1/value": "Documented", "/versions/18/facts/2/label": "Source environment fallback", "/versions/18/facts/2/value": "None declared in the option table", "/versions/18/facts/3/label": "Compiled fallback expression", "/versions/18/related/0/label": "Connection service file", "/versions/18/related/1/label": "Password file", "/versions/18/related/2/label": "All libpq environment variables", "/versions/18/sections/0/title": "Default resolution and service-file precedence", "/versions/18/sections/1/title": "Environment variable evidence", "/versions/18/sections/0/paragraphs/0": "The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "/versions/18/sections/0/paragraphs/1": "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "/versions/18/sections/0/paragraphs/2": "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."}, "fallback_fields": [], "source_language": "en", "original_snapshot_sha256": "50de12c3f8e068f00fb0a217910fa822f65d650540a0ac40545953d4f095fde1"}, "source_option": {"keyword": "oauth_issuer", "declaration": "\"oauth_issuer\", NULL, NULL, NULL, \"OAuth-Issuer\", \"\", 40, offsetof(struct pg_conn, oauth_issuer)", "environment": "", "source_notes": [], "compiled_default_expression": "NULL"}, "comparison_data": {"keyword": "oauth_issuer", "definition": "The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \"mix-up attacks\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .", "documented": true, "environment": "", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "compiled_default_expression": "NULL"}, "comparison_hash": "9afc5e8603b6a862d897284099f310b696b3365ecc6dbb724802de062d37fa13", "manual_language": "zh", "default_evidence": ["You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:"], "precedence_evidence": ["The following environment variables can be used to select default connection parameter values, which will be used by PQconnectdb , PQsetdbLogin and PQsetdb if no value is directly specified by the calling code. These are useful to avoid hard-coding database connection information into simple client applications, for example.", "Service names can be defined in either a per-user service file or a system-wide file. If the same service name exists in both the user and the system file, the user file takes precedence. By default, the per-user service file is named ~/.pg_service.conf . On Microsoft Windows, it is named %APPDATA%\\postgresql\\.pg_service.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). A different file name can be specified by setting the environment variable PGSERVICEFILE . The system-wide file is named pg_service.conf . By default it is sought in the etc directory of the PostgreSQL installation (use pg_config --sysconfdir to identify this directory precisely). Another directory, but not a different file name, can be specified by setting the environment variable PGSYSCONFDIR .", "Connection parameters obtained from a service file are combined with parameters obtained from other sources. A service file setting overrides the corresponding environment variable, and in turn can be overridden by a value given directly in the connection string. For example, using the above service file, a connection string service=mydb port=5434 will use host somehost , port 5434 , user admin , and other parameters as set by environment variables or built-in defaults."]}, "comparison": {"left": "17", "right": "18", "status": "added", "diff": "--- PostgreSQL 17\n+++ PostgreSQL 18\n@@ -1 +1,10 @@\n-\u8be5\u7248\u672a\u6536\u5f55\n+{\n+  \"compiled_default_expression\": \"NULL\",\n+  \"default_evidence\": [\n+    \"You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints:\"\n+  ],\n+  \"definition\": \"The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration . As part of the standard authentication handshake, libpq will ask the server for a discovery document: a URL providing a set of OAuth configuration parameters. The server must provide a URL that is directly constructed from the components of the oauth_issuer , and this value must exactly match the issuer identifier that is declared in the discovery document itself, or the connection will fail. This is required to prevent a class of \\\"mix-up attacks\\\" on OAuth clients. You may also explicitly set oauth_issuer to the /.well-known/ URI used for OAuth discovery. In this case, if the server asks for a different URL, the connection will fail, but a custom OAuth flow may be able to speed up the standard handshake by using previously cached tokens. (In this case, it is recommended that oauth_scope be set as well, since the client will not have a chance to ask the server for a correct scope setting, and the default scopes for a token may not be sufficient to connect.) libpq currently supports the following well-known endpoints: /.well-known/openid-configuration /.well-known/oauth-authorization-server Warning Issuers are highly privileged during the OAuth connection handshake. As a rule of thumb, if you would not trust the operator of a URL to handle access to your servers, or to impersonate you directly, that URL should not be trusted as an oauth_issuer .\",\n+  \"documented\": true,\n+  \"environment\": \"\",\n+  \"keyword\": \"oauth_issuer\"\n+}"}}