Resolve token_audience from default_oidc_audience in host metadata#1371
Closed
Resolve token_audience from default_oidc_audience in host metadata#1371
Conversation
Signed-off-by: Tanmay Rustagi <tanmay.rustagi@databricks.com>
This was referenced Mar 30, 2026
Signed-off-by: Tanmay Rustagi <tanmay.rustagi@databricks.com>
Signed-off-by: Tanmay Rustagi <tanmay.rustagi@databricks.com>
ca751ee to
493fe38
Compare
Align the field name with the API contract for the well-known databricks-config endpoint. Co-authored-by: Isaac
The API returns this field as an array of strings. Use the first element when resolving token_audience. Co-authored-by: Isaac
Co-authored-by: Isaac
|
If integration tests don't run automatically, an authorized user can run them manually by following the instructions below: Trigger: Inputs:
Checks will be approved automatically on success. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🥞 Stacked PR
Use this link to review incremental changes.
Changes
Resolve
token_audiencefrom thedefault_oidc_audiencefield in host metadata:default_oidc_audiencefield to theHostMetadatadataclass, parsed from the discovery endpoint.Config._resolve_host_metadata(), settoken_audiencefromdefault_oidc_audiencewhen no explicittoken_audienceis configured. This takes priority overthe existing
account_idfallback for account-level hosts.Tests
default_oidc_audiencesetstoken_audiencewhen not explicitly configured.default_oidc_audiencetakes priority over theaccount_idfallback for account hosts.token_audienceis not overwritten bydefault_oidc_audience.account_idwhendefault_oidc_audienceis absent and noworkspace_id.