Skip to content

PS-11419 [8.4] Enable proxied users for long group names or ids in OI… - #6072

Open
jankowsk wants to merge 1 commit into
percona:8.4from
jankowsk:PS-10999-8.4-OIDC_Authentication
Open

PS-11419 [8.4] Enable proxied users for long group names or ids in OI…#6072
jankowsk wants to merge 1 commit into
percona:8.4from
jankowsk:PS-10999-8.4-OIDC_Authentication

Conversation

@jankowsk

Copy link
Copy Markdown
Contributor

…DC plugin

Problem:
MySQL account name length is limited to 32 characters. If the group claim in the id token contains a group name longer than 32, it is impossible to proxy the user to account having the same name as the group. E.g. Microsoft Entra uses Group Object IDs which are longer than 32.

Solution:
Provide a way to define group - proxied account mapping. Thre ways to define proxying in IDENTIFIED ... AS (way 1 has been the only so far): 1) "group":<group_name> -if the user is member of <group_name>,
he will be proxied to account <group_name>
2) "group":[<group_name>, <proxied_account>] -if the user is member of <group_name>,
he will be proxied to account <proxied_account>
3) "group":[[<group_name_1>, <proxied_account_1>], [<group_name_2>, <proxied_account_2>] … ]
-same as previous, but allows for specifying multiple groups and additionally to decide
which group to select if the user is member of many groups.

…DC plugin

Problem:
MySQL account name length is limited to 32 characters. If the group claim in the
id token contains a group name longer than 32, it is impossible to proxy
the user to account having the same name as the group.
E.g. Microsoft Entra uses Group Object IDs which are longer than 32.

Solution:
Provide a way to define group - proxied account mapping.
Thre ways to define proxying in IDENTIFIED ... AS (way 1 has been the only so far):
1) "group":<group_name> -if the user is member of <group_name>,
    he will be proxied to account <group_name>
2) "group":[<group_name>, <proxied_account>] -if the user is member of <group_name>,
   he will be proxied to account <proxied_account>
3) "group":[[<group_name_1>, <proxied_account_1>], [<group_name_2>, <proxied_account_2>] … ]
    -same as previous, but allows for specifying multiple groups and additionally to decide
   which group to select if the user is member of many groups.
@jankowsk jankowsk self-assigned this Jul 16, 2026
@jankowsk
jankowsk requested a review from catalinbp July 16, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant