PS-11419 [8.4] Enable proxied users for long group names or ids in OI… - #6072
Open
jankowsk wants to merge 1 commit into
Open
PS-11419 [8.4] Enable proxied users for long group names or ids in OI…#6072jankowsk wants to merge 1 commit into
jankowsk wants to merge 1 commit into
Conversation
catalinbp
requested changes
Aug 21, 2026
…DC plugin
Problem:
MySQL account name length is limited to 32 characters. If the group claim in the
id token contains a group name longer than 32, it is impossible to proxy
the user to account having the same name as the group.
E.g. Microsoft Entra uses Group Object IDs which are longer than 32.
Solution:
Provide a way to define group - proxied account mapping.
The ways to define proxying in IDENTIFIED ... AS (way 1 has been the only so far):
1) "group":<group_name> -if the user is member of <group_name>,
he will be proxied to account <group_name>
2) "group":[[<group_name_1>, <proxied_account_1>], [<group_name_2>, <proxied_account_2>] … ]
-same as previous, but allows for specifying multiple groups and additionally to decide
which group to select if the user is member of many groups.
jankowsk
force-pushed
the
PS-10999-8.4-OIDC_Authentication
branch
from
August 21, 2026 13:00
5098613 to
883c6d5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
…DC plugin
Problem:
MySQL account name length is limited to 32 characters. If the group claim in the id token contains a group name longer than 32, it is impossible to proxy the user to account having the same name as the group. E.g. Microsoft Entra uses Group Object IDs which are longer than 32.
Solution:
Provide a way to define group - proxied account mapping. Thre ways to define proxying in IDENTIFIED ... AS (way 1 has been the only so far): 1) "group":<group_name> -if the user is member of <group_name>,
he will be proxied to account <group_name>
2) "group":[<group_name>, <proxied_account>] -if the user is member of <group_name>,
he will be proxied to account <proxied_account>
3) "group":[[<group_name_1>, <proxied_account_1>], [<group_name_2>, <proxied_account_2>] … ]
-same as previous, but allows for specifying multiple groups and additionally to decide
which group to select if the user is member of many groups.