Skip to content

[OBO] End‑to‑End OBO & RLS Validation #3126

@anushakolan

Description

@anushakolan

Validate full end‑to‑end delegated identity behavior including SQL RLS.

  • Validate:

    1. SUSER_NAME() reflects delegated user
    2. RLS filters rows per user
    3. guest/B2B users succeed
  • Validate HTTP mapping

    1. invalid/missing token → 401
    2. missing identity claims → 401
    3. OBO failure → 401
    4. SQL permission denied → 403

Metadata

Metadata

Assignees

Labels

2.0oboThese tasks are related to DAB OBO Delegated Identity implmentation.

Type

Projects

Status

Todo

Relationships

None yet

Development

No branches or pull requests

Issue actions