Skip to content

[OBO] End‑to‑End OBO & RLS Validation #3126

@anushakolan

Description

@anushakolan

Validate full end‑to‑end delegated identity behavior including SQL RLS.

  • Validate:

    1. SUSER_NAME() reflects delegated user
    2. RLS filters rows per user
    3. guest/B2B users succeed
  • Validate HTTP mapping

    1. invalid/missing token → 401
    2. missing identity claims → 401
    3. OBO failure → 401
    4. SQL permission denied → 403

Metadata

Metadata

Assignees

Labels

2.0oboThese tasks are related to DAB OBO Delegated Identity implmentation.

Type

Projects

Status

Todo

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions