Skip to content

feat(api): add OAuth Postgres Query API support - #1024

Open
sdairs wants to merge 2 commits into
codex/998-permission-helpfrom
codex/1023-postgres-query-api
Open

sdairs wants to merge 2 commits into
codex/998-permission-helpfrom
codex/1023-postgres-query-api

Conversation

@sdairs

@sdairs sdairs commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Postgres queries currently require a native client and database credentials. Add Client::run_postgres_query_bearer and RunPostgresQueryRequest for the non-OpenAPI /service/{serviceId}/runPostgres?orgId=... route, using the existing query-host selection policy.

The helper sends OAuth Bearer credentials, rejects API-key clients before HTTP, and returns the gzip-decoded response for streaming. SQL and HTTP failures retain their existing typed classification. The fixed response format is JSONCompactEachRowWithNamesAndTypes; requests are never retried or provisioned. Includes an analyzer exemption, documentation, offline contract tests, and an ignored live smoke test against an existing service.

Refs #1023. CLI exposure is implemented separately in #1025, stacked on this branch.

Control-plane #41025 merged on September 28. Production Postgres query support was verified live on September 29 with clickhousectl OAuth credentials. API-key clients remain unsupported.

Validation:

  • cargo fmt --all --check
  • cargo clippy -p clickhouse-cloud-api -p clickhouse-openapi-analyzer --all-targets -- -D warnings
  • cargo test -p clickhouse-cloud-api -p clickhouse-openapi-analyzer
  • python3 -m unittest discover -s scripts/tests -p 'test_*.py'

Live validation (2026-09-29, existing evaluation service; no persistent database changes):

  • The repository's live_postgres_query_bearer_smoke passed with both postgres and an existing non-default database.
  • All 12 CLI acceptance checks passed: ID/name selectors, explicit database, human/JSON output, inline/file/implicit and explicit stdin, final-statement script results, empty results, duplicate names, nulls, Unicode, SQL errors, rejected writes, and organization access denial.
  • A separate non-default database check returned the requested database and current_user = chpg_console_readonly.
  • The rollback-protected CREATE TABLE probe was rejected with permission denied for schema public (CLI sql_error, exit 1).
  • Invalid Bearer credentials returned HTTP 401; querying with an unrelated organization returned HTTP 403 (auth_required, exit 4).

No implementation fixes were needed. Updated only the documentation to remove the resolved deployment caveat; formatting and diff checks passed. Draft status is retained. The broader repository Cloud integration CI gate is separate from this direct OAuth verification.

@sdairs
sdairs added this pull request to stack #1026 September 27, 2026 11:59
@sdairs
sdairs marked this pull request as ready for review September 29, 2026 17:49
@sdairs
sdairs requested a review from iskakaushik as a code owner September 29, 2026 17:49
@sdairs
sdairs force-pushed the codex/1023-postgres-query-api branch from 034d3a7 to a152bae Compare October 1, 2026 17:24
@sdairs
sdairs removed this pull request from stack #1026 October 1, 2026 17:26
@sdairs
sdairs changed the base branch from main to codex/998-permission-help October 1, 2026 17:27
@sdairs
sdairs added this pull request to stack #1001 October 1, 2026 17:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant