database backend: support @ in role name #31617
Open
+301
−7
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
closes #31613
I'm trying to write a templated policy to allow users to have access to a list of roles they can use.
Instead of writing a policy rule per database role, the templated policy I want looks like:
In my case, the mount is an OIDC mount, and the entity alias name with the default plugin is the user_claim, which in my case is the user email
Without this PR, the @ character is invalid, so I cannot create a database role that will match this policy rule.
And I get the following error :