{"record":{"id":"413b3e2bfc9f47b6","repo":"risingwavelabs/risingwave","slug":"auth-method-password-requires-password","errorCode":null,"errorMessage":"auth.method=password requires `password`","messagePattern":"auth\\.method=password requires `password`","errorType":"validation","errorClass":"SinkError::Config","httpStatus":null,"severity":"error","filePath":"src/connector/src/sink/snowflake_redshift/snowflake.rs","lineNumber":283,"sourceCode":"        if config.task_serverless && config.snowflake_warehouse.is_some() {\n            return Err(SinkError::Config(anyhow!(\n                \"`task.serverless` must not be combined with `warehouse`\"\n            )));\n        }\n\n        // Normalize and validate authentication method\n        let has_password = config.password.is_some();\n        let has_file = config.private_key_file.is_some();\n        let has_pem = config.private_key_pem.as_deref().is_some();\n\n        let normalized_auth_method = match config\n            .auth_method\n            .as_deref()\n            .map(|s| s.trim().to_ascii_lowercase())\n        {\n            Some(method) if method == AUTH_METHOD_PASSWORD => {\n                if !has_password {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=password requires `password`\"\n                    )));\n                }\n                if has_file || has_pem {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=password must not set `private_key_file`/`private_key_pem`\"\n                    )));\n                }\n                AUTH_METHOD_PASSWORD.to_owned()\n            }\n            Some(method) if method == AUTH_METHOD_KEY_PAIR_FILE => {\n                if !has_file {\n                    return Err(SinkError::Config(anyhow!(\n                        \"auth.method=key_pair_file requires `private_key_file`\"\n                    )));\n                }\n                if has_password {\n                    return Err(SinkError::Config(anyhow!(","sourceCodeStart":265,"sourceCodeEnd":301,"githubUrl":"https://github.com/risingwavelabs/risingwave/blob/6469eb736d691e8e9b8a419a57edd6429ca77417/src/connector/src/sink/snowflake_redshift/snowflake.rs#L265-L301","documentation":"When `auth.method` is explicitly set to `password`, SnowflakeSinkConfig::from_btreemap requires a `password` option to authenticate with. The sink fails at creation when the password-auth method is selected but no password is supplied.","triggerScenarios":"CREATE SINK with `auth.method = 'password'` (case-insensitive) but no `password` in the WITH options.","commonSituations":"Using an example DDL with auth.method=password but keeping credentials in a separate secrets step that was skipped; renaming options when copying configs so `password` was lost; switching from key-pair auth to password auth without adding the password.","solutions":["Add `password = '<secret>'` to the WITH options (via secret reference if supported)","Remove `auth.method = 'password'` if you intend to use the default/auth-detection path","Provide key-pair credentials instead (`private_key_file` or `private_key_pem`) and set the matching auth.method"],"exampleFix":"// before\nWITH (connector='snowflake', auth.method='password', user='u');\n// after\nWITH (connector='snowflake', auth.method='password', user='u', password='***');","handlingStrategy":"validation","validationCode":"if auth_method == \"password\" && !options.contains_key(\"password\") {\n    return Err(\"auth.method=password requires password\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Store Snowflake credentials in a secrets manager and inject at deploy time","Verify all options required by the chosen auth.method exist before CREATE SINK","Prefer explicit auth.method only when its credentials are also present"],"tags":["snowflake","sink","auth","config-validation"],"backgroundTag":"missing-required-config-field","analyzedSha":"6469eb736d691e8e9b8a419a57edd6429ca77417","analyzedAt":"2026-09-11T21:06:21.487Z","contentChangedAt":"2026-09-11T21:06:21.487Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}