{"record":{"id":"83f4cdd63008df70","repo":"jackc/pgx","slug":"oauth-authentication-failed-s","errorCode":null,"errorMessage":"OAuth authentication failed: %s","messagePattern":"OAuth authentication failed: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"pgconn/auth_oauth.go","lineNumber":59,"sourceCode":"\tcase *pgproto3.AuthenticationOk:\n\t\treturn nil\n\tcase *pgproto3.AuthenticationSASLContinue:\n\t\t// Server sent error response in SASL continue\n\t\t// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.2\n\t\t// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.3\n\t\terrResponse := struct {\n\t\t\tStatus              string `json:\"status\"`\n\t\t\tScope               string `json:\"scope\"`\n\t\t\tOpenIDConfiguration string `json:\"openid-configuration\"`\n\t\t}{}\n\t\terr := json.Unmarshal(m.Data, &errResponse)\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"invalid OAuth error response from server: %w\", err)\n\t\t}\n\n\t\t// Per RFC 7628 section 3.2.3, we should send a SASLResponse which only contains \\x01.\n\t\t// However, since the connection will be closed anyway, we can skip this\n\t\treturn fmt.Errorf(\"OAuth authentication failed: %s\", errResponse.Status)\n\n\tcase *pgproto3.ErrorResponse:\n\t\treturn ErrorResponseToPgError(m)\n\n\tdefault:\n\t\treturn fmt.Errorf(\"unexpected message type during OAuth auth: %T\", msg)\n\t}\n}\n","sourceCodeStart":41,"sourceCodeEnd":68,"githubUrl":"https://github.com/jackc/pgx/blob/ec1a0befd22592cffffdeeb0a50311b506372f4c/pgconn/auth_oauth.go#L41-L68","documentation":"The server rejected OAuth authentication: it returned a well-formed RFC 7628 error envelope in the SASLContinue message, and its status field (e.g. 'not_supported' or 'invalid_token') is reported here.","triggerScenarios":"Thrown at pgconn/auth_oauth.go:59 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Check the status value — obtain a fresh token or fix scopes per the server's error detail","Verify the token provider and server agree on the OAuth issuer and scope configuration","Use a different authentication method if the server does not support OAuth"],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"ec1a0befd22592cffffdeeb0a50311b506372f4c","analyzedAt":"2026-08-04T22:52:11.263Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}