Repository navigation
Conversation
Generate JWT access tokens from Snowflake connection private keys and set the appropriate authorization token type for OAuth and key-pair authentication. Add unit tests covering both authentication paths and credential failures.
|
I just had another look at the other files in the directory for the snowflake provider hooks, and it appears that |
Not near my laptop so I can't look but I assume these files were also generated intially by AI who used bad patterns as example? There are very few cases where |
Description
This change adds key-pair authentication support to
SnowflakeCortexAgentHook, alongside the existing OAuth authentication support.Rationale
SnowflakeCortexAgentHookpreviously required an OAuth access token, preventing users with private-key-based Snowflake connections from calling Cortex Agent endpoints. Supporting key-pair authentication aligns the hook with the authentication methods already supported by Snowflake connections.Tests
Added unit tests verifying that:
test_get_auth_headers_uses_oauthconfirms OAuth authentication is used when an access token is available.test_get_auth_headers_uses_keypair_jwtconfirms key-pair credentials are used to generate a JWT.test_get_auth_headers_raises_when_credentials_missingconfirms an error is raised when neither authentication method is configured.test_get_auth_headers_raises_when_jwt_generation_failsconfirms an error is raised when JWT generation fails.Backward Compatibility
This change is backward compatible. Existing OAuth connections continue to work as before, while key-pair authentication is available when no OAuth token is configured.
Was generative AI tooling used to co-author this PR?
Generated-by: [GPT 5.6] following the guidelines