Skip to content

Constrain Graph v4 authentication to the configured origin - #4012

Merged
Iarek Kovtunenko (iarekk) merged 3 commits into
masterfrom
iinglese/graph-request-destination-validation-minimal
Sep 14, 2026
Merged

Iarek Kovtunenko (iarekk) merged 3 commits into
masterfrom
iinglese/graph-request-destination-validation-minimal

Conversation

@iNinja

@iNinja Ignacio Inglese (iNinja) commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bind Graph v4 authentication to the configured or factory-created HTTPS origin.
  • Attach credentials only when the request destination matches that origin, including after request customization.
  • Preserve the Graph SDK default URL and custom Graph proxy support through the client's effective base URL.

Release notes

Graph v4 authentication now attaches credentials only to absolute HTTPS request destinations matching the configured client origin. Requests for other destinations continue without an authorization header. Blank base URL configuration continues to use the Graph SDK default, while custom factories must return a client with an absolute HTTPS base URL.

Testing

  • 73 focused provider and registration tests passed on .NET 8.
  • Stable and Beta Graph projects built successfully across their configured target frameworks.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Constrains Graph v4 authentication tokens to the configured HTTPS origin, including custom Graph proxies.

Changes:

  • Validates request origins before and after customization.
  • Binds factory-created clients to their HTTPS base URL.
  • Adds focused origin-validation and factory tests.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/Microsoft.Identity.Web.MicrosoftGraph/TokenAcquisitionAuthenticationProvider.cs Implements origin binding and validation.
src/Microsoft.Identity.Web.MicrosoftGraph/MicrosoftGraphExtensions.cs Binds factory clients to their origin.
src/Microsoft.Identity.Web.MicrosoftGraph/GraphServiceCollectionExtensions.cs Binds configured Graph clients securely.
src/Microsoft.Identity.Web.MicrosoftGraph/Properties/InternalsVisibleTo.cs Enables internal provider testing.
tests/Microsoft.Identity.Web.Test/TokenAcquisitionAuthenticationProviderTests.cs Covers URI validation and authorization cleanup.
tests/Microsoft.Identity.Web.Test/WebAppExtensionsTests.cs Covers custom factory base URLs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@bgavrilMS
Bogdan Gavril (bgavrilMS) force-pushed the iinglese/graph-request-destination-validation-minimal branch from 8f8e911 to 9abebe2 Compare September 14, 2026 11:05
@iarekk
Iarek Kovtunenko (iarekk) force-pushed the iinglese/graph-request-destination-validation-minimal branch from 9abebe2 to 421e6af Compare September 14, 2026 14:55
@iarekk
Iarek Kovtunenko (iarekk) force-pushed the iinglese/graph-request-destination-validation-minimal branch from 421e6af to d3d2098 Compare September 14, 2026 15:13
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@iarekk
Iarek Kovtunenko (iarekk) force-pushed the iinglese/graph-request-destination-validation-minimal branch from d3d2098 to 6b221fc Compare September 14, 2026 15:18
@iarekk
Iarek Kovtunenko (iarekk) merged commit 686217e into master Sep 14, 2026
9 checks passed
@iarekk
Iarek Kovtunenko (iarekk) deleted the iinglese/graph-request-destination-validation-minimal branch September 14, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants