Skip to content

Use app acquisition for EasyAuth app authentication results - #4015

Merged
Nilesh Choudhary (4gust) merged 5 commits into
masterfrom
iinglese/easyauth-contract-validation-minimal
Sep 8, 2026
Merged

Nilesh Choudhary (4gust) merged 5 commits into
masterfrom
iinglese/easyauth-contract-validation-minimal

Conversation

@iNinja

@iNinja Ignacio Inglese (iNinja) commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Use the existing MSAL client credentials flow for both EasyAuth app-token methods.
  • Return a genuine app-only authentication result instead of the provider token associated with the signed-in user.
  • Keep EasyAuth user provider tokens opaque and preserve the existing user-token behavior.

Release notes

EasyAuth GetAuthenticationResultForAppAsync now performs client-credential acquisition and returns an app-only authentication result instead of the provider token associated with the signed-in user. Applications using this method must have valid application credentials and the required application permissions.

EasyAuth user-token behavior is unchanged. User-token methods continue to return the provider token supplied by App Services authentication for the current request.

Testing

  • 6 focused AppServicesAuthenticationTokenAcquisitionTests passed on .NET 8.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Enforces constraints on EasyAuth-provided user tokens while preserving unconstrained opaque-token behavior.

Changes:

  • Validates explicit tenant, audience, and delegated scopes.
  • Adds sovereign-cloud Microsoft Graph alias handling.
  • Separates app-token and user-token result behavior.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
src/Microsoft.Identity.Web/AppServicesAuth/AppServicesAuthenticationTokenAcquisition.cs Implements token constraints and tenant-aware app acquisition.
tests/Microsoft.Identity.Web.Test/AppServicesAuthenticationTokenAcquisitionTests.cs Adds focused EasyAuth behavior tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@bgavrilMS Bogdan Gavril (bgavrilMS) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clients MUST not parse tokens.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@iNinja Ignacio Inglese (iNinja) changed the title Enforce EasyAuth token request constraints Use app acquisition for EasyAuth app authentication results Sep 2, 2026
@4gust

Copy link
Copy Markdown
Contributor

I tested the manually and the fix works.

@4gust
Nilesh Choudhary (4gust) merged commit 7469616 into master Sep 8, 2026
10 checks passed
@4gust
Nilesh Choudhary (4gust) deleted the iinglese/easyauth-contract-validation-minimal branch September 8, 2026 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants