Skip to content

Added support for validating Microsoft Entra v2 access tokens - #46416

Merged
getvictor merged 17 commits into
mainfrom
victor/46388-entra-v2
Jun 1, 2026
Merged

getvictor merged 17 commits into
mainfrom
victor/46388-entra-v2

Conversation

@getvictor

@getvictor getvictor commented May 29, 2026 •

Copy link
Copy Markdown
Member

Related issue: Resolves #46388

Video demo: https://www.youtube.com/watch?v=t3yuGh0kwP8
Docs PR: #46483

Checklist for submitter

If some of the following don't apply, delete the relevant line.

  • Changes file added for user-visible changes in changes/, orbit/changes/ or ee/fleetd-chrome/changes.
  • Input data is properly validated, SELECT * is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters.

Testing

  • Added/updated automated tests
  • QA'd all new/changed functionality manually

Database migrations

  • Checked schema for all modified table for columns that will auto-update timestamps during migration.
  • Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects.

New Fleet configuration settings

If you didn't check the box above, follow this checklist for GitOps-enabled settings:

  • Verified that the setting is exported via fleetctl generate-gitops
  • Verified the setting is documented in a separate PR to the GitOps documentation
  • Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional)
  • Verified that any relevant UI is disabled when GitOps mode is enabled

Summary by CodeRabbit

  • New Features

    • UI to add/remove Entra application (client) IDs for Windows automatic enrollment; add/delete modals and list management.
  • Enhancements

    • Activity feed entries for added/removed Entra client IDs.
    • Entra client ID allowlist surfaced in GitOps and persisted config; client IDs normalized (trim/lowercase) and de-duplicated.
  • Documentation

    • Note: from July 1, 2026 new on‑prem Windows MDM apps receive Entra v2 tokens with aud = client ID; v1 tokens remain supported.

@getvictor
getvictor requested a review from Copilot May 29, 2026 02:26
@getvictor

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented May 29, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@getvictor

Copy link
Copy Markdown
Member Author

/agentic_review

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented May 29, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)

Grey Divider


Remediation recommended

1. Audience port not verified ✓ Resolved 🐞 Bug ⛨ Security
Description
hasAuthorizedAzureAudience authorizes v1 (URL) audiences by hostname-only comparison, so a token
with an audience URL on the same hostname but a different port/scheme is still accepted. If Fleet’s
configured ServerURL includes a non-default port, this weakens the audience check used for Windows
automatic enrollment and can authorize tokens minted for a different origin on the same host.
Code

server/service/microsoft_mdm.go[R984-990]

Evidence
The helper authorizes URL audiences via audURL.Hostname() equality only, and the call site passes
expectedURLParsed.Hostname() (dropping any configured port). The repo also demonstrates ServerURL
can include a port, meaning this hostname-only comparison can accept audiences for a different port
on the same host.

server/service/microsoft_mdm.go[960-993]
server/service/microsoft_mdm.go[1066-1091]
server/service/microsoft_mdm_test.go[1724-1746]
server/service/service_appconfig_test.go[47-56]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`hasAuthorizedAzureAudience` currently treats any URL audience whose **hostname** matches Fleet’s server hostname as authorized (v1 token path). This ignores **port** and **scheme**, so when Fleet is configured with a non-default port (e.g. `https://acme.co:8080/`), an audience such as `https://acme.co:443/...` (or any other port) is accepted.
### Issue Context
This check gates Windows automatic enrollment (`authBinarySecurityToken`). The prior behavior compared `audURL.Host` against `expectedURLParsed.Host` (host+port), but the new helper compares only `Hostname()`.
### Fix Focus Areas
- server/service/microsoft_mdm.go[960-993]
- server/service/microsoft_mdm.go[1066-1091]
- server/service/microsoft_mdm_test.go[1724-1766]
### What to change
- Change `hasAuthorizedAzureAudience` to accept the *full expected server URL* (or expected host+port+scheme) rather than just `serverHostname`.
- For v1 URL audiences:
- Parse both the expected server URL and each audience URL.
- Compare hostnames case-insensitively.
- Compare **ports** after normalizing defaults (e.g. treat empty port as `443` for `https`, `80` for `http`).
- Optionally also require scheme match (`http` vs `https`) if that’s part of the intended security boundary.
- Update unit tests to ensure:
- `:443` matches when expected is `https://host`.
- A non-default port does **not** match (e.g. expected `https://host:8080` must not accept `https://host:443`).

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Client ID case mismatch ✓ Resolved 🐞 Bug ≡ Correctness
Description
The Add Entra client ID UI validates input using validator.js isUUID, which accepts uppercase
UUIDs, but the backend requires a strict lowercase GUID regex (^[a-f0-9]{8}-...$). This allows
users to submit IDs that pass client-side validation but are rejected server-side, resulting in a
confusing failure path.
Code

frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/helpers.ts[R39-50]

Evidence
Frontend uses validator.js isUUID for client ID validation (case-insensitive), while backend
explicitly validates against a lowercase-only GUID regex for both tenant IDs and client IDs, so
uppercase UUIDs will pass FE but fail BE.

frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/helpers.ts[39-50]
frontend/components/forms/validators/valid_uuid/valid_uuid.ts[1-5]
server/service/appconfig.go[1522-1526]
server/service/appconfig.go[1842-1854]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Frontend validates Entra client IDs with `validator.js` `isUUID`, but backend validation requires canonical **lowercase** GUIDs via `windowsEntraGUIDRegex`. This mismatch causes inputs that appear valid in the UI to fail when saved.
### Issue Context
- FE: `isUUID` accepts uppercase hex.
- BE: `windowsEntraGUIDRegex` only matches `[a-f0-9]` (lowercase).
### Fix Focus Areas
- frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/helpers.ts[25-52]
- frontend/components/forms/validators/valid_uuid/valid_uuid.ts[1-5]
- server/service/appconfig.go[1522-1526]
- server/service/appconfig.go[1842-1854]
### What to change (pick one consistent approach)
**Option A (recommended): normalize client-side before submit**
- In `onChangeClientId` and/or before `configAPI.update`, `trim()` and `toLowerCase()` the client ID.
- Update the duplicate check to be case-insensitive.
**Option B: enforce lowercase in FE validation**
- Replace `isUUID` with the same canonical regex (or an equivalent) so the UI blocks uppercase.
**Option C: accept uppercase in BE but store canonical**
- In backend config modification, normalize to lowercase before validating/storing, while still rejecting non-canonical structural formats (braces, missing hyphens, etc.).
Also update the error messaging if you intentionally require lowercase (so users know what to fix).

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Client IDs may stay null ✓ Resolved 🐞 Bug ≡ Correctness
Description
ModifyAppConfig clears WindowsEntraClientIDs by only assigning .Value, so if the field is ever in
the optjson “Valid=false” state (e.g., PATCH sets it to null), it will continue to marshal back to
JSON null instead of []. This contradicts the migration’s goal of stabilizing GET /config and can
reintroduce noisy config diffs.
Code

server/service/appconfig.go[R512-515]

Evidence
The PR’s migration explicitly initializes windows_entra_client_ids as an empty array ([]) using
optjson.SetSlice, but ModifyAppConfig later clears the field by only setting .Value, which does not
update optjson’s Valid flag. optjson.Slice marshals to null whenever Valid is false (including after
UnmarshalJSON(null)), so the field can remain persisted/returned as null instead of [].

server/service/appconfig.go[507-515]
pkg/optjson/optjson.go[135-171]
server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs.go[14-21]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`optjson.Slice[T]` marshals to JSON `null` when `Valid=false`, regardless of the `Value` content. In `ModifyAppConfig`, the code clears `WindowsEntraClientIDs` (and similarly `WindowsEntraTenantIDs`) by assigning only `.Value = []string{}`. If the slice is in a `Valid=false` state (e.g., a client PATCHed `null` at some point), this assignment does not flip `Valid` back to `true`, so the persisted JSON remains `null`.
This undermines the migration’s explicit intent to keep `windows_entra_client_ids` as `[]` (not `null`) for stable `GET /config` responses and stable GitOps diffs.
### Issue Context
- `optjson.Slice.UnmarshalJSON(null)` sets `Set=true`, leaves `Valid=false`, and sets `Value` to an empty slice.
- `optjson.Slice.MarshalJSON()` returns `null` when `Valid=false`.
- The migration correctly uses `optjson.SetSlice([]string{})` (sets `Valid=true`) to initialize the field.
### Fix
When forcing these fields to be an empty array, assign the whole optjson value (or set `Valid=true`), e.g.:
- `appConfig.MDM.WindowsEntraClientIDs = optjson.SetSlice([]string{})`
- (and for consistency) `appConfig.MDM.WindowsEntraTenantIDs = optjson.SetSlice([]string{})`
### Fix Focus Areas
- server/service/appconfig.go[507-515]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds support for validating Microsoft Entra (Azure AD) v2 access tokens during Windows MDM automatic enrollment by authorizing tokens whose aud matches a configured Entra application client ID, while preserving the existing v1 aud (Fleet server URL host) behavior.

Changes:

  • Add mdm.windows_entra_client_ids app config setting (including migration) and validate it (premium-only, GUID format, Windows MDM enabled).
  • Update Windows MDM JWT audience authorization logic to accept either configured client IDs (v2) or server URL host (v1), plus add unit coverage for the matching helper.
  • Extend GitOps parsing/generation and anonymous statistics payload to include the new setting.

Reviewed changes

Copilot reviewed 19 out of 20 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
server/service/microsoft_mdm.go Adds shared audience-matching helper and uses it when authorizing Entra JWTs for Windows automatic enrollment.
server/service/microsoft_mdm_test.go Adds unit tests for the audience authorization helper (v1 URL-host and v2 client-ID paths).
server/service/client.go Ensures GitOps/app config patching includes windows_entra_client_ids with stable empty-array defaults.
server/service/appconfig.go Validates the new client ID allowlist, clears it when disabling Windows MDM, and emits add/remove activities.
server/service/appconfig_test.go Updates MDM config test fixtures and adds validation-focused test cases for the new setting.
server/fleet/app.go Adds WindowsEntraClientIDs to the fleet.MDM config struct and deep-copies it in AppConfig.Copy().
server/fleet/activities.go Introduces new activity types for adding/deleting Microsoft Entra client IDs.
server/fleet/statistics.go Adds numWindowsEntraClientIDs to the anonymous statistics payload.
server/datastore/mysql/statistics.go Populates the new statistics field from app config.
server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs.go Migration initializes mdm.windows_entra_client_ids to [] for upgraded installs.
server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs_test.go Verifies the migration initializes windows_entra_client_ids to an empty array in app config JSON.
pkg/spec/gitops.go Extends GitOps controls schema and Set() detection to include windows_entra_client_ids.
pkg/spec/gitops_test.go Asserts GitOps parsing includes the new key.
pkg/spec/testdata/team_config_no_paths.yml Adds windows_entra_client_ids: [] to GitOps testdata.
pkg/spec/testdata/team_config_invalid_sha.yml Adds windows_entra_client_ids: [] to GitOps testdata.
pkg/spec/testdata/global_config_no_paths.yml Adds windows_entra_client_ids: [] to GitOps testdata.
pkg/spec/testdata/controls.yml Adds windows_entra_client_ids: [] to GitOps testdata.
pkg/spec/testdata/controls_new_names.yml Adds windows_entra_client_ids: [] to GitOps testdata.
cmd/fleetctl/fleetctl/generate_gitops.go Emits windows_entra_client_ids in generated GitOps controls when configured and Windows MDM is enabled.
changes/46388-windows-entra-v2-access-tokens Adds a release note for v2 access token support and the new configuration key.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread changes/46388-windows-entra-v2-access-tokens Outdated
Comment thread server/service/appconfig.go Outdated
Comment thread server/service/appconfig_test.go
@coderabbitai

coderabbitai Bot commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Walkthrough

This pull request adds support for Microsoft Entra v2 access tokens during Windows MDM enrollment. It introduces a new AppConfig field for an Entra application client ID allowlist, a DB migration to initialize it, validation/normalization and activity emission on config changes, JWT audience authorization that accepts v2 client-ID GUIDs alongside existing v1 URL audiences, updated Azure claim extraction (UPN fallback and optional unique_name), GitOps and fleetctl support, frontend UI to manage client IDs, and tests covering unit, migration, and integration scenarios.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 68.42% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title 'Added support for validating Microsoft Entra v2 access tokens' clearly summarizes the main change - adding support for v2 token validation, which is the core objective of this PR.
Description check ✅ Passed The PR description is largely complete with checked boxes for changes file, input validation, testing, database migrations, and GitOps-enabled settings verification.
Linked Issues check ✅ Passed The PR implements all major coding requirements from #46388: new mdm.windows_entra_client_ids field with GUID validation, v2 token audience check (case-insensitive GUID matching), UPN fallback to preferred_username, migration seeding, activity events, frontend UI controls, GitOps support, and comprehensive tests.
Out of Scope Changes check ✅ Passed All changes are directly related to adding Microsoft Entra v2 token support and the associated configuration/UI infrastructure. No out-of-scope modifications were detected.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch victor/46388-entra-v2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@changes/46388-windows-entra-v2-access-tokens`:
- Line 1: Update the release note text to match Microsoft's wording and include
the official doc link: change the cutoff phrasing from "after 2026-07-01" to
"effective July 1, 2026" (or "starting July 1, 2026") and specify that this
applies to new on-premises MDM applications created via the Entra Portal flow;
keep that v1 tokens continue to work unchanged and retain the configuration
reference mdm.windows_entra_client_ids (or controls.windows_entra_client_ids)
and append the Microsoft link
https://learn.microsoft.com/en-us/windows/client-management/azure-active-directory-integration-with-mdm
for reference.

In
`@server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs_test.go`:
- Line 17: The test currently reads the app_config_json row with a
non-deterministic query (`SELECT json_value FROM app_config_json LIMIT 1`),
which relies on an implicit singleton invariant; update the test to explicitly
target the singleton row by querying with WHERE id = 1 (e.g., use `SELECT
json_value FROM app_config_json WHERE id = 1`) or alternatively add a clear
comment documenting the singleton invariant for app_config_json, referencing the
test that runs this query
(20260529120000_AddAppConfigMDMWindowsEntraClientIDs_test.go) so future changes
don’t introduce additional rows that break the assertion.

In `@server/service/microsoft_mdm.go`:
- Around line 969-988: The v1 audience host check in hasAuthorizedAzureAudience
currently does a case-sensitive compare between audURL.Host and serverHost which
can fail due to casing or default-port formatting; update the logic to
canonicalize both sides by parsing/normalizing hosts (split host and port,
remove default ports like :443 for https or :80 for http, or normalize to just
hostname) and then perform a case-insensitive comparison (e.g., use
strings.EqualFold on the normalized hostnames). Ensure you normalize serverHost
once (parse expected URL or host string) and apply the same normalization to
audURL.Host before comparing so v1 audience matches ignore case and default-port
differences.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: ba6db45b-c762-43fd-8355-1bc3dd5bbd13

📥 Commits

Reviewing files that changed from the base of the PR and between 8feb3bd and e9cd9ff.

📒 Files selected for processing (20)
  • changes/46388-windows-entra-v2-access-tokens
  • cmd/fleetctl/fleetctl/generate_gitops.go
  • pkg/spec/gitops.go
  • pkg/spec/gitops_test.go
  • pkg/spec/testdata/controls.yml
  • pkg/spec/testdata/controls_new_names.yml
  • pkg/spec/testdata/global_config_no_paths.yml
  • pkg/spec/testdata/team_config_invalid_sha.yml
  • pkg/spec/testdata/team_config_no_paths.yml
  • server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs.go
  • server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs_test.go
  • server/datastore/mysql/statistics.go
  • server/fleet/activities.go
  • server/fleet/app.go
  • server/fleet/statistics.go
  • server/service/appconfig.go
  • server/service/appconfig_test.go
  • server/service/client.go
  • server/service/microsoft_mdm.go
  • server/service/microsoft_mdm_test.go

Comment thread changes/46388-windows-entra-v2-access-tokens Outdated
Comment thread server/service/microsoft_mdm.go
@codecov

codecov Bot commented May 29, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 75.26882% with 46 lines in your changes missing coverage. Please review.
✅ Project coverage is 66.85%. Comparing base (9e10c3c) to head (91c6344).
⚠️ Report is 63 commits behind head on main.

Files with missing lines Patch % Lines
...vityFeed/GlobalActivityItem/GlobalActivityItem.tsx 0.00% 17 Missing ⚠️
...ts/AddEntraClientIDModal/AddEntraClientIDModal.tsx 62.85% 13 Missing ⚠️
server/service/appconfig.go 89.28% 4 Missing and 2 partials ⚠️
...0529120000_AddAppConfigMDMWindowsEntraClientIDs.go 66.66% 4 Missing ⚠️
server/service/microsoft_mdm.go 83.33% 2 Missing and 2 partials ⚠️
...ttings/components/AddEntraClientIDModal/helpers.ts 96.42% 1 Missing ⚠️
server/mdm/microsoft/wstep.go 80.00% 0 Missing and 1 partial ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #46416      +/-   ##
==========================================
+ Coverage   66.81%   66.85%   +0.04%     
==========================================
  Files        2804     2813       +9     
  Lines      223574   223893     +319     
  Branches    11346    11336      -10     
==========================================
+ Hits       149379   149689     +310     
+ Misses      60640    60630      -10     
- Partials    13555    13574      +19     
Flag Coverage Δ
backend 68.58% <85.84%> (+0.04%) ⬆️
frontend 56.52% <61.25%> (+0.04%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@getvictor

Copy link
Copy Markdown
Member Author

@coderabbitai full review

@getvictor

Copy link
Copy Markdown
Member Author

/agentic_review

@coderabbitai

coderabbitai Bot commented May 29, 2026

Copy link
Copy Markdown
Contributor
✅ Actions performed

Full review triggered.

@getvictor
getvictor requested a review from Copilot May 29, 2026 13:21
@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented May 29, 2026 •

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit c001e70

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 37 out of 38 changed files in this pull request and generated 3 comments.

Comment thread server/service/microsoft_mdm.go Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
server/mdm/microsoft/wstep.go (1)

411-484: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Don’t require unique_name in azureDataFromClaims (v2 tokens)

azureDataFromClaims currently fails with invalid UniqueName claim when claims["unique_name"] is missing. This blocks Entra v2 access tokens that use preferred_username instead. The automatic-enrollment auth path only uses tokenData.Audience, tokenData.TenantID, and returns tokenData.UPN—UniqueName isn’t used—so unique_name should be optional. Microsoft documents unique_name as v1-only and preferred_username as v2.
https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference

💡 Minimal fix
-	// Get UniqueName claim
-	uniqueNameClaim, ok := claims["unique_name"].(string)
-	if !ok {
-		return AzureData{}, ctxerr.New(ctx, "invalid UniqueName claim")
-	}
+	// `unique_name` is v1-only. Keep it when present, but don't reject v2 tokens that
+	// identify the user via `preferred_username`.
+	uniqueNameClaim, _ := claims["unique_name"].(string)
+	if uniqueNameClaim == "" {
+		uniqueNameClaim = upnClaim
+	}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/mdm/microsoft/wstep.go` around lines 411 - 484, azureDataFromClaims
currently returns an error if claims["unique_name"] is missing; make UniqueName
optional to support Entra v2 tokens that use preferred_username instead: in
azureDataFromClaims remove the hard failure on missing unique_name (the block
referencing uniqueNameClaim and the error "invalid UniqueName claim"), instead
set AzureData.UniqueName to the value if present
(claims["unique_name"].(string)) or leave it empty when absent; ensure
downstream use (e.g., automatic-enrollment path) continues to rely only on
Audience, TenantID and UPN.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/AddEntraClientIDModal.tsx`:
- Around line 60-68: The add flow treats clientId as possibly undefined and does
a case-sensitive duplicate check; update the AddEntraClientIDModal logic to
first narrow/guard clientId (e.g., early return if !clientId) so TypeScript
knows it's a string before using it in [...currentClientIds, clientId] and
configAPI.update, and perform a case-insensitive duplicate check by normalizing
both currentClientIds and clientId (e.g., compare currentClientIds.map(id =>
id.toLowerCase()) includes clientId.toLowerCase()) when computing clientIdExists
and before pushing into windows_entra_client_ids.

In
`@frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/EntraClientIDsListItem.tsx`:
- Around line 27-34: The icon-only delete Button in the EntraClientIDsListItem
component lacks an accessible name; update the Button (the element using props
disabled={disableChildren}, onClick={onClickDelete},
className={`${baseClass}__action-button`} and variant="icon") to include an
appropriate aria-label (e.g., "Delete client ID" or similar contextual text) so
screen readers can identify the action.

In
`@frontend/pages/DashboardPage/cards/ActivityFeed/GlobalActivityItem/GlobalActivityItem.tsx`:
- Around line 2098-2106: The addedMicrosoftEntraClientId and
deletedMicrosoftEntraClientId renderers currently interpolate
activity.details?.client_id directly which can produce "(undefined)"; update
both functions to guard the value and either omit the parenthetical when
client_id is falsy or supply a safe fallback (e.g., "unknown" or "unspecified")
and render accordingly so the UI never shows "undefined" in the activity text.

In `@server/service/appconfig.go`:
- Around line 1522-1525: The windowsEntraGUIDRegex only accepts lowercase hex
and rejects valid GUIDs with A-F; update its pattern to accept uppercase hex as
well (e.g. make character classes include A-F or use a case-insensitive regex
flag) so the Entra tenant and application client ID validations that use
windowsEntraGUIDRegex (the validation calls around the current checks) will
accept valid UUIDs in either case.

---

Outside diff comments:
In `@server/mdm/microsoft/wstep.go`:
- Around line 411-484: azureDataFromClaims currently returns an error if
claims["unique_name"] is missing; make UniqueName optional to support Entra v2
tokens that use preferred_username instead: in azureDataFromClaims remove the
hard failure on missing unique_name (the block referencing uniqueNameClaim and
the error "invalid UniqueName claim"), instead set AzureData.UniqueName to the
value if present (claims["unique_name"].(string)) or leave it empty when absent;
ensure downstream use (e.g., automatic-enrollment path) continues to rely only
on Audience, TenantID and UPN.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 20f97e63-6dc1-47af-88d1-ebd26479dfd8

📥 Commits

Reviewing files that changed from the base of the PR and between 8feb3bd and c001e70.

📒 Files selected for processing (38)
  • changes/46388-windows-entra-v2-access-tokens
  • cmd/fleetctl/fleetctl/generate_gitops.go
  • frontend/__mocks__/configMock.ts
  • frontend/interfaces/activity.ts
  • frontend/interfaces/config.ts
  • frontend/pages/DashboardPage/cards/ActivityFeed/GlobalActivityItem/GlobalActivityItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListHeader/EntraClientIDsListHeader.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListHeader/_styles.scss
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListHeader/index.ts
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/EntraClientIDsListItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/_styles.scss
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/index.ts
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/WindowsAutomaticEnrollmentPage.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/AddEntraClientIDModal.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/helpers.ts
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/index.ts
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/DeleteEntraClientIDModal/DeleteEntraClientIDModal.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/DeleteEntraClientIDModal/index.ts
  • pkg/spec/gitops.go
  • pkg/spec/gitops_test.go
  • pkg/spec/testdata/controls.yml
  • pkg/spec/testdata/controls_new_names.yml
  • pkg/spec/testdata/global_config_no_paths.yml
  • pkg/spec/testdata/team_config_invalid_sha.yml
  • pkg/spec/testdata/team_config_no_paths.yml
  • server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs.go
  • server/datastore/mysql/migrations/tables/20260529120000_AddAppConfigMDMWindowsEntraClientIDs_test.go
  • server/datastore/mysql/statistics.go
  • server/fleet/activities.go
  • server/fleet/app.go
  • server/fleet/statistics.go
  • server/mdm/microsoft/wstep.go
  • server/mdm/microsoft/wstep_test.go
  • server/service/appconfig.go
  • server/service/appconfig_test.go
  • server/service/client.go
  • server/service/microsoft_mdm.go
  • server/service/microsoft_mdm_test.go

Comment thread server/service/appconfig.go Outdated
@getvictor
getvictor marked this pull request as ready for review May 29, 2026 23:50
@getvictor
getvictor requested review from a team as code owners May 29, 2026 23:50

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.


// do an additional validation to check if the client id already exists in the config
const clientIdExists =
config?.mdm.windows_entra_client_ids?.includes(clientId ?? "") ?? false;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confused a bit.

Array.includes() is strict equality. The input has been lowercased, but config.mdm.windows_entra_client_ids contains whatever was stored which could be uppercase if the list was populated via GitOps or the API directly. The backend hasAuthorizedAzureAudience uses case-insensitive comparison, so both entries would authorize the same v2 token. So could the UI display two list entries that are functionally identical?

Comment thread server/mdm/microsoft/wstep.go Outdated
upnClaim, ok := claims["upn"].(string)
if !ok || len(upnClaim) == 0 {
return AzureData{}, ctxerr.New(ctx, "invalid UPN claim")
upnClaim, ok = claims["preferred_username"].(string)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

On https://learn.microsoft.com/en-us/entra/identity-platform/access-token-claims-reference
The preferred_username entry there states: "Its value is mutable and might change over time. Since it's mutable, this value can't be used to make authorization decisions." Is it safe to use preferred_username.

Also just making sure but is the profile scope present in the token? As far as I understand the preferred_username needs that to appear at all, so if a v2 token is issued without that scope, the fallback would also fail and Fleet would reject the token entirely.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct, preferred_username (or upn) is never compared against anything to grant or deny enrollment

I'll make the change to make it optional like unique_name.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
server/service/microsoft_mdm_test.go (1)

1748-1752: ⚡ Quick win

Add the reverse case-insensitivity regression for configured client IDs.

These cases only prove that an upper-cased token aud matches a lower-cased configured ID. Please also cover the inverse (clientIDs: []string{strings.ToUpper(clientID)}, audiences: []string{clientID}), otherwise an implementation that only normalizes the token side would still pass.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/service/microsoft_mdm_test.go` around lines 1748 - 1752, Add
complementary test rows to microsoft_mdm_test.go to cover the reverse
case-insensitivity of configured client IDs (so implementations that only
normalize the token side fail). Specifically add cases like "v2 configured
client ID uppercase" with clientIDs: []string{strings.ToUpper(clientID)} and
audiences: []string{clientID} expecting true, and "v2 configured client ID
uppercase with surrounding whitespace" with clientIDs: []string{"  " +
strings.ToUpper(clientID) + "  "} and audiences: []string{clientID} expecting
true; mirror the existing tests that reference clientID and clientID2 to ensure
both single and multi-config scenarios are covered.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@server/service/appconfig.go`:
- Around line 517-533: The code currently normalizes and de-duplicates
admin-provided Entra client IDs by mutating
appConfig.MDM.WindowsEntraClientIDs.Value; remove this normalization so stored
values remain exactly as provided (do not trim, lowercase, or dedupe on write).
Instead, perform canonicalization (trim+lowercase and dedupe) only at comparison
time where the values are checked (e.g., in hasAuthorizedAzureAudience or the
authorization-checking path that consumes appConfig.MDM.WindowsEntraClientIDs)
so comparisons remain case-insensitive but saved config is unchanged.

---

Nitpick comments:
In `@server/service/microsoft_mdm_test.go`:
- Around line 1748-1752: Add complementary test rows to microsoft_mdm_test.go to
cover the reverse case-insensitivity of configured client IDs (so
implementations that only normalize the token side fail). Specifically add cases
like "v2 configured client ID uppercase" with clientIDs:
[]string{strings.ToUpper(clientID)} and audiences: []string{clientID} expecting
true, and "v2 configured client ID uppercase with surrounding whitespace" with
clientIDs: []string{"  " + strings.ToUpper(clientID) + "  "} and audiences:
[]string{clientID} expecting true; mirror the existing tests that reference
clientID and clientID2 to ensure both single and multi-config scenarios are
covered.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: d9fc46e6-a1e4-496d-ac00-3f26e49c067f

📥 Commits

Reviewing files that changed from the base of the PR and between c001e70 and ee3d68b.

📒 Files selected for processing (31)
  • changes/46388-windows-entra-v2-access-tokens
  • cmd/fleetctl/fleetctl/gitops_test.go
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigJson.json
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigTeamMaintainerJson.json
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigTeamMaintainerYaml.yml
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigYaml.yml
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigIncludeServerConfigJson.json
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigIncludeServerConfigYaml.yml
  • cmd/fleetctl/fleetctl/testdata/generateGitops/appConfig.json
  • cmd/fleetctl/fleetctl/testdata/generateGitops/expectedGlobalControls.yaml
  • cmd/fleetctl/fleetctl/testdata/generateGitops/test_dir_premium/fleets/unassigned.yml
  • cmd/fleetctl/fleetctl/testdata/macosSetupExpectedAppConfigEmpty.yml
  • cmd/fleetctl/fleetctl/testdata/macosSetupExpectedAppConfigSet.yml
  • frontend/interfaces/config.ts
  • frontend/pages/DashboardPage/cards/ActivityFeed/GlobalActivityItem/GlobalActivityItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/EntraClientIDsListItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraTenantsListItem/EntraTenantsListItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/WindowsAutomaticEnrollmentPage.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/_styles.scss
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/AddEntraClientIDModal.tests.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/AddEntraClientIDModal.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/DeleteEntraClientIDModal/DeleteEntraClientIDModal.tsx
  • server/datastore/mysql/schema.sql
  • server/fleet/app.go
  • server/mdm/microsoft/wstep.go
  • server/mdm/microsoft/wstep_test.go
  • server/service/appconfig.go
  • server/service/appconfig_test.go
  • server/service/microsoft_mdm.go
  • server/service/microsoft_mdm_test.go
  • tools/cloner-check/generated_files/appconfig.txt
✅ Files skipped from review due to trivial changes (9)
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigIncludeServerConfigJson.json
  • tools/cloner-check/generated_files/appconfig.txt
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigTeamMaintainerJson.json
  • cmd/fleetctl/fleetctl/testdata/generateGitops/expectedGlobalControls.yaml
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigYaml.yml
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigTeamMaintainerYaml.yml
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigIncludeServerConfigYaml.yml
  • changes/46388-windows-entra-v2-access-tokens
  • server/mdm/microsoft/wstep_test.go
🚧 Files skipped from review as they are similar to previous changes (15)
  • cmd/fleetctl/fleetctl/testdata/macosSetupExpectedAppConfigSet.yml
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraTenantsListItem/EntraTenantsListItem.tsx
  • cmd/fleetctl/fleetctl/testdata/expectedGetConfigAppConfigJson.json
  • frontend/interfaces/config.ts
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/EntraClientIDsListItem/EntraClientIDsListItem.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/_styles.scss
  • server/fleet/app.go
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/WindowsAutomaticEnrollmentPage/WindowsAutomaticEnrollmentPage.tsx
  • server/mdm/microsoft/wstep.go
  • frontend/pages/DashboardPage/cards/ActivityFeed/GlobalActivityItem/GlobalActivityItem.tsx
  • cmd/fleetctl/fleetctl/testdata/generateGitops/appConfig.json
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/DeleteEntraClientIDModal/DeleteEntraClientIDModal.tsx
  • frontend/pages/admin/IntegrationsPage/cards/MdmSettings/components/AddEntraClientIDModal/AddEntraClientIDModal.tsx
  • server/datastore/mysql/schema.sql
  • server/service/microsoft_mdm.go

Comment on lines +517 to 533
// Normalize Entra client IDs to canonical lower-case and de-duplicate them. They are authorized
// case-insensitively (see hasAuthorizedAzureAudience), so storing them canonically prevents
// functionally-identical duplicates that differ only in case (for example, an upper-case ID added via
// GitOps or the API alongside a lower-case one added through the UI).
if appConfig.MDM.WindowsEntraClientIDs.Set && appConfig.MDM.WindowsEntraClientIDs.Valid {
seen := make(map[string]struct{}, len(appConfig.MDM.WindowsEntraClientIDs.Value))
normalized := make([]string, 0, len(appConfig.MDM.WindowsEntraClientIDs.Value))
for _, clientID := range appConfig.MDM.WindowsEntraClientIDs.Value {
id := strings.ToLower(strings.TrimSpace(clientID))
if _, ok := seen[id]; ok {
continue
}
seen[id] = struct{}{}
normalized = append(normalized, id)
}
appConfig.MDM.WindowsEntraClientIDs.Value = normalized
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Don't canonicalize stored Entra client IDs.

This mutates admin-provided config by trimming, lower-casing, and de-duplicating it before save. The PR contract says client IDs should be compared case-insensitively, not rewritten on write, so this will cause GitOps/API read-after-write drift and case-only edits to disappear. Keep the raw stored values and do the case-insensitive handling only at comparison/activity time.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@server/service/appconfig.go` around lines 517 - 533, The code currently
normalizes and de-duplicates admin-provided Entra client IDs by mutating
appConfig.MDM.WindowsEntraClientIDs.Value; remove this normalization so stored
values remain exactly as provided (do not trim, lowercase, or dedupe on write).
Instead, perform canonicalization (trim+lowercase and dedupe) only at comparison
time where the values are checked (e.g., in hasAuthorizedAzureAudience or the
authorization-checking path that consumes appConfig.MDM.WindowsEntraClientIDs)
so comparisons remain case-insensitive but saved config is unchanged.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmd/fleetctl/fleetctl/gitops_test.go`:
- Around line 571-573: The test is asserting that client IDs are stored
lower-cased and de-duplicated, but the feature requires case-insensitive
matching for validation while preserving the original stored values; update the
assertions in gitops_test.go (the `fleetctl gitops apply` test) so they no
longer expect canonical lower-casing or case-only de-duplication — instead
assert that the stored client IDs equal the original input list (including the
upper-case GUID and its case-only duplicate) at the three assertion sites
mentioned (around the current checks at ~571, ~596, and ~619-621), i.e. replace
expectations that downcase/deduplicate with equality to the original client ID
entries while leaving token-validation tests unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 66f43c2b-1edc-4015-bb63-38c9e9d54875

📥 Commits

Reviewing files that changed from the base of the PR and between ee3d68b and 91c6344.

📒 Files selected for processing (1)
  • cmd/fleetctl/fleetctl/gitops_test.go

Comment on lines +571 to +573
// `fleetctl gitops` apply (issue #46388). The client IDs include an upper-case GUID and a case-only duplicate of it,
// which exercises server-side normalization: client IDs are authorized case-insensitively, so they are stored
// canonically (lower-cased and de-duplicated) to avoid functionally-identical entries that differ only in case.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

This test now asserts the wrong storage contract.

The PR objective says Entra client IDs should be matched case-insensitively for token validation but stored without normalization. Expecting lower-casing and case-only de-duplication here would fail a correct implementation and bakes in behavior the feature explicitly says not to add.

Suggested expectation update
-// which exercises server-side normalization: client IDs are authorized case-insensitively, so they are stored
-// canonically (lower-cased and de-duplicated) to avoid functionally-identical entries that differ only in case.
+// which exercises case-insensitive audience matching. Stored config values should still be preserved as provided.

-	// The upper-case client ID and its case-only duplicate are normalized to a single canonical lower-case entry.
+	// Client IDs should round-trip without storage normalization.
 	require.Equal(t,
-		[]string{"abcdef12-3456-7890-abcd-ef1234567890", "11111111-2222-3333-4444-555555555555"},
+		[]string{
+			"ABCDEF12-3456-7890-ABCD-EF1234567890",
+			"abcdef12-3456-7890-abcd-ef1234567890",
+			"11111111-2222-3333-4444-555555555555",
+		},
 		(*savedAppConfigPtr).MDM.WindowsEntraClientIDs.Value)

Also applies to: 596-596, 619-621

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/fleetctl/fleetctl/gitops_test.go` around lines 571 - 573, The test is
asserting that client IDs are stored lower-cased and de-duplicated, but the
feature requires case-insensitive matching for validation while preserving the
original stored values; update the assertions in gitops_test.go (the `fleetctl
gitops apply` test) so they no longer expect canonical lower-casing or case-only
de-duplication — instead assert that the stored client IDs equal the original
input list (including the upper-case GUID and its case-only duplicate) at the
three assertion sites mentioned (around the current checks at ~571, ~596, and
~619-621), i.e. replace expectations that downcase/deduplicate with equality to
the original client ID entries while leaving token-validation tests unchanged.

@ksykulev ksykulev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

CI Feedback 🧐

A test triggered by this PR failed. Here is an AI-generated analysis of the failure:

Action: test-go (fleetctl, mysql:8.0.44) / test

Failed stage: Run Go Tests [❌]

Failed test name: TestIntegrationsVulnerabilityDataStream

Failure summary:

The action failed because the Go integration test TestIntegrationsVulnerabilityDataStream failed in
cmd/fleetctl/integrationtest/vuln (reported at
cmd/fleetctl/integrationtest/vuln/vulnerability_data_stream_test.go:44).
The test error was:
- Error
downloading OSV artifacts: getting latest release: github http status error: 403
This indicates the
test depends on downloading artifacts from GitHub/OSV during the run, but the request was forbidden
(HTTP 403), causing make test-go to exit non-zero (make[1]: *** [Makefile:286: .run-go-tests] Error
1, make: *** [Makefile:401: test-go] Error 2).

Relevant error logs:
1:  ##[group]Runner Image Provisioner
2:  Hosted Compute Agent
...

1062:  �[36;1mattempt=1�[0m
1063:  �[36;1m�[0m
1064:  �[36;1mwhile [ $attempt -le $max_attempts ]; do�[0m
1065:  �[36;1m  echo "Attempt $attempt of $max_attempts"�[0m
1066:  �[36;1m�[0m
1067:  �[36;1m  # Try to connect to MySQL�[0m
1068:  �[36;1m  if wait_for_mysql "mysql_test"; then�[0m
1069:  �[36;1m    # If MySQL is ready, try to connect to MySQL replica�[0m
1070:  �[36;1m    if wait_for_mysql "mysql_replica_test"; then�[0m
1071:  �[36;1m      # Both are ready, we're done�[0m
1072:  �[36;1m      echo "All MySQL connections successful"�[0m
1073:  �[36;1m      exit 0�[0m
1074:  �[36;1m    fi�[0m
1075:  �[36;1m  fi�[0m
1076:  �[36;1m�[0m
1077:  �[36;1m  # If we get here, at least one connection failed�[0m
1078:  �[36;1m  echo "Failed to connect to MySQL on attempt $attempt"�[0m
1079:  �[36;1m�[0m
1080:  �[36;1m  if [ $attempt -lt $max_attempts ]; then�[0m
1081:  �[36;1m    echo "Restarting containers and trying again..."�[0m
1082:  �[36;1m    restart_containers�[0m
1083:  �[36;1m  else�[0m
1084:  �[36;1m    echo "Maximum attempts reached. Failing the job."�[0m
1085:  �[36;1m    exit 1�[0m
...

1364:  go: downloading github.com/hashicorp/golang-lru v0.5.4
1365:  go: downloading github.com/pmezard/go-difflib v1.0.0
1366:  go: downloading github.com/stretchr/objx v0.5.2
1367:  go: downloading github.com/pkg/term v0.0.0-20190109203006-aa71e9d9e942
1368:  github.com/fleetdm/fleet/v4/cmd/fleetctl:
1369:  github.com/fleetdm/fleet/v4/cmd/fleetctl/fleetctl/testing_utils:
1370:  github.com/fleetdm/fleet/v4/cmd/fleetctl/fleetctl/goquerycmd:
1371:  github.com/fleetdm/fleet/v4/cmd/fleetctl/fleetctl/fleetctltest:
1372:  github.com/fleetdm/fleet/v4/cmd/fleetctl/integrationtest:
1373:  github.com/fleetdm/fleet/v4/cmd/fleetctl/integrationtest/package:
1374:  �[32m✓�[0m Package (3.52s)
1375:  �[32m✓�[0m Package - -use-sytem-configuration can't be used on installers that aren't pkg (0.00s)
1376:  �[32m✓�[0m Package deb (1.85s)
1377:  github.com/fleetdm/fleet/v4/cmd/fleetctl/integrationtest/preview:
1378:  �[32m✓�[0m Integrations preview (53.69s)
1379:  �[32m✓�[0m Preview fails on invalid license key (0.00s)
1380:  github.com/fleetdm/fleet/v4/cmd/fleetctl/integrationtest/vuln:
...

1487:  �[32m✓�[0m Apply specs deprecated keys app config windows updates.grace period days not a number (0.42s)
1488:  �[32m✓�[0m Apply specs deprecated keys app config windows updates.grace period days out of range (0.44s)
1489:  �[32m✓�[0m Apply specs deprecated keys config with FIM values for agent options (#869 9) (0.48s)
1490:  �[32m✓�[0m Apply specs deprecated keys config with blank required org name (0.37s)
1491:  �[32m✓�[0m Apply specs deprecated keys config with blank required server url (0.43s)
1492:  �[32m✓�[0m Apply specs deprecated keys config with invalid agent options command-line flags (0.54s)
1493:  �[32m✓�[0m Apply specs deprecated keys config with invalid agent options data type in dry-run (0.50s)
1494:  �[32m✓�[0m Apply specs deprecated keys config with invalid agent options data type with force (0.38s)
1495:  �[32m✓�[0m Apply specs deprecated keys config with invalid agent options in dry-run (0.38s)
1496:  �[32m✓�[0m Apply specs deprecated keys config with invalid key type (0.45s)
1497:  �[32m✓�[0m Apply specs deprecated keys config with invalid value for agent options command-line flags (0.50s)
1498:  �[32m✓�[0m Apply specs deprecated keys config with unknown key (0.47s)
1499:  �[32m✓�[0m Apply specs deprecated keys config with valid agent options command-line flags (0.40s)
1500:  �[32m✓�[0m Apply specs deprecated keys dry-run set with unsupported spec (0.38s)
1501:  �[32m✓�[0m Apply specs deprecated keys dry-run set with various specs, appconfig warning for legacy (0.37s)
1502:  �[32m✓�[0m Apply specs deprecated keys dry-run set with various specs, no errors (0.40s)
1503:  �[32m✓�[0m Apply specs deprecated keys empty config (0.37s)
...

1506:  �[32m✓�[0m Apply specs deprecated keys invalid agent options dry-run (0.51s)
1507:  �[32m✓�[0m Apply specs deprecated keys invalid agent options field type (0.53s)
1508:  �[32m✓�[0m Apply specs deprecated keys invalid agent options field type in overrides (0.64s)
1509:  �[32m✓�[0m Apply specs deprecated keys invalid agent options for existing team (0.46s)
1510:  �[32m✓�[0m Apply specs deprecated keys invalid agent options for new team (0.55s)
1511:  �[32m✓�[0m Apply specs deprecated keys invalid agent options force (0.44s)
1512:  �[32m✓�[0m Apply specs deprecated keys invalid known key's value type for team cannot be forced (0.41s)
1513:  �[32m✓�[0m Apply specs deprecated keys invalid team agent options command-line flag (0.40s)
1514:  �[32m✓�[0m Apply specs deprecated keys invalid top-level key for team (0.37s)
1515:  �[32m✓�[0m Apply specs deprecated keys macos updates deadline set but minimum version empty (0.35s)
1516:  �[32m✓�[0m Apply specs deprecated keys macos updates minimum version set but deadline empty (0.35s)
1517:  �[32m✓�[0m Apply specs deprecated keys macos updates.deadline with incomplete date (0.37s)
1518:  �[32m✓�[0m Apply specs deprecated keys macos updates.deadline with invalid date (0.40s)
1519:  �[32m✓�[0m Apply specs deprecated keys macos updates.deadline with timestamp (0.52s)
1520:  �[32m✓�[0m Apply specs deprecated keys macos updates.minimum version with build version (0.40s)
1521:  �[32m✓�[0m Apply specs deprecated keys missing required failing policies destination url (0.54s)
1522:  �[32m✓�[0m Apply specs deprecated keys missing required host status days count (0.39s)
...

1530:  �[32m✓�[0m Apply specs deprecated keys team config macos settings.enable disk encryption true (0.40s)
1531:  �[32m✓�[0m Apply specs deprecated keys team config macos settings.enable disk encryption with invalid value type (0.39s)
1532:  �[32m✓�[0m Apply specs deprecated keys team config macos settings.enable disk encryption without a value (0.38s)
1533:  �[32m✓�[0m Apply specs deprecated keys unknown key for team can be forced (0.53s)
1534:  �[32m✓�[0m Apply specs deprecated keys valid team agent options command-line flag (0.36s)
1535:  �[32m✓�[0m Apply specs deprecated keys windows updates unset valid (0.48s)
1536:  �[32m✓�[0m Apply specs deprecated keys windows updates valid (0.50s)
1537:  �[32m✓�[0m Apply specs deprecated keys windows updates.deadline days but grace period empty (0.58s)
1538:  �[32m✓�[0m Apply specs deprecated keys windows updates.deadline days not a number (0.41s)
1539:  �[32m✓�[0m Apply specs deprecated keys windows updates.deadline days out of range (0.55s)
1540:  �[32m✓�[0m Apply specs deprecated keys windows updates.grace period days but deadline empty (0.36s)
1541:  �[32m✓�[0m Apply specs deprecated keys windows updates.grace period days not a number (0.45s)
1542:  �[32m✓�[0m Apply specs deprecated keys windows updates.grace period days out of range (0.39s)
1543:  �[32m✓�[0m Apply specs dry-run set with unsupported spec (0.37s)
1544:  �[32m✓�[0m Apply specs dry-run set with various specs, appconfig warning for legacy (0.36s)
1545:  �[32m✓�[0m Apply specs dry-run set with various specs, no errors (0.46s)
1546:  �[32m✓�[0m Apply specs empty config (0.49s)
...

1549:  �[32m✓�[0m Apply specs invalid agent options dry-run (0.39s)
1550:  �[32m✓�[0m Apply specs invalid agent options field type (0.46s)
1551:  �[32m✓�[0m Apply specs invalid agent options field type in overrides (0.48s)
1552:  �[32m✓�[0m Apply specs invalid agent options for existing team (0.39s)
1553:  �[32m✓�[0m Apply specs invalid agent options for new team (0.38s)
1554:  �[32m✓�[0m Apply specs invalid agent options force (0.45s)
1555:  �[32m✓�[0m Apply specs invalid known key's value type for team cannot be forced (0.45s)
1556:  �[32m✓�[0m Apply specs invalid team agent options command-line flag (0.42s)
1557:  �[32m✓�[0m Apply specs invalid top-level key for team (0.38s)
1558:  �[32m✓�[0m Apply specs macos updates deadline set but minimum version empty (0.39s)
1559:  �[32m✓�[0m Apply specs macos updates minimum version set but deadline empty (0.36s)
1560:  �[32m✓�[0m Apply specs macos updates.deadline with incomplete date (0.33s)
1561:  �[32m✓�[0m Apply specs macos updates.deadline with invalid date (0.39s)
1562:  �[32m✓�[0m Apply specs macos updates.deadline with timestamp (0.47s)
1563:  �[32m✓�[0m Apply specs macos updates.minimum version with build version (0.40s)
1564:  �[32m✓�[0m Apply specs missing required failing policies destination url (0.53s)
1565:  �[32m✓�[0m Apply specs missing required host status days count (0.47s)
...

1584:  �[32m✓�[0m Apply specs windows updates.grace period days not a number (0.42s)
1585:  �[32m✓�[0m Apply specs windows updates.grace period days out of range (0.41s)
1586:  �[32m✓�[0m Apply team specs (0.55s)
1587:  �[32m✓�[0m Apply user roles (0.35s)
1588:  �[32m✓�[0m Apply user roles deprecated (0.69s)
1589:  �[32m✓�[0m Apply windows updates (0.35s)
1590:  �[32m✓�[0m Apply windows updates field omitted (0.00s)
1591:  �[32m✓�[0m Apply windows updates with null values (0.00s)
1592:  �[32m✓�[0m Apply windows updates with values (0.00s)
1593:  �[32m✓�[0m Can apply intervals in nanoseconds (0.54s)
1594:  �[32m✓�[0m Can apply intervals using durations (0.47s)
1595:  �[32m✓�[0m Clean status code err (0.00s)
1596:  �[32m✓�[0m Clean status code err bare wrapped status code err (0.00s)
1597:  �[32m✓�[0m Clean status code err nil (0.00s)
1598:  �[32m✓�[0m Clean status code err outer-wrapped status code err (0.00s)
1599:  �[32m✓�[0m Clean status code err plain error untouched (0.00s)
1600:  �[32m✓�[0m Compute label changes (0.00s)
...

1656:  �[32m✓�[0m Filename functions (0.00s)
1657:  �[32m✓�[0m Filename functions outfile name builds a file name using the name provided + current time (0.00s)
1658:  �[32m✓�[0m Filename functions outfile name with ext builds a file name using the name and extension provided + current time (0.00s)
1659:  �[32m✓�[0m FleetctlUpgradePacks empty packs (0.43s)
1660:  �[32m✓�[0m FleetctlUpgradePacks no pack (0.36s)
1661:  �[32m✓�[0m FleetctlUpgradePacks non empty (0.43s)
1662:  �[32m✓�[0m FleetctlUpgradePacks not admin (0.36s)
1663:  �[32m✓�[0m Format XML (0.00s)
1664:  �[32m✓�[0m Format XML XML with attributes (0.00s)
1665:  �[32m✓�[0m Format XML basic XML (0.00s)
1666:  �[32m✓�[0m Format XML empty XML (0.00s)
1667:  �[32m✓�[0m Format XML invalid XML (0.00s)
1668:  �[32m✓�[0m Format XML nested XML (0.00s)
1669:  �[32m✓�[0m Generate MDM apple (0.93s)
1670:  �[32m✓�[0m Generate MDM apple BM (0.50s)
1671:  �[32m✓�[0m Generate MDM apple CSR API call fails (0.49s)
1672:  �[32m✓�[0m Generate MDM apple successful run (0.45s)
1673:  �[32m✓�[0m Generate MDMVPP tokens (0.00s)
1674:  �[32m✓�[0m Generate MDMVPP tokens get VPP tokens error (0.00s)
1675:  �[32m✓�[0m Generate MDMVPP tokens multiple tokens with different teams (0.00s)
...

1691:  �[32m✓�[0m Generate org settings insecure (0.01s)
1692:  �[32m✓�[0m Generate org settings masked google calendar api key (0.00s)
1693:  �[32m✓�[0m Generate policies (0.00s)
1694:  �[32m✓�[0m Generate queries (0.00s)
1695:  �[32m✓�[0m Generate software (0.00s)
1696:  �[32m✓�[0m Generate software auto update schedule (0.00s)
1697:  �[32m✓�[0m Generate software script packages (0.00s)
1698:  �[32m✓�[0m Generate team settings (0.00s)
1699:  �[32m✓�[0m Generate team settings insecure (0.00s)
1700:  �[32m✓�[0m Generated org settings no SSO (0.00s)
1701:  �[32m✓�[0m Generated org settings okta conditional access not included (0.00s)
1702:  �[32m✓�[0m Get MDM command results (0.46s)
1703:  �[32m✓�[0m Get MDM command results command flag required (0.00s)
1704:  �[32m✓�[0m Get MDM command results command not found (0.01s)
1705:  �[32m✓�[0m Get MDM command results command results empty (0.01s)
1706:  �[32m✓�[0m Get MDM command results command results error (0.01s)
1707:  �[32m✓�[0m Get MDM command results darwin command results (0.00s)
1708:  �[32m✓�[0m Get MDM command results host specific results (0.00s)
1709:  �[32m✓�[0m Get MDM command results windows command results (0.00s)
1710:  �[32m✓�[0m Get MDM commands (0.49s)
1711:  �[32m✓�[0m Get apple BM (1.55s)
1712:  �[32m✓�[0m Get apple BM free license (0.38s)
1713:  �[32m✓�[0m Get apple BM premium license, multiple tokens (0.44s)
1714:  �[32m✓�[0m Get apple BM premium license, no token (0.32s)
1715:  �[32m✓�[0m Get apple BM premium license, single token (0.42s)
1716:  �[32m✓�[0m Get apple MDM (0.39s)
1717:  �[32m✓�[0m Get carve (0.36s)
1718:  �[32m✓�[0m Get carve with error (0.40s)
1719:  �[32m✓�[0m Get carves (0.44s)
...

1726:  �[32m✓�[0m Get config app config as team users (0.04s)
1727:  �[32m✓�[0m Get config include server config (0.02s)
1728:  �[32m✓�[0m Get config remove deprecated keys (0.00s)
1729:  �[32m✓�[0m Get enrollment secrets (0.47s)
1730:  �[32m✓�[0m Get hosts (0.40s)
1731:  �[32m✓�[0m Get hosts MDM (0.49s)
1732:  �[32m✓�[0m Get hosts MDM get hosts - -mdm - -json - expected list hosts MD m .json (0.00s)
1733:  �[32m✓�[0m Get hosts MDM get hosts - -mdm - -mdm-pending - (0.00s)
1734:  �[32m✓�[0m Get hosts MDM get hosts - -mdm-pending - -yaml - expected list hosts yaml.yml (0.01s)
1735:  �[32m✓�[0m Get hosts get hosts - -json - -remove-deprecated-keys (0.00s)
1736:  �[32m✓�[0m Get hosts get hosts - -json - expected list hosts json.json (0.00s)
1737:  �[32m✓�[0m Get hosts get hosts - -json test host - expected host detail response json.json (0.00s)
1738:  �[32m✓�[0m Get hosts get hosts - -yaml - expected list hosts yaml.yml (0.00s)
1739:  �[32m✓�[0m Get hosts get hosts - -yaml test host - expected host detail response yaml.yml (0.00s)
1740:  �[32m✓�[0m Get label (0.40s)
1741:  �[32m✓�[0m Get label usage multiple label keys error (0.00s)
1742:  �[32m✓�[0m Get label usage profile path shortened (0.00s)
...

1750:  �[32m✓�[0m Get queries as observer team observer (0.01s)
1751:  �[32m✓�[0m Get query (0.49s)
1752:  �[32m✓�[0m Get query labels include all (0.44s)
1753:  �[32m✓�[0m Get reports labels include all (0.57s)
1754:  �[32m✓�[0m Get software titles (0.42s)
1755:  �[32m✓�[0m Get software versions (0.43s)
1756:  �[32m✓�[0m Get teams (0.87s)
1757:  �[32m✓�[0m Get teams YAML and apply (0.41s)
1758:  �[32m✓�[0m Get teams by name (0.46s)
1759:  �[32m✓�[0m Get teams expired license (0.40s)
1760:  �[32m✓�[0m Get teams not expired license (0.47s)
1761:  �[32m✓�[0m Get teams software from source of truth (0.39s)
1762:  �[32m✓�[0m Get user roles (0.36s)
1763:  �[32m✓�[0m Git ops ABM (5.59s)
1764:  �[32m✓�[0m Git ops ABM backwards compat (0.60s)
1765:  �[32m✓�[0m Git ops ABM both keys errors (0.44s)
1766:  �[32m✓�[0m Git ops ABM deprecated config with two tokens in the db fails (0.42s)
1767:  �[32m✓�[0m Git ops ABM new key all valid (0.82s)
1768:  �[32m✓�[0m Git ops ABM new key multiple elements (0.64s)
1769:  �[32m✓�[0m Git ops ABM no team is supported (0.49s)
1770:  �[32m✓�[0m Git ops ABM non existent org name fails (0.54s)
1771:  �[32m✓�[0m Git ops ABM not provided teams defaults to no team (0.46s)
1772:  �[32m✓�[0m Git ops ABM renamed new key all valid (0.69s)
1773:  �[32m✓�[0m Git ops ABM using an undefined team errors (0.49s)
1774:  �[32m✓�[0m Git ops EULA setting (4.24s)
...

1777:  �[32m✓�[0m Git ops EULA setting not a PDF file (0.51s)
1778:  �[32m✓�[0m Git ops EULA setting relative path to working dir to pdf file (no existing EULA uploaded) (0.55s)
1779:  �[32m✓�[0m Git ops EULA setting relative path to yaml file to pdf file (no existing EULA uploaded) (0.50s)
1780:  �[32m✓�[0m Git ops EULA setting uploading the same EULA again (0.46s)
1781:  �[32m✓�[0m Git ops EULA setting valid new pdf file (different EULA already uploaded) (0.56s)
1782:  �[32m✓�[0m Git ops EULA setting valid pdf file (no existing EULA uploaded) (0.48s)
1783:  �[32m✓�[0m Git ops MDM auth settings (0.49s)
1784:  �[32m✓�[0m Git ops SMTP settings (0.69s)
1785:  �[32m✓�[0m Git ops SSO server URL (0.54s)
1786:  �[32m✓�[0m Git ops SSO settings (0.56s)
1787:  �[32m✓�[0m Git ops android certificates add (0.56s)
1788:  �[32m✓�[0m Git ops android certificates change (0.71s)
1789:  �[32m✓�[0m Git ops android certificates delete all (0.58s)
1790:  �[32m✓�[0m Git ops android certificates delete one (0.44s)
1791:  �[32m✓�[0m Git ops app store app auto update (0.50s)
1792:  �[32m✓�[0m Git ops app store app auto update invalid auto-update window triggers error and does not call update software title auto update config (0.01s)
1793:  �[32m✓�[0m Git ops app store app auto update no auto update settings and no existing schedule does not call update software title auto update config (0.02s)
...

1796:  �[32m✓�[0m Git ops apple OS updates (0.51s)
1797:  �[32m✓�[0m Git ops apple OS updates ios updates (0.05s)
1798:  �[32m✓�[0m Git ops apple OS updates ios updates changed deadline triggers bulk set pending MDM host profiles (0.02s)
1799:  �[32m✓�[0m Git ops apple OS updates ios updates changed minimum version triggers bulk set pending MDM host profiles (0.01s)
1800:  �[32m✓�[0m Git ops apple OS updates ios updates same values do not trigger bulk set pending MDM host profiles (0.01s)
1801:  �[32m✓�[0m Git ops apple OS updates ipados updates (0.05s)
1802:  �[32m✓�[0m Git ops apple OS updates ipados updates changed deadline triggers bulk set pending MDM host profiles (0.01s)
1803:  �[32m✓�[0m Git ops apple OS updates ipados updates changed minimum version triggers bulk set pending MDM host profiles (0.02s)
1804:  �[32m✓�[0m Git ops apple OS updates ipados updates same values do not trigger bulk set pending MDM host profiles (0.01s)
1805:  �[32m✓�[0m Git ops apple OS updates macos updates (0.05s)
1806:  �[32m✓�[0m Git ops apple OS updates macos updates changed deadline triggers bulk set pending MDM host profiles (0.02s)
1807:  �[32m✓�[0m Git ops apple OS updates macos updates changed minimum version triggers bulk set pending MDM host profiles (0.01s)
1808:  �[32m✓�[0m Git ops apple OS updates macos updates same values do not trigger bulk set pending MDM host profiles (0.01s)
1809:  �[32m✓�[0m Git ops basic global and no team (0.55s)
1810:  �[32m✓�[0m Git ops basic global and no team basic global and no-team.yml (0.05s)
1811:  �[32m✓�[0m Git ops basic global and no team both global and no-team.yml define controls -- should fail (0.01s)
1812:  �[32m✓�[0m Git ops basic global and no team controls only defined in no-team.yml (0.05s)
1813:  �[32m✓�[0m Git ops basic global and no team global DOES NOT define controls -- should fail (0.01s)
1814:  �[32m✓�[0m Git ops basic global and no team global and no-team.yml DO NOT define controls -- should fail (0.01s)
1815:  �[32m✓�[0m Git ops basic global and no team global defines software -- should fail (0.01s)
1816:  �[32m✓�[0m Git ops basic global and no team no-team provided without global -- should fail (0.01s)
1817:  �[32m✓�[0m Git ops basic global and no team no-team.yml defines policy with calendar events enabled -- should fail (0.01s)
1818:  �[32m✓�[0m Git ops basic global and no team unassigned provided without global -- should fail (0.01s)
1819:  �[32m✓�[0m Git ops basic global and team (0.68s)
...

1825:  �[32m✓�[0m Git ops custom settings global macos windows custom settings valid.yml (0.46s)
1826:  �[32m✓�[0m Git ops custom settings global windows custom settings invalid label mix 2 .yml (0.51s)
1827:  �[32m✓�[0m Git ops custom settings global windows custom settings invalid label mix.yml (0.42s)
1828:  �[32m✓�[0m Git ops custom settings global windows custom settings unknown label.yml (0.47s)
1829:  �[32m✓�[0m Git ops custom settings team macos custom settings valid deprecated.yml (0.39s)
1830:  �[32m✓�[0m Git ops custom settings team macos windows custom settings invalid labels mix 2 .yml (0.45s)
1831:  �[32m✓�[0m Git ops custom settings team macos windows custom settings invalid labels mix.yml (0.41s)
1832:  �[32m✓�[0m Git ops custom settings team macos windows custom settings unknown label.yml (0.59s)
1833:  �[32m✓�[0m Git ops custom settings team macos windows custom settings valid.yml (0.49s)
1834:  �[32m✓�[0m Git ops dry run rejects invalid label platform (0.38s)
1835:  �[32m✓�[0m Git ops exception enforcement (0.42s)
1836:  �[32m✓�[0m Git ops exception enforcement free tier (0.46s)
1837:  �[32m✓�[0m Git ops exceptions preserve omitted keys (0.52s)
1838:  �[32m✓�[0m Git ops features (0.64s)
1839:  �[32m✓�[0m Git ops filename validation (0.00s)
1840:  �[32m✓�[0m Git ops fleet failing policies webhook policy IDs (0.41s)
1841:  �[32m✓�[0m Git ops fleet webhooks and tickets enabled (0.72s)
...

2018:  �[32m✓�[0m Run api command get scripts full path missing (0.00s)
2019:  �[32m✓�[0m Run api command get scripts team (0.00s)
2020:  �[32m✓�[0m Run api command get scripts team no cache (0.00s)
2021:  �[32m✓�[0m Run api command get typo (0.00s)
2022:  �[32m✓�[0m Run api command upload script (0.00s)
2023:  �[32m✓�[0m Run script command (0.48s)
2024:  �[32m✓�[0m Run script command disabled scripts globally (0.00s)
2025:  �[32m✓�[0m Run script command host not found (0.01s)
2026:  �[32m✓�[0m Run script command invalid file type (0.00s)
2027:  �[32m✓�[0m Run script command invalid hashbang (0.01s)
2028:  �[32m✓�[0m Run script command invalid utf 8 (0.00s)
2029:  �[32m✓�[0m Run script command missing one of script-path and script-nqme (0.00s)
2030:  �[32m✓�[0m Run script command output truncated (0.01s)
2031:  �[32m✓�[0m Run script command posix shell hashbang (0.01s)
2032:  �[32m✓�[0m Run script command script empty (0.00s)
2033:  �[32m✓�[0m Run script command script failed (0.01s)
2034:  �[32m✓�[0m Run script command script killed (0.01s)
...

2072:  �[32m✓�[0m User is observer (0.00s)
2073:  �[32m✓�[0m User is observer global maintainer (0.00s)
2074:  �[32m✓�[0m User is observer global observer (0.00s)
2075:  �[32m✓�[0m User is observer global observer+ (0.00s)
2076:  �[32m✓�[0m User is observer team maintainer (0.00s)
2077:  �[32m✓�[0m User is observer team observer (0.00s)
2078:  �[32m✓�[0m User is observer team observer and maintainer (0.00s)
2079:  �[32m✓�[0m User is observer team observer+ (0.00s)
2080:  �[32m✓�[0m User is observer user without roles (0.00s)
2081:  github.com/fleetdm/fleet/v4/cmd/fleetctl/integrationtest/gitops:
2082:  �[32m✓�[0m Git ops VPP (3.92s)
2083:  �[32m✓�[0m Git ops VPP all teams is supported (0.57s)
2084:  �[32m✓�[0m Git ops VPP new key all valid (0.64s)
2085:  �[32m✓�[0m Git ops VPP new key multiple elements (0.55s)
2086:  �[32m✓�[0m Git ops VPP no team is supported (0.50s)
2087:  �[32m✓�[0m Git ops VPP non existent location fails (0.52s)
2088:  �[32m✓�[0m Git ops VPP not provided teams defaults to no team (0.65s)
2089:  �[32m✓�[0m Git ops VPP using an undefined team errors (0.49s)
2090:  �[32m✓�[0m Git ops existing team VPP apps with missing team (0.63s)
...

2178:  �[32m✓�[0m Git ops team software installers team software installer with display name.yml (1.46s)
2179:  �[32m✓�[0m Integrations enterprise gitops (306.80s)
2180:  �[32m✓�[0m Integrations enterprise gitops test CA integrations (3.78s)
2181:  �[32m✓�[0m Integrations enterprise gitops test FMA labels include all (5.88s)
2182:  �[32m✓�[0m Integrations enterprise gitops test IPA software installers (9.32s)
2183:  �[32m✓�[0m Integrations enterprise gitops test JSON configuration profile escaping (1.27s)
2184:  �[32m✓�[0m Integrations enterprise gitops test add manual labels (1.45s)
2185:  �[32m✓�[0m Integrations enterprise gitops test configuration profile escaping (1.29s)
2186:  �[32m✓�[0m Integrations enterprise gitops test delete CA with certificate templates (5.88s)
2187:  �[32m✓�[0m Integrations enterprise gitops test delete mac OS setup (4.86s)
2188:  �[32m✓�[0m Integrations enterprise gitops test deleting no team YAML (2.60s)
2189:  �[32m✓�[0m Integrations enterprise gitops test disallow software setup experience (123.62s)
2190:  �[32m✓�[0m Integrations enterprise gitops test disallow software setup experience all VPP with setup experience (1.23s)
2191:  �[32m✓�[0m Integrations enterprise gitops test disallow software setup experience no team VPP (1.12s)
2192:  �[32m✓�[0m Integrations enterprise gitops test disallow software setup experience no team installers (60.50s)
2193:  �[32m✓�[0m Integrations enterprise gitops test disallow software setup experience packages fail (60.61s)
2194:  �[32m✓�[0m Integrations enterprise gitops test dry run mac OS setup script with manual agent install conflict (0.40s)
...

2223:  �[32m✓�[0m Integrations enterprise gitops test omitted top level keys global (2.42s)
2224:  �[32m✓�[0m Integrations enterprise gitops test remove custom settings from default YAML (2.51s)
2225:  �[32m✓�[0m Integrations enterprise gitops test special case teams VPP apps (3.69s)
2226:  �[32m✓�[0m Integrations enterprise gitops test special case teams VPP apps all teams (2.32s)
2227:  �[32m✓�[0m Integrations enterprise gitops test special case teams VPP apps no team (1.21s)
2228:  �[32m✓�[0m Integrations enterprise gitops test unset configuration profile labels (4.78s)
2229:  �[32m✓�[0m Integrations enterprise gitops test unset software installer labels (9.17s)
2230:  �[32m✓�[0m Integrations enterprise starter library (4.75s)
2231:  �[32m✓�[0m Integrations enterprise starter library test apply starter library premium (3.39s)
2232:  �[32m✓�[0m Integrations gitops (2.24s)
2233:  �[32m✓�[0m Integrations gitops test fleet gitops (0.44s)
2234:  �[32m✓�[0m Integrations gitops test fleet gitops DDM fleet vars requires premium (0.11s)
2235:  �[32m✓�[0m Integrations gitops test fleet gitops with fleet secrets (0.21s)
2236:  �[32m✓�[0m Integrations starter library (1.54s)
2237:  �[32m✓�[0m Integrations starter library test apply starter library free (0.18s)
2238:  === �[31mFailed�[0m
2239:  === �[31mFAIL�[0m: cmd/fleetctl/integrationtest/vuln TestIntegrationsVulnerabilityDataStream (97.91s)
2240:  nettest.go:33: network test start: TestIntegrationsVulnerabilityDataStream
2241:  vulnerability_data_stream_test.go:44: 
2242:  Error Trace:	/home/runner/work/fleet/fleet/cmd/fleetctl/integrationtest/vuln/vulnerability_data_stream_test.go:44
2243:  Error:      	Received unexpected error:
2244:  Error downloading OSV artifacts: getting latest release: github http status error: 403
2245:  Test:       	TestIntegrationsVulnerabilityDataStream
2246:  nettest.go:36: network test done: TestIntegrationsVulnerabilityDataStream
2247:  DONE 860 tests, 1 failure in 634.555s
2248:  make[1]: *** [Makefile:286: .run-go-tests] Error 1
2249:  make[1]: Leaving directory '/home/runner/work/fleet/fleet'
2250:  make: *** [Makefile:401: test-go] Error 2
2251:  ##[error]Process completed with exit code 2.
2252:  ##[group]Run actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a
2253:  with:
2254:  name: fleetctl-mysql8.0.44-coverage
2255:  path: ./coverage.txt
2256:  if-no-files-found: error
2257:  compression-level: 6
...

2269:  With the provided path, there will be 1 file uploaded
2270:  Artifact name is valid!
2271:  Root directory input is valid!
2272:  Beginning upload of artifact content to blob storage
2273:  Uploaded bytes 2222547
2274:  Finished uploading artifact content to blob storage!
2275:  SHA256 hash of uploaded artifact zip is c3297d14a1bdea94244fd2265ef39eb5a933e513c0827c828ff0c5780aec8997
2276:  Finalizing artifact upload
2277:  Artifact fleetctl-mysql8.0.44-coverage.zip successfully finalized. Artifact ID 7344915427
2278:  Artifact fleetctl-mysql8.0.44-coverage has been successfully uploaded! Final size is 2222547 bytes. Artifact ID is 7344915427
2279:  Artifact download URL: https://github.com/fleetdm/fleet/actions/runs/26786306834/artifacts/7344915427
2280:  ##[group]Run c1grep() { grep "$@" || test $? = 1; }
2281:  �[36;1mc1grep() { grep "$@" || test $? = 1; }�[0m
2282:  �[36;1mc1grep -oP 'FAIL: .*$' /tmp/gotest.log > /tmp/summary.txt�[0m
2283:  �[36;1mc1grep 'test timed out after' /tmp/gotest.log >> /tmp/summary.txt�[0m
2284:  �[36;1mc1grep 'fatal error:' /tmp/gotest.log >> /tmp/summary.txt�[0m
2285:  �[36;1mc1grep -A 10 'panic: runtime error: ' /tmp/gotest.log >> /tmp/summary.txt�[0m
2286:  �[36;1mc1grep ' FAIL\t' /tmp/gotest.log >> /tmp/summary.txt�[0m
2287:  �[36;1mGO_FAIL_SUMMARY=$(head -n 5 /tmp/summary.txt | sed ':a;N;$!ba;s/\n/\\n/g')�[0m
2288:  �[36;1mecho "GO_FAIL_SUMMARY=$GO_FAIL_SUMMARY"�[0m
2289:  �[36;1mif [[ -z "$GO_FAIL_SUMMARY" ]]; then�[0m
2290:  �[36;1m  GO_FAIL_SUMMARY="unknown, please check the build URL"�[0m
2291:  �[36;1mfi�[0m
2292:  �[36;1mGO_FAIL_SUMMARY=$GO_FAIL_SUMMARY envsubst < .github/workflows/config/slack_payload_template.json > ./payload.json�[0m
2293:  shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
2294:  env:
2295:  RACE_ENABLED: false
2296:  GO_TEST_TIMEOUT: 20m
2297:  DOCKER_COMMAND: docker compose -f docker-compose.yml -f docker-compose-redis-cluster.yml up -d mysql_test mysql_replica_test redis redis-cluster-1 redis-cluster-2 redis-cluster-3 redis-cluster-4 redis-cluster-5 redis-cluster-6 redis-cluster-setup s3 saml_idp mailhog mailpit smtp4dev_test
2298:  RUN_TESTS_ARG: 
2299:  CI_TEST_PKG: fleetctl
2300:  NEED_DOCKER: 1
2301:  ARTIFACT_PREFIX: fleetctl-mysql8.0.44
2302:  GOTOOLCHAIN: local
2303:  ##[endgroup]
2304:  GO_FAIL_SUMMARY=
2305:  ##[group]Run actions/upload-artifact@834a144ee995460fba8ed112a2fc961b36a5ec5a
2306:  with:
2307:  name: fleetctl-mysql8.0.44-test-log
2308:  path: /tmp/gotest.log
2309:  if-no-files-found: error
2310:  compression-level: 6

@getvictor
getvictor merged commit 1072c85 into main Jun 1, 2026
45 of 47 checks passed
@getvictor
getvictor deleted the victor/46388-entra-v2 branch June 1, 2026 22:58

This branch was previously deployed

1 inactive deployment
Docker Hub — 91c63440 Deployed Jun 1, 2026 by getvictor via publish #91469
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support Microsoft Entra v2 access tokens for Windows MDM enrollment

3 participants