This repository is a proof-of-concept reference application. Only the latest commit on main is maintained. It assumes:
- a single Microsoft Entra ID tenant, with app registrations created by
scripts/setup-entra.ps1; - Azure platform services (Entra ID, API Management, App Service, Azure Functions, Cosmos DB, Azure Monitor) behaving as documented;
- deployments performed by
scripts/deploy.ps1or the GitHubdeployworkflow with OIDC.
Design details are in docs/security.md and docs/threat-model.md.
Do not open a public issue for a vulnerability. Use GitHub's private vulnerability reporting for this repository (Security, Report a vulnerability) if it is enabled, or contact the repository owner privately. Include:
- a description of the issue and its impact;
- steps to reproduce against a local environment (
Auth:Mode=Dev) where possible; - affected files, commits, or configuration.
Expect an acknowledgement within a reasonable time; this is a PoC maintained on a best-effort basis.
- Never commit credentials: client secrets, access or refresh tokens, storage or Cosmos keys, connection strings with keys, certificates with private keys, or the Cosmos DB Emulator key (copy it from Microsoft's documentation into the untracked
local.settings.json). - Tenant, subscription, and client ids are not secrets but are supplied through configuration, not committed.
- Install the pre-commit hook (
pwsh ./scripts/install-git-hooks.ps1); it runsscripts/check-repo-safety.ps1. CI runs the same checks. - If a secret is committed, treat it as compromised: revoke or rotate it first, then remove it from history.
- access tokens (anything starting with
eyJ),Authorizationheaders, cookies; - connection strings, keys, client secrets, publishing profiles;
- personal data from real users, including todo content;
- full HTTP captures from an authenticated session.
Redact these before sharing screenshots, logs, or Postman exports.