token_grant: support client_id so client_credentials works with Microsoft Entra federated credentials
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 70/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- azure, rust
- Domain
- authentication
Research direction
Start with TokenGrantParams in crates/openshell-core/src/oauth.rs, which builds the form body from client_assertion, client_assertion_type, audience and scope. Add an optional client_id field and include it as a form field only when it is set, leaving existing requests unchanged. Done means a token_grant config with client_id sends it in the body, and a config without it sends the same body as before; look for existing token request tests to extend.
Written by the indexing model from the issue text.
Description
We're trying to use token_grant with client_credentials against Microsoft Entra ID, with the sandbox's SPIFFE JWT-SVID as the client assertion. Entra supports this through federated identity credentials (https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire), but it needs client_id in the request body to pick the app registration.
TokenGrantParams in crates/openshell-core/src/oauth.rs only sends client_assertion, client_assertion_type, audience and scope, so there's no way to set it. We tried two workarounds against Entra:
client_idin the token endpoint's query string is ignored.- Without
client_idin the body, Entra uses the assertion'sissas the app identifier and fails with AADSTS700016.
Could token_grant take an optional client_id that's sent as a form field? Something like:
credentials:
- name: graph_access_token
auth_style: bearer
header_name: Authorization
token_grant:
token_endpoint: https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token
client_id: <app id>
jwt_svid_audience: api://AzureADTokenExchange
scopes: [https://graph.microsoft.com/.default]
Without it we need a small broker in front of Entra just to add one field. Happy to send a PR if this sounds reasonable.
- Dominant language
- Rust
- Stars
- 15.4k
- Forks
- 1.7k
- Avg merge
- 1d 21h
- Merged PRs (30d)
- 366
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NVIDIA/OpenShell
-
docs: document workspace and provider label capabilitiesPossibly taken @johntmyers claimed this 3 days ago. Openarea:docs
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NVIDIA/OpenShell#4250 · 2 comments ·
Maintainers usually reply within 1 day
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentPossibly taken @feloy claimed this 4 days ago. Openstate:triage-needed
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configPossibly taken @fede-kamel claimed this 8 days ago. Openarea:cli os:linux os:macos state:validated
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
NVIDIA/OpenShell#4042 · 2 comments ·
Maintainers usually reply within 1 day
-
state:triage-needed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
NVIDIA/OpenShell#3995 · 2 comments ·
Maintainers usually reply within 1 day
-
OCSF shorthand renders Unknown and Other severities as [INFO]Possibly taken @ericcurtin claimed this 9 days ago. Openstate:triage-needed
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
All issues in NVIDIA/OpenShell
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
mishraprafful/multihull#150 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
voidzero-dev/vite-plus#2970 ·
Maintainers usually reply within 1 day
-
ai_p2 comp-parquet-reader-v3
Difficulty 2/5 Half a day Newbie friendliness 66/100
ClickHouse/ClickHouse#124986 ·
Maintainers usually reply within 1 day
-
bug(ktuner): exporter directories hide daemon processesPossibly taken @iloveeyjafjalla claimed this today. Opencomponent:ktuner
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
agentic-os-org/ANOLISA#6905 · 1 comment ·
Maintainers usually reply within 1 day
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
maniator/verticopolis#880 ·
Maintainers usually reply within 1 day