Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

token_grant: support client_id so client_credentials works with Microsoft Entra federated credentials

Offen Anfängerfreundlich
#4,372 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
70/100
Issue-Typ
Feature
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
azure, rust
Bereich
authentication

Rechercherichtung

Beginne bei TokenGrantParams in crates/openshell-core/src/oauth.rs, wo der Formularkörper aus client_assertion, client_assertion_type, audience und scope aufgebaut wird. Füge ein optionales Feld client_id hinzu und nimm es nur dann als Formularfeld auf, wenn es gesetzt ist, sodass bestehende Anfragen unverändert bleiben. Fertig ist, wenn eine token_grant-Konfiguration mit client_id dieses im Körper sendet und eine Konfiguration ohne client_id denselben Körper wie bisher sendet; suche nach bestehenden Tests für Token-Anfragen, die du erweitern kannst.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

state:triage-needed

We're trying to use token_grant with client_credentials against Microsoft Entra ID, with the sandbox's SPIFFE JWT-SVID as the client assertion. Entra supports this through federated identity credentials (https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire), but it needs client_id in the request body to pick the app registration.

TokenGrantParams in crates/openshell-core/src/oauth.rs only sends client_assertion, client_assertion_type, audience and scope, so there's no way to set it. We tried two workarounds against Entra:

  • client_id in the token endpoint's query string is ignored.
  • Without client_id in the body, Entra uses the assertion's iss as the app identifier and fails with AADSTS700016.

Could token_grant take an optional client_id that's sent as a form field? Something like:

credentials:
  - name: graph_access_token
    auth_style: bearer
    header_name: Authorization
    token_grant:
      token_endpoint: https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token
      client_id: <app id>
      jwt_svid_audience: api://AzureADTokenExchange
      scopes: [https://graph.microsoft.com/.default]

Without it we need a small broker in front of Entra just to add one field. Happy to send a PR if this sounds reasonable.

Vorherrschende Sprache
Rust
Sterne
15.4k
Forks
1.7k
Ø Merge
1 T. 21 Std.
Gemergte PRs (30 T.)
358

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus NVIDIA/OpenShell

Alle Issues in NVIDIA/OpenShell

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.