token_grant: support client_id so client_credentials works with Microsoft Entra federated credentials
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 70/100
- Issue-Typ
- Feature
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- azure, rust
- Bereich
- authentication
Rechercherichtung
Beginne bei TokenGrantParams in crates/openshell-core/src/oauth.rs, wo der Formularkörper aus client_assertion, client_assertion_type, audience und scope aufgebaut wird. Füge ein optionales Feld client_id hinzu und nimm es nur dann als Formularfeld auf, wenn es gesetzt ist, sodass bestehende Anfragen unverändert bleiben. Fertig ist, wenn eine token_grant-Konfiguration mit client_id dieses im Körper sendet und eine Konfiguration ohne client_id denselben Körper wie bisher sendet; suche nach bestehenden Tests für Token-Anfragen, die du erweitern kannst.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
We're trying to use token_grant with client_credentials against Microsoft Entra ID, with the sandbox's SPIFFE JWT-SVID as the client assertion. Entra supports this through federated identity credentials (https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire), but it needs client_id in the request body to pick the app registration.
TokenGrantParams in crates/openshell-core/src/oauth.rs only sends client_assertion, client_assertion_type, audience and scope, so there's no way to set it. We tried two workarounds against Entra:
client_idin the token endpoint's query string is ignored.- Without
client_idin the body, Entra uses the assertion'sissas the app identifier and fails with AADSTS700016.
Could token_grant take an optional client_id that's sent as a form field? Something like:
credentials:
- name: graph_access_token
auth_style: bearer
header_name: Authorization
token_grant:
token_endpoint: https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token
client_id: <app id>
jwt_svid_audience: api://AzureADTokenExchange
scopes: [https://graph.microsoft.com/.default]
Without it we need a small broker in front of Entra just to add one field. Happy to send a PR if this sounds reasonable.
- Vorherrschende Sprache
- Rust
- Sterne
- 15.4k
- Forks
- 1.7k
- Ø Merge
- 1 T. 21 Std.
- Gemergte PRs (30 T.)
- 358
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus NVIDIA/OpenShell
-
state:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
Maintainer antworten meist innerhalb von 1 Tag
-
docs: document workspace and provider label capabilitiesEvtl. vergeben @johntmyers hat das vor 4 Tagen übernommen. Offenarea:docs
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
NVIDIA/OpenShell#4250 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentEvtl. vergeben @feloy hat das vor 6 Tagen übernommen. Offenstate:triage-needed
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configEvtl. vergeben @fede-kamel hat das vor 9 Tagen übernommen. Offenarea:cli os:linux os:macos state:validated
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
NVIDIA/OpenShell#4042 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
state:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
NVIDIA/OpenShell#3995 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in NVIDIA/OpenShell
Ähnliche Issues
-
C-bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
rust-lang/rust-analyzer#23501 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug P2 ready for work T-security T-transport
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/rust-sdk#1339 ·
Maintainer antworten meist innerhalb von 3 Tagen
-
French BIP39 wordlist starts with a UTF-8 BOM, so generated French mnemonics carry U+FEFF and derive a non-canonical seedEvtl. vergeben @Kshot3000 hat das heute übernommen. Offen
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 91/100
ergoplatform/sigma-rust#976 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
[Bug]: Web chat input doesn't regain focus after a reply finishesEvtl. vergeben @GaijinSystems hat das heute übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
zeroclaw-labs/zeroclaw#11658 ·
Maintainer antworten meist innerhalb von 2 Tagen