[azure-core-amqp] Preserve structured CBS failures through token refresh retries
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 32/100
- Tipo di issue
- Refactoring
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- azure, cpp
- Ambito
- authentication, security
Direzione di ricerca
Inizia tracciando RefreshTokenForAudience attraverso l’acquisizione delle credenziali, l’apertura di CBS, PutTokenForAudience e la pulizia, quindi esamina come il livello Event Hubs utilizza il risultato. Usa la checklist di convalida per definire il completamento: risultati distinti, conservazione dello stato CBS, decisioni sui tentativi non basate sul testo, gestione corretta dell’annullamento e test per ogni percorso di errore elencato, senza registrare il materiale dei token.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
RefreshTokenForAudience catches every standard exception and retains only what(). The refresh scheduler therefore cannot distinguish credential acquisition, CBS open, put-token refusal, transport failure, timeout, and shutdown cancellation. It can only retry every failure with the same policy and write an unstructured warning.
Issue #7330 covers the low-level ambiguity where PutTokenForAudience raises AuthenticationException for every non-Ok CBS result. This issue carries structured failure information through the refresh worker after the low-level result has been classified. Rust transport parity is outside this issue.
Proposal
Introduce an internal refresh outcome that records:
- The failed stage: credential acquisition, CBS open, put-token, or cleanup.
- The CBS operation result and service status when available.
- Whether the failure is retryable on the same connection.
- Whether a fresh connection is required.
- Whether the operation ended because of caller cancellation or connection shutdown.
Use the outcome rather than exception text to select the next refresh action. Transport errors, timeouts, throttling, and retryable service failures may retain the current authorization and schedule another attempt. An explicit credential or claim rejection remains a permanent authentication result after the bounded fresh-connection probe in the Event Hubs layer.
Preserve exception text for diagnostics, but do not parse it to make a retry decision. Logs may include the audience, connection instance, failure stage, attempt number, remaining token lifetime, and next delay. They must never include the token.
Validation
- Each credential and CBS failure stage produces a distinct internal outcome.
- Cancellation and shutdown are not logged or scheduled as ordinary retryable failures.
- CBS service status and description survive to the final actionable exception when available.
- Retry decisions do not inspect exception text.
- Logs state the retry decision and next delay without exposing token material.
- Tests cover transient transport failure, explicit authorization refusal, timeout, cancellation, and unknown exception paths.
This issue changes authentication failure handling and requires explicit security-focused review.
- Lingua principale
- C++
- Stelle
- 207
- Fork
- 173
- Merge medio
- 1g 10h
- PR unite (30g)
- 30
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Azure/azure-sdk-for-cpp
-
DataLakeFileSystemClient::ListPaths() throws JSON exception due to accessing undefined fieldsApertacustomer-reported needs-triage question
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
Azure/azure-sdk-for-cpp#7435 ·
I maintainer di solito rispondono entro 1 giorno
-
bug EngSys
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
Azure/azure-sdk-for-cpp#7362 ·
I maintainer di solito rispondono entro 1 giorno
-
Client needs-team-attention Service Attention Storage
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Azure/azure-sdk-for-cpp#7347 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Client Event Hubs needs-team-attention Service Attention
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
Azure/azure-sdk-for-cpp#7333 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
DataLakeDirectoryClient::ListPaths() throws exception due to incorrect format used for date-time fieldsForse già presa @seanmcc-msft l’ha presa oggi. Apertacustomer-reported needs-triage question
Azure/azure-sdk-for-cpp#7436 · 1 commento · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Azure/azure-sdk-for-cpp
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mpfaffenberger/privateer_reimagined#658 ·
I maintainer di solito rispondono entro 1 giorno
-
Broken links in the docsAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
microsoft/onnxruntime#33018 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
AXERA-TECH/ax-llm#81 ·
-
enhancement
Difficoltà 2/5 Mezza giornata Idoneità per principianti 78/100
ros-industrial/ros2_canopen#448 ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno