Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Support secretless credential options (workload identity federation / certificates) for OBO authentication

Aperta
#3,641 3 commenti 2 reazioni 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

auth mcp-server

Summary

DAB SQL MCP OBO currently only supports client secrets (DAB_OBO_CLIENT_SECRET + WithClientSecret(...)) for building the MSAL confidential client used in the On-Behalf-Of flow. Please add support for secretless credential options such as workload identity federation (FIC), client certificates, or client assertions.

Context

We are validating SQL MCP hosting inside a managed Connector Gateway / ADC sandbox environment. We tested DAB 2.0.1-rc over HTTP MCP and confirmed the basic OBO flow works end-to-end (describe_entities, read_records both succeed).

The current OBO flow:

  1. DAB reads the user token from Authorization: Bearer <user token>
  2. Uses MSAL.NET AcquireTokenOnBehalfOf(...) to exchange it for an Azure SQL scope token (https://database.windows.net/.default)
  3. Sets the token on SqlConnection.AccessToken

This requires three environment variables today:

  • DAB_OBO_CLIENT_ID
  • DAB_OBO_TENANT_ID
  • DAB_OBO_CLIENT_SECRET

Problem

In our managed hosting scenario, the sandbox environment is fully abstracted from the customer. Storing customer app secrets in sandbox/container configuration is problematic because:

  1. SFI (Secure Future Initiative) compliance — Using secrets for Entra Apps is blocked on most Microsoft tenants and requires multiple levels of exception processes.
  2. Security posture — Long-lived client secrets in container configuration are difficult or unacceptable for many tenants.

OBO still requires the middle-tier app to authenticate as a confidential client, but the credential ideally should not need to be a long-lived client secret.

Requested Credential Options

Support one or more of the following in addition to client secret:

  • Workload identity federation (Federated Identity Credentials / FIC)
  • Client certificate (WithCertificate(...))
  • Client assertion (WithClientAssertion(...))

References

Lingua principale
C#
Stelle
1.5k
Fork
371
Merge medio
9g 2h
PR unite (30g)
10

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Azure/data-api-builder

Tutte le issue di Azure/data-api-builder

Issue simili

Altre issue su C#

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.