AAD Manifest parameters
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- azure, csharp
- Domain
- api, authentication
Research direction
Start with the Microsoft documentation linked in the issue and compare the Azure AD manifests for PersonalMicrosoftAccount and AzureADMyOrg. Determine which manifest attributes and token version are required for the package uploader, then verify that the resulting client-secret token is accepted without introducing other authentication problems.
Written by the indexing model from the issue text.
Description
Specifically "signInAudience" (aka: Supported account type) seems to matter for the AAD application being used for authentication.
"PersonalMicrosoftAccount" seems to give issues and does not let the AAD app be used for package uploader.
If we change "signInAudience" to be "AzureADMyOrg" things will probably work, but are there are other manifest attributes that will need to change as well in order to support this and not cause any problems?
We noticed that in the manifest an app with "signInAudience":"PersonalMicrosoftAccount", it has "accessTokenAcceptedVersion": 2 but this restriction isn't there for an app with "signInAudience":"AzureADMyOrg" (null value for that key). From reading various available documentation like these:
[https://learn.microsoft.com/en-us/azure/active-directory/develop/supported-accounts-validation]
[https://learn.microsoft.com/en-us/azure/active-directory/develop/access-tokens#token-formats]
...it seems that the supported account type changes features available and Azure AD apps use version 1.0 tokens if I'm not mistaken. So part of what we're wondering is if this is why the client secret token is accepted for "signInAudience":"AzureADMyOrg" but rejected for "signInAudience":"PersonalMicrosoftAccount".
- Dominant language
- C#
- Stars
- 67
- Forks
- 19
- Avg merge
- 3d 7h
- Merged PRs (30d)
- 2
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/PackageUploader
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
microsoft/PackageUploader#142 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
microsoft/PackageUploader#140 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 42/100
microsoft/PackageUploader#107 · 4 comments ·
-
Doesn't Sign InOpen
Difficulty 4/5 3-5 days Newbie friendliness 25/100
microsoft/PackageUploader#106 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 45/100
microsoft/PackageUploader#95 · 1 reaction ·
All issues in microsoft/PackageUploader
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Esri/calcite-dotnet-toolkit#30 · 1 reaction ·
-
VideoViewer: rotated (portrait phone) videos shown sideways when system decimal separator is a commaOpen
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
security
Difficulty 1/5 Under an hour Newbie friendliness 85/100
MorganHacks/Arctic#182 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Volodymyr-Petrunin/Bankomaten#45 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
thekid/inotify-win#45 ·