Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

OIDC ALLOWED_HOSTS suffix recognition accepts any azure.<tld>, including non-Microsoft TLDs open for public registration

Open Beginner friendly
#934 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
82/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
azure, mongodb, typescript

Research direction

Start in src/documentdb/auth/oidcAllowedHosts.ts and read getAzureHostSuffix together with getOidcAllowedHosts. Compare the recognized suffixes with the documented Azure cloud domains and verify that documented hosts remain allowed while azure subdomains under arbitrary TLDs are rejected.

Written by the indexing model from the issue text.

Description

Summary

#721 replaced the hardcoded *.azure.com OIDC allowlist with suffix recognition: getAzureHostSuffix (src/documentdb/auth/oidcAllowedHosts.ts) accepts a host when its registrable second-level label is azure — and the top-level label is ANY non-empty string:

const topLevel = labels[labels.length - 1];
const secondLevel = labels[labels.length - 2];

if (secondLevel === 'azure' && topLevel.length > 0) {
    return `azure.${topLevel}`;
}

So *.azure.com, *.azure.us, *.azure.cn pass — and so does *.azure.<any open TLD>: azure.xyz, azure.top, azure.live, and so on. Those domains are registrable by anyone. The file's own comment names the intent as "sovereign clouds (azure.us, azure.cn, ...)", but the implementation does not bound the suffix set to Microsoft-operated clouds.

Consequence, by the file's own description of the control ("the driver only sends the OIDC token to a server whose hostname matches one of these patterns"): a connection string whose host sits under a registrable azure.<openTld> is positively classified as Azure-family, and the token-delivery host allowlist widens to match it. On a machine with a managed identity (the new auth surface) or an interactive Entra sign-in, a connection string of the shape

mongodb://x.azure.xyz:10255/?authMechanism=MONGODB-OIDC&...

pasted into the connection wizard classifies x.azure.xyz as an allowed token-delivery host.

Two things bound this in practice and belong in the assessment:

  • The enabling surface predates the managed-identity work: the same azure.<tld> recognition already governed the Entra ID user-token path in 0.10.2 (oidcAllowedHosts.ts unchanged since 2026-06-26), so wizard + allowlist is pre-existing behavior; the new auth methods add token principals, not a new gate, host, or channel.
  • Reaching it needs the conjunction of an attacker-registered lookalike domain AND a user pasting a hostile connection string AND (for the identity-token path) a host with the relevant identity configured.
Repro

Logic-level, against the shipped function:

getAzureHostSuffix('x.azure.xyz')   // => 'azure.xyz'   (recognized as Azure-family)
getOidcAllowedHosts('mongodb://x.azure.xyz:10255/?authMechanism=MONGODB-OIDC')
// => ['*.azure.xyz']               (token-delivery allowlist widened to the lookalike)

Any first-level label under any azure.<tld> behaves the same; only the second-level label is inspected.

Suggested fix

Bound the recognized suffixes to the documented sovereign set instead of any TLD:

const AZURE_HOST_SUFFIXES = new Set(['azure.com', 'azure.us', 'azure.cn']);

// in getAzureHostSuffix:
const candidate = `${secondLevel}.${topLevel}`;
return AZURE_HOST_SUFFIXES.has(candidate) ? candidate : undefined;

Private endpoints keep working (they resolve under *.azure.com — the file comment already notes this). If broader coverage is ever wanted, the #639 option of an explicit user setting for custom domains keeps the default closed while still serving sovereign/custom deployments.

Impact framing

Allowlist-breadth hardening filed as a follow-up to #639/#721, not a vulnerability report: the design goals (don't echo the raw host back into the allowlist; cover sovereign clouds) are right, and the gap is that the suffix predicate is open-ended where the intent was a curated set. With the pre-existing parity noted above, tightening closes a lookalike-domain variant of the paste-a-connection-string flow while leaving every documented deployment shape unchanged.

Dominant language
TypeScript
Stars
33
Forks
22
Avg merge
18h 6m
Merged PRs (30d)
41

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/vscode-documentdb

All issues in microsoft/vscode-documentdb

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.