OIDC ALLOWED_HOSTS suffix recognition accepts any azure.<tld>, including non-Microsoft TLDs open for public registration
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 82/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- azure, mongodb, typescript
- Domain
- authentication, security
Research direction
Start in src/documentdb/auth/oidcAllowedHosts.ts and read getAzureHostSuffix together with getOidcAllowedHosts. Compare the recognized suffixes with the documented Azure cloud domains and verify that documented hosts remain allowed while azure subdomains under arbitrary TLDs are rejected.
Written by the indexing model from the issue text.
Description
Summary
#721 replaced the hardcoded *.azure.com OIDC allowlist with suffix recognition: getAzureHostSuffix (src/documentdb/auth/oidcAllowedHosts.ts) accepts a host when its registrable second-level label is azure — and the top-level label is ANY non-empty string:
const topLevel = labels[labels.length - 1];
const secondLevel = labels[labels.length - 2];
if (secondLevel === 'azure' && topLevel.length > 0) {
return `azure.${topLevel}`;
}
So *.azure.com, *.azure.us, *.azure.cn pass — and so does *.azure.<any open TLD>: azure.xyz, azure.top, azure.live, and so on. Those domains are registrable by anyone. The file's own comment names the intent as "sovereign clouds (azure.us, azure.cn, ...)", but the implementation does not bound the suffix set to Microsoft-operated clouds.
Consequence, by the file's own description of the control ("the driver only sends the OIDC token to a server whose hostname matches one of these patterns"): a connection string whose host sits under a registrable azure.<openTld> is positively classified as Azure-family, and the token-delivery host allowlist widens to match it. On a machine with a managed identity (the new auth surface) or an interactive Entra sign-in, a connection string of the shape
mongodb://x.azure.xyz:10255/?authMechanism=MONGODB-OIDC&...
pasted into the connection wizard classifies x.azure.xyz as an allowed token-delivery host.
Two things bound this in practice and belong in the assessment:
- The enabling surface predates the managed-identity work: the same
azure.<tld>recognition already governed the Entra ID user-token path in 0.10.2 (oidcAllowedHosts.tsunchanged since 2026-06-26), so wizard + allowlist is pre-existing behavior; the new auth methods add token principals, not a new gate, host, or channel. - Reaching it needs the conjunction of an attacker-registered lookalike domain AND a user pasting a hostile connection string AND (for the identity-token path) a host with the relevant identity configured.
Repro
Logic-level, against the shipped function:
getAzureHostSuffix('x.azure.xyz') // => 'azure.xyz' (recognized as Azure-family)
getOidcAllowedHosts('mongodb://x.azure.xyz:10255/?authMechanism=MONGODB-OIDC')
// => ['*.azure.xyz'] (token-delivery allowlist widened to the lookalike)
Any first-level label under any azure.<tld> behaves the same; only the second-level label is inspected.
Suggested fix
Bound the recognized suffixes to the documented sovereign set instead of any TLD:
const AZURE_HOST_SUFFIXES = new Set(['azure.com', 'azure.us', 'azure.cn']);
// in getAzureHostSuffix:
const candidate = `${secondLevel}.${topLevel}`;
return AZURE_HOST_SUFFIXES.has(candidate) ? candidate : undefined;
Private endpoints keep working (they resolve under *.azure.com — the file comment already notes this). If broader coverage is ever wanted, the #639 option of an explicit user setting for custom domains keeps the default closed while still serving sovereign/custom deployments.
Impact framing
Allowlist-breadth hardening filed as a follow-up to #639/#721, not a vulnerability report: the design goals (don't echo the raw host back into the allowlist; cover sovereign clouds) are right, and the gap is that the suffix predicate is open-ended where the intent was a curated set. With the pre-existing parity noted above, tightening closes a lookalike-domain variant of the paste-a-connection-string flow while leaving every documented deployment shape unchanged.
- Dominant language
- TypeScript
- Stars
- 33
- Forks
- 22
- Avg merge
- 18h 6m
- Merged PRs (30d)
- 41
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/vscode-documentdb
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
microsoft/vscode-documentdb#956 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
microsoft/vscode-documentdb#885 ·
Maintainers usually reply within 1 day
-
bug-bash
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/vscode-documentdb#875 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
microsoft/vscode-documentdb#831 · 1 comment ·
Maintainers usually reply within 1 day
-
Revisit: getMongoClient() JSDoc is misleading; only used by main thread scanCollectionSchemaMay be free again A pull request for this issue was closed without being merged. Opendocumentation needs-triage P3
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
microsoft/vscode-documentdb#643 ·
Maintainers usually reply within 1 day
All issues in microsoft/vscode-documentdb
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
AOSSIE-Org/DebateAI#611 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
openzim/mwoffliner#2933 ·
Maintainers usually reply within 1 day
-
Use the README category name for website links and submissionsPossibly taken @dajiaohuang claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
birobirobiro/awesome-shadcn-ui#647 ·
Maintainers usually reply within 2 days
-
Twake Drive picker: closePicker() never destroys the intent (stop() is on the promise returned by start(), not by create())Possibly taken @chibenwa claimed this today. Openclaude
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
linagora/twake-calendar-frontend#1498 · 1 comment ·
Maintainers usually reply within 1 day
-
check:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day