token_grant: support client_id so client_credentials works with Microsoft Entra federated credentials
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 70/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- azure, rust
- Lĩnh vực
- authentication
Hướng nghiên cứu
Bắt đầu với TokenGrantParams trong crates/openshell-core/src/oauth.rs, nơi tạo nội dung form từ client_assertion, client_assertion_type, audience và scope. Thêm trường tùy chọn client_id và chỉ đưa nó vào như một trường form khi trường này được thiết lập, để các yêu cầu hiện có không thay đổi. Hoàn thành khi một cấu hình token_grant có client_id gửi trường này trong nội dung, còn cấu hình không có client_id gửi cùng nội dung như trước; hãy tìm các bài kiểm thử yêu cầu token hiện có để mở rộng.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
We're trying to use token_grant with client_credentials against Microsoft Entra ID, with the sandbox's SPIFFE JWT-SVID as the client assertion. Entra supports this through federated identity credentials (https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire), but it needs client_id in the request body to pick the app registration.
TokenGrantParams in crates/openshell-core/src/oauth.rs only sends client_assertion, client_assertion_type, audience and scope, so there's no way to set it. We tried two workarounds against Entra:
client_idin the token endpoint's query string is ignored.- Without
client_idin the body, Entra uses the assertion'sissas the app identifier and fails with AADSTS700016.
Could token_grant take an optional client_id that's sent as a form field? Something like:
credentials:
- name: graph_access_token
auth_style: bearer
header_name: Authorization
token_grant:
token_endpoint: https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token
client_id: <app id>
jwt_svid_audience: api://AzureADTokenExchange
scopes: [https://graph.microsoft.com/.default]
Without it we need a small broker in front of Entra just to add one field. Happy to send a PR if this sounds reasonable.
- Ngôn ngữ chính
- Rust
- Star
- 15.4k
- Fork
- 1.7k
- Merge trung bình
- 1 ngày 21 giờ
- Pull request đã merge (30 ngày)
- 366
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của NVIDIA/OpenShell
-
docs: document workspace and provider label capabilitiesCó thể đã có người làm @johntmyers đã nhận 3 ngày trước. Đang mởarea:docs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
NVIDIA/OpenShell#4250 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentCó thể đã có người làm @feloy đã nhận 5 ngày trước. Đang mởstate:triage-needed
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configCó thể đã có người làm @fede-kamel đã nhận 8 ngày trước. Đang mởarea:cli os:linux os:macos state:validated
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
NVIDIA/OpenShell#4042 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
state:triage-needed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
NVIDIA/OpenShell#3995 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
OCSF shorthand renders Unknown and Other severities as [INFO]Có thể đã có người làm @ericcurtin đã nhận 9 ngày trước. Đang mởstate:triage-needed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của NVIDIA/OpenShell
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
rescript-lang/rescript#8765 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
chroma-core/chroma#7879 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
priority middle
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
KATO-Hiro/AtCoderClans#12838 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
clap_complete env (PowerShell): values after a space don't complete in Windows PowerShell 5.1Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày