Make api_key and identity auth modes disjoint by deprecating the implicit Entra fallback
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python
- Lĩnh vực
- authentication
Hướng nghiên cứu
Start with pyrit/auth/openai_auth.py::resolve_openai_auth, then compare the inlined authentication chains in AzureMLChatTarget and PromptShieldTarget. This work is ordered after #2846, which adds explicit auth-mode support to AzureBlobStorageTarget; review that dependency and #3010 before changing behavior. Done means the implicit identity fallback warns for one release, strict modes and cleanup are addressed, and the setup and per-target notebooks plus release and migration guidance are updated.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Is your feature request related to a problem? Please describe.
Follow-up to review feedback on #3010 (thread).
api_key authentication mode can currently resolve to identity. The chain in pyrit/auth/openai_auth.py::resolve_openai_auth is:
- token-provider callable passed as
api_key - explicit
api_keystring - the target's API key environment variable
- fallback: an Entra token, for recognized Azure endpoints only
Step 4 is why "no api_key passed" was ambiguous in the first place — it can mean "the user chose identity" or "no key is available, mint a token." #3010 fixed the user-facing symptom by adding an explicit auth_mode, but left the underlying fallback in place for backward compatibility, so the two modes still overlap rather than being disjoint.
The same inlined chain exists in AzureMLChatTarget and PromptShieldTarget.
Describe the solution you'd like
Make the two modes disjoint:
auth_mode="api_key"requires a key or an explicitly supplied token provider, and fails clearly when neither is present. No implicit identity fallback.auth_mode="identity"uses identity and ignores keys (already true as of #3010).
This is a breaking change: OpenAIChatTarget(endpoint=<azure endpoint>) with no key plus az login works silently today and is documented that way, so it should go through a deprecation cycle rather than being removed outright:
- One release emitting a
DeprecationWarningwhen the implicit fallback is taken, namingauth_mode="identity"as the replacement. - Removal in the following release, called out in the release notes and migration guidance.
Two cleanups land with this:
TargetService._accepts_auth_modecan be deleted. It exists solely becauseAzureBlobStorageTargethas noauth_modeparameter; once every identity-advertising target accepts the explicit mode, a target that cannot meet that contract should fail loudly instead of being quietly skipped. This is blocked on #2846, which adds explicit auth-mode support toAzureBlobStorageTarget.doc/code/setup/1_configuration.py/.ipynband the per-target notebooks that describe keyless Azure auth need updating.
Describe alternatives you've considered, if relevant
- Keep the fallback indefinitely. Lowest churn, but leaves
api_keymode able to silently produce identity auth, which is the ambiguity #3010 set out to remove. - Remove it immediately in #3010. Rejected: an unannounced break buried in a bugfix, with no warning period for users relying on the documented keyless Azure path.
- Add an explicit
automode that keeps today's chain, leavingapi_keyandidentitystrict. Preserves the behavior under an honest name, but adds a third mode to document and reason about; only worth it if the keyless path turns out to be widely depended upon.
Additional context
Ordering: this should land after #2846, which supplies the AzureBlobStorageTarget half and unblocks removing _accepts_auth_mode. #2846 and #3010 also introduce two overlapping mechanisms for the same concern (a per-class get_auth_mode_parameters hook vs. an explicit auth_mode constructor argument); reconciling those into one belongs in the same pass.
Related: #3010, #2846, #2235 (which introduced the fallback — correctly, for its original purpose as a last resort when no key exists).
- Ngôn ngữ chính
- Python
- Star
- 4.6k
- Fork
- 924
- Merge trung bình
- 2 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 251
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Không có hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/PyRIT
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 2 ngày
-
BUG: PlagiarismScorer accepts invalid n-gram size and blank reference textCó thể đã có người làm @RohithPariki đã nhận 4 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 2 ngày
-
PackageHallucinationScorer (Python) misses `from pkg.sub import x` and indented importsCó thể đã có người làm @barry166 đã nhận 6 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
microsoft/PyRIT#2948 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
BUG Configuration keeps runtime-status errors after polling recoversCó thể đã có người làm @rupayon123 đã nhận 12 ngày trước. Đang mởBug: triage GUI help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
microsoft/PyRIT#2868 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
ObjectiveScorerEvaluator scores every conversation message as an assistant responseCó thể đã có người làm @feiiiiii5 đã nhận 12 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của microsoft/PyRIT
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
RedHatQE/mtv-api-tests#721 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 85/100
pytest-dev/pluggy#757 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 85/100
NousResearch/hermes-agent#134960 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
HTML backend: `<br>` leaks the internal sentinel U+E000 into list items, headings and captionsCó thể đã có người làm @morten-lagabote đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 67/100
docling-project/docling#4671 ·
Maintainer thường phản hồi trong vòng 1 ngày