Sporadic ClaimsChallengeRequiredException using client secret authentication in newer versions of SDK
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 25/100
- Issue 類型
- 缺陷
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- azure, java, kotlin, spring-boot
- 領域
- api, authentication, backend
研究方向
從使用 ClientSecretCredentialBuilder 的 GraphServiceClient bean 和 applicationsWithAppId 健康檢查開始。比較 SDK 6.12.0 和 6.18.0 版本之間的驗證行為,重點關注為什麼所有使用相同 service principal 的執行個體會同時收到 ClaimsChallengeRequiredException。完成標準是重現該偶發例外,或找出其回歸原因,並提供經過驗證的修正方案。
由索引模型根據 Issue 內容生成。
描述
Describe the bug
After upgrading the library to version 6.18.0 (or any version other than 6.12.0), we sporadically encounter ClaimsChallengeRequiredExceptions.
When this issue arises, the com.microsoft.graph.serviceclient.GraphServiceClient consistently returns ClaimsChallengeRequiredException, and this can persist for several hours before the problem resolves itself. The issue may or may not recur the following day, with occurrences ranging from twice a day to once every four days.
Sample response from the Graph API:
{
"error":{
"code":"InvalidAuthenticationToken",
"message":"Exception of type 'Microsoft.Graph.AGS.Contracts.ClaimsChallengeRequiredException' was thrown.",
"innerError": {"date":"2024-10-25T12:28:03", "request-id":"f9d0585e-13fc-45d5-8e04-052b9768bcc0", "client-request-id":"83e18f5d-2547-4cac-8aa1-3b11f3a8148d"}
}
}
Downgrading to 6.12.0 will cause the problem to not appea, while other applications running 6.18.0 for the same service principal still get the error.
Expected behavior
We do not expect to get sporadic ClaimsChallengeRequiredException's
How to reproduce
In our spring boot kotlin application we have defined a spring bean for a GraphServiceClient like this
@Bean
fun graphServiceClient(): GraphServiceClient {
return GraphServiceClient(
ClientSecretCredentialBuilder()
.clientId(azureProperties.clientId)
.clientSecret(azureProperties.clientSecret)
.tenantId(azureProperties.tenantId)
.build(),
SCOPES,
)
}
We also have a health check that pings
graphServiceClient.applicationsWithAppId(azureProperties.clientId).get()
to verify that the client works.
With this we can expect the exception to be thrown at any moment / random.
The following image displays occurances of this exception the last 14 days.
SDK Version
6.18.0
Latest version known to work for scenario above?
6.12.0
Known Workarounds
We have currently two workarounds:
- Restarting the application, which reinitializes the GraphServiceClient bean
or - Wait an hour or two for the problem to disappear
Other information
When running multiple instances of the same application, using the same service principal, all instances will be affected at the same time, when this issue occurs.
- 主要語言
- Java
- 星號
- 444
- 分支
- 154
- 平均合併
- 18 小時 28 分鐘
- 30 天內合併 PR
- 4
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
microsoftgraph/msgraph-sdk-java 的其他 Issue
-
status:waiting-for-triage type:bug
難度 2/5 1-3 小時 新手友好度 68/100
microsoftgraph/msgraph-sdk-java#2610 ·
-
status:waiting-for-triage type:bug
難度 3/5 1-2 天 新手友好度 55/100
microsoftgraph/msgraph-sdk-java#2656 ·
-
status:waiting-for-triage type:bug
難度 4/5 3-5 天 新手友好度 38/100
microsoftgraph/msgraph-sdk-java#2654 ·
-
status:waiting-for-triage
難度 4/5 3-5 天 新手友好度 35/100
microsoftgraph/msgraph-sdk-java#2639 ·
-
status:waiting-for-triage type:bug
難度 3/5 1-2 天 新手友好度 35/100
microsoftgraph/msgraph-sdk-java#2589 · 1 則留言 ·
查看 microsoftgraph/msgraph-sdk-java 的全部 Issue
相似的 Issue
-
certification
難度 1/5 1 小時以內 新手友好度 80/100
-
難度 2/5 1-3 小時 新手友好度 75/100
-
[BUG] ECR GetAuthorizationToken returns a proxyEndpoint for the default region, not the request's 未關閉bug ecr
難度 2/5 1-3 小時 新手友好度 75/100
-
Needs: Triage Type: Feature request
難度 2/5 1-3 小時 新手友好度 70/100
AntennaPod/AntennaPod#8794 ·
-
agentic-workflows
難度 2/5 1-3 小時 新手友好度 65/100
github/copilot-sdk#2760 ·