Support storage-account-level Azure RBAC authentication in attach (WAT) flow
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 55/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- azure
- 领域
- authentication, cloud
调研方向
首先定位现有的、用于单个容器的数据平面 attach 机制,然后跟踪 attach 流程如何处理 Blob/dfs 终结点和 List Containers 操作。完成的标准是:账户范围的 Blob 或 ADLS 终结点可以使用 Azure AD 令牌进行 attach 和浏览,而无需 subscription Reader 权限,同时仅限 ARM 的账户管理操作仍不可用。
由索引模型根据 Issue 内容生成。
描述
Feature request
Support storage-account-level Azure RBAC authentication in the "attach with Azure AD" (WAT / Connect) flow.
Problem
Customers following least-privilege want to grant a user a data-plane role - Storage Blob Data Reader or Storage Blob Data Contributor - scoped directly to a single storage account, without granting Reader at the subscription level (which would let the user discover/enumerate every other storage account in the subscription).
Today:
- Container-level RBAC -> the user can attach and browse that container via Azure AD (data-plane OAuth attach works).
- Storage-account-level Blob Data RBAC -> the user cannot attach the whole storage account via Azure AD. Account discovery is bound to subscription/ARM enumeration, which requires subscription Reader.
As a result, users with account-scoped Blob Data roles are effectively forced to use subscription Reader + sign-in (over-permissioned) or fall back to SAS/account-key authentication - both of which defeat the least-privilege goal.
Requested improvement
Allow a user who holds Storage Blob Data Reader/Contributor scoped to a specific storage account to attach and browse that account's blob/ADLS data plane via Azure AD, by supplying the account's blob/dfs endpoint (e.g. https://<account>.blob.core.windows.net) and an Azure AD token - without requiring subscription-level Reader.
The natural implementation reuses the existing data-plane attach machinery (already used for single containers) and enumerates the account's containers using the data-plane List Containers operation, which is permitted for Storage Blob Data Reader.
Scope / caveats
- This is a data-plane capability (browse containers/blobs/ADLS paths). Account management operations that are ARM-only (viewing keys, account properties/config) would remain unavailable for a data-plane-only attach and should be greyed out or hidden.
- Applies to Blob and ADLS Gen2 endpoints; File/Queue/Table data-plane RBAC could be considered separately.
Why now
Repeatedly requested by customers via CSS. Complements the broader RBAC-experience investigation in #8650, but is a specific, self-contained gap: account-scoped Blob Data RBAC cannot be used to attach an account today.
- 主要语言
- 没有语言数据
- 星标
- 455
- 派生
- 92
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/AzureStorageExplorer 的其他 Issue
-
:beetle: regression :copilot: copilot :test_tube: testing
难度 2/5 1-3 小时 新手友好度 76/100
microsoft/AzureStorageExplorer#9191 · 1 条评论 ·
-
难度 2/5 1-2 天 新手友好度 76/100
microsoft/AzureStorageExplorer#9186 ·
-
:globe_with_meridians: hard-coded string :globe_with_meridians: localization :test_tube: testing
难度 2/5 1-3 小时 新手友好度 68/100
microsoft/AzureStorageExplorer#9152 ·
-
难度 4/5 3-5 天 新手友好度 25/100
microsoft/AzureStorageExplorer#9207 ·
-
Sign-in error未关闭
难度 4/5 3-5 天 新手友好度 45/100
microsoft/AzureStorageExplorer#9206 · 4 条评论 · 1 个 reaction ·
查看 microsoft/AzureStorageExplorer 的全部 Issue
相似的 Issue
-
github_actions security
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
langchain-ai/langgraphjs#2958 ·
维护者通常 1 天内回复
-
allow igdb.com未关闭
难度 2/5 1-3 小时 新手友好度 61/100
AdguardTeam/HostlistsRegistry#939 ·
维护者通常 1 天内回复
-
backlog
难度 2/5 1-3 小时 新手友好度 65/100
维护者通常 1 天内回复
-
RPMDistro._update_packages() always passes --nogpgcheck, bypassing package signature verification未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复