Add comprehensive authority configuration and precedence documentation - #3617
Iarek Kovtunenko (iarekk) merged 6 commits into
Conversation
Jean-Marc Prieur (jmprieur)
left a comment
There was a problem hiding this comment.
Copilot. I left 2 comments.
There is also one meta-point (applying everywhere in this doc). "PreserveAuthority" is a MergedOptions property. It's not accessible to developers, nor settable through the configuration.
Removed all references to PreserveAuthority in commit 4491701. You're correct - it's an internal MergedOptions property not accessible to developers. Updated all documentation to clarify that the library automatically handles CIAM authorities correctly without requiring any special configuration from developers. |
Bogdan Gavril (bgavrilMS)
left a comment
There was a problem hiding this comment.
Let's discuss about deprecating Authority altoghter instead?
Bogdan Gavril (bgavrilMS)
left a comment
There was a problem hiding this comment.
I think we should not advise ppl to use Authority for AAD authorities, because they risk disabling defenses like authority validation and other AAD specific logic.
|
Travis Walker (@trwalke) - you worked on CIAM before. Can you please take over this PR from Jean-Marc and get it merged? |
|
Jean-Marc Prieur (@jmprieur) - is this ready to be merged? It is marked as draft. |
yes, you had blocked it ... |
|
Copilot - update this PR by rebasing it to master |
I can't rebase this PR because the environment doesn't support force-push. The merge also reveals conflicts in source files ( |
Authority Configuration Documentation
Comprehensive documentation for authority configuration in Microsoft.Identity.Web (Issue #3613), rebased on master which includes the throwing behavior from PR #3873.
Documentation added/updated
Key points reflected in docs
InvalidOperationExceptionat startup (PR Throw on Authority vs Instance/TenantId conflict (OIDC + MSAL parity) #3873)Authorityalone routes throughWithOidcAuthority()(generic OIDC) -- lacks AAD-specific security/resilience.Instance+TenantIdis strongly recommended for AAD.PreserveAuthorityis internal-only, not developer-accessible -- removed from docsAuthorityHelpers.BuildCiamAuthorityIfNeededandTokenAcquisitionFixes #3613