Fixing OBO user error - #3712
Merged
Merged
Conversation
Bogdan Gavril (bgavrilMS)
approved these changes
Feb 5, 2026
MARCIN Z (MZOLN)
approved these changes
Feb 5, 2026
Ray Luo (rayluo)
added a commit
that referenced
this pull request
Feb 9, 2026
…ipal from token In PR #3712 changed the usage of user to userHint, but based on the logic at the beginning of the changed method, the single source of truth in terms of OBO shall be derived from tokenUsedToCallTheWebApi. This change constructs a ClaimsPrincipal from the token string and preserves the BootstrapContext for use in event handlers.
Travis Walker (trwalke)
added a commit
that referenced
this pull request
Feb 11, 2026
…sPricipal from token (#3714) * Update OnBeforeTokenAcquisitionForOnBehalfOf event to use ClaimsPrincipal from token In PR #3712 changed the usage of user to userHint, but based on the logic at the beginning of the changed method, the single source of truth in terms of OBO shall be derived from tokenUsedToCallTheWebApi. This change constructs a ClaimsPrincipal from the token string and preserves the BootstrapContext for use in event handlers. * Adding DTO for OBO event * Updated comments * Updating PR --------- Co-authored-by: trwalke <trwalke@microsoft.com> Co-authored-by: Travis Walker <travis.walker@microsoft.com>
This was referenced Mar 1, 2026
deps: Bump Microsoft.Identity.Web from 4.3.0 to 4.4.0
microsoft/dragon-copilot-extension-samples#173
Merged
Closed
Merged
Closed
This was referenced Jul 13, 2026
Closed
Closed
This was referenced Jul 27, 2026
Closed
Closed
This was referenced Aug 3, 2026
Closed
This was referenced Aug 12, 2026
Merged
This was referenced Aug 19, 2026
This was referenced Sep 7, 2026
This was referenced Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces improvements to the handling and testing of the
OnBeforeTokenAcquisitionForOnBehalfOfevent in token acquisition scenarios, specifically ensuring that the correctClaimsPrincipalis passed and its context is preserved. The most important changes are grouped below by theme.Token Acquisition Logic Improvement:
NotifyCertificateSelectionmethod inTokenAcquisition.csto useuserHintinstead ofuserwhen invoking theOnBeforeTokenAcquisitionForOnBehalfOfAsyncevent, ensuring the correct principal is used during token acquisition.Unit Test Enhancements:
AuthorizationHeaderProviderTests.cs, enhanced theLongRunningSessionForDefaultAuthProviderForUserDefaultKeyTestby configuring theTokenAcquisitionExtensionOptionsto subscribe to theOnBeforeTokenAcquisitionForOnBehalfOfevent. The test now verifies that theClaimsPrincipalpassed to the event matches the one used in the authorization header provider and that theBootstrapContextis preserved.ClaimsPrincipaland its identity earlier in the test and removing duplicate code.Dependency Update:
NSubstitute.Extensionsto the test file imports, likely to support more advanced mocking scenarios in unit tests.Fixing OBO user error