Skip to content

Isolate mutable token acquisition request options - #4013

Open
Ignacio Inglese (iNinja) wants to merge 4 commits into
masterfrom
iinglese/token-acquisition-option-isolation-minimal
Open

Ignacio Inglese (iNinja) wants to merge 4 commits into
masterfrom
iinglese/token-acquisition-option-isolation-minimal

Conversation

@iNinja

@iNinja Ignacio Inglese (iNinja) commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Use the Microsoft.Identity.Abstractions option-clone contract for Downstream API and FIC requests.
  • Isolate the remaining mutable parameters in authorization-header and non-bearer Graph requests.
  • Preserve request-owned long-running session-key output without mutating shared Graph configuration.

Release notes

No intended API behavior change. Request-specific token acquisition parameters no longer modify shared authorization-header or Graph configuration. Downstream API and FIC isolation use the clone behavior provided by Microsoft.Identity.Abstractions.

Testing

  • 95 focused token-acquisition and Downstream API tests passed on .NET 8.
  • 4 Graph service client tests passed on .NET 8.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Isolates request-specific token acquisition state to prevent mutation of shared configuration during concurrent requests.

Changes:

  • Clones mutable extra parameters while preserving standard dictionary comparers.
  • Isolates FIC, agent, Graph, and mTLS PoP request options.
  • Propagates generated long-running session keys only to request-owned Graph options.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquirerExtensions.cs Isolates FIC assertion parameters.
src/Microsoft.Identity.Web.TokenAcquisition/DefaultAuthorizationHeaderProvider.cs Isolates token-binding parameters.
src/Microsoft.Identity.Web.GraphServiceClient/GraphAuthenticationProvider.cs Clones Graph token options and propagates session keys safely.
src/Microsoft.Identity.Web.DownstreamApi/DownstreamApi.cs Copies mutable parameters before request overrides.
tests/Microsoft.Identity.Web.Test/TokenAcquirerExtensionsTests.cs Tests FIC parameter isolation.
tests/Microsoft.Identity.Web.Test/DownstreamWebApiSupport/DownstreamApiTests.cs Tests agent override isolation and comparer preservation.
tests/Microsoft.Identity.Web.Test/DefaultAuthorizationHeaderProviderTests.cs Tests mTLS PoP parameter isolation.
tests/E2E Tests/GraphServiceClientTests/GraphServiceClientTests.cs Tests Graph isolation, cancellation, and session-key behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@iarekk

Copy link
Copy Markdown
Contributor

Heads-up for a later cleanup: Microsoft.Identity.Abstractions 12.6.1 makes the
Clone() / copy-constructors on AcquireTokenOptions and DownstreamApiOptions
allocate independent containers for their mutable collections
(ExtraParameters, ExtraQueryParameters, ExtraHeadersParameters) instead of
copying the references (AzureAD/microsoft-identity-abstractions-for-dotnet#269).

So once IdWeb takes 12.6.1 (via #4020), the per-request copies added here are
also guaranteed at the library level -- the local CopyExtraParameters helpers
become belt-and-suspenders and could be simplified in a follow-up. No change
needed in this PR; the defensive copies are fine to ship now.

}

DownstreamApiOptions clonedOptions = new DownstreamApiOptions(options);
clonedOptions.AcquireTokenOptions.ExtraParameters =

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Iarek Kovtunenko (@iarekk) - didn't you just fix this in DownstreamApiOptions in Abstractions?

{
AcquireTokenOptions = graphServiceClientOptions.AcquireTokenOptions.Clone()
};
authorizationHeaderProviderOptions.AcquireTokenOptions.ExtraParameters =

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clone() should take care of this. I believe Iarek Kovtunenko (@iarekk) fixed this?

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use the polymorphic options clone path when isolating non-bearer Graph requests and cover custom CloneInternal overrides.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants