Isolate mutable token acquisition request options - #4013
Ignacio Inglese (iNinja) wants to merge 4 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Isolates request-specific token acquisition state to prevent mutation of shared configuration during concurrent requests.
Changes:
- Clones mutable extra parameters while preserving standard dictionary comparers.
- Isolates FIC, agent, Graph, and mTLS PoP request options.
- Propagates generated long-running session keys only to request-owned Graph options.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquirerExtensions.cs |
Isolates FIC assertion parameters. |
src/Microsoft.Identity.Web.TokenAcquisition/DefaultAuthorizationHeaderProvider.cs |
Isolates token-binding parameters. |
src/Microsoft.Identity.Web.GraphServiceClient/GraphAuthenticationProvider.cs |
Clones Graph token options and propagates session keys safely. |
src/Microsoft.Identity.Web.DownstreamApi/DownstreamApi.cs |
Copies mutable parameters before request overrides. |
tests/Microsoft.Identity.Web.Test/TokenAcquirerExtensionsTests.cs |
Tests FIC parameter isolation. |
tests/Microsoft.Identity.Web.Test/DownstreamWebApiSupport/DownstreamApiTests.cs |
Tests agent override isolation and comparer preservation. |
tests/Microsoft.Identity.Web.Test/DefaultAuthorizationHeaderProviderTests.cs |
Tests mTLS PoP parameter isolation. |
tests/E2E Tests/GraphServiceClientTests/GraphServiceClientTests.cs |
Tests Graph isolation, cancellation, and session-key behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Heads-up for a later cleanup: So once IdWeb takes 12.6.1 (via #4020), the per-request copies added here are |
| } | ||
|
|
||
| DownstreamApiOptions clonedOptions = new DownstreamApiOptions(options); | ||
| clonedOptions.AcquireTokenOptions.ExtraParameters = |
There was a problem hiding this comment.
Iarek Kovtunenko (@iarekk) - didn't you just fix this in DownstreamApiOptions in Abstractions?
| { | ||
| AcquireTokenOptions = graphServiceClientOptions.AcquireTokenOptions.Clone() | ||
| }; | ||
| authorizationHeaderProviderOptions.AcquireTokenOptions.ExtraParameters = |
There was a problem hiding this comment.
Clone() should take care of this. I believe Iarek Kovtunenko (@iarekk) fixed this?
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use the polymorphic options clone path when isolating non-bearer Graph requests and cover custom CloneInternal overrides. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Summary
Microsoft.Identity.Abstractionsoption-clone contract for Downstream API and FIC requests.Release notes
No intended API behavior change. Request-specific token acquisition parameters no longer modify shared authorization-header or Graph configuration. Downstream API and FIC isolation use the clone behavior provided by Microsoft.Identity.Abstractions.
Testing