Skip to content

Fix FIC telemetry enrichment during credential warm-up and assertion cache hits - #4072

Merged
Neha Bhargava (neha-bhargava) merged 3 commits into
masterfrom
nebharg/fic-otel-enrichment-bug
Sep 25, 2026
Merged

Neha Bhargava (neha-bhargava) merged 3 commits into
masterfrom
nebharg/fic-otel-enrichment-bug

Conversation

@neha-bhargava

@neha-bhargava Neha Bhargava (neha-bhargava) commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Replaces #4069 to move the head branch into this repository. The head commit is unchanged; prior review discussion remains on #4069.

Summary Fix FIC OpenTelemetry enrichment during credential warm-up and inner MSAL cache hits. Follow-up to #3968 (AB#3696484). ## Changes - Forward operation-local enrichment to OIDC, managed-identity, and key-attested managed-identity warm-up. - Add TokenAcquisitionExtensionOptions.DefaultAppTokenOtelTagsEnricher for enrichment configured before client construction. - Use a per-request callback for built-in OIDC and managed-identity providers so inner MSAL handles caching and telemetry. Direct calls and custom providers retain Identity.Web assertion caching. - Forward OIDC claims so a claims challenge does not reuse an unsuitable cached assertion. - Preserve credential fallback and existing bound/FMI warm-up deferral. ## Behavior - Per-request enrichment takes precedence over the default. - Callbacks are not retained on cached providers and must be thread-safe. - Outer bearer-token cache hits do not request an assertion or emit an inner acquisition metric. - User FIC factories, custom FMI providers, telemetry exporters, and client-capability propagation are unchanged. - No dependency or package-version changes. ## Validation - Focused FIC, warm-up, caching, provider, loader, and CAE tests: 96 passed on .NET 8 and 96 passed on .NET 10. - OidcFIC builds for netstandard2.0 and net472: passed with public API analyzers enabled. - Public API baselines and credential documentation updated.

Forward operation-local enrichment to credential loaders and add an early default callback. Delegate built-in OIDC and managed-identity assertion caching to MSAL while preserving fallback and custom-provider caching.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 7cbc27ae-808b-448b-9eed-2b32355607f3
@neha-bhargava
Neha Bhargava (neha-bhargava) merged commit 91ff24d into master Sep 25, 2026
9 checks passed
@neha-bhargava
Neha Bhargava (neha-bhargava) deleted the nebharg/fic-otel-enrichment-bug branch September 25, 2026 19:33
Sarah Sayeed Qureshi (sarahsa) pushed a commit to heimdallpower/api-sdk that referenced this pull request Oct 2, 2026
Updated
[coverlet.collector](https://github.com/coverlet-coverage/coverlet) from
10.0.1 to 10.1.0.

<details>
<summary>Release notes</summary>

_Sourced from [coverlet.collector's
releases](https://github.com/coverlet-coverage/coverlet/releases)._

## 10.1.0

### Improvements

- Publish Microsoft.Testing.Platform coverage messages from coverlet.MTP
[#​2019](coverlet-coverage/coverlet#2019)
- Implement dynamic exclusion filters for assemblies (Coverlet.MTP)
[#​1946](coverlet-coverage/coverlet#1946)
- Replace legacy .sln files with modern .slnx format
[#​1966](coverlet-coverage/coverlet#1966)
- coverlet.console: add trace diagnostics and actionable warnings for
instrumentation/hit/empty-result failures
[#​2005](coverlet-coverage/coverlet#2005)
- Relax auto-property skip logic and improve coverage for records
[#​1941](coverlet-coverage/coverlet#1941)

### Fixed

- Fix coverlet.MTP does not collect coverage on the .NET Framework
portion of a large project
[#​1980](coverlet-coverage/coverlet#1980)
[#​1967](coverlet-coverage/coverlet#1967)
- Fix Regression in branch coverage for lambda expressions
[#​1938](coverlet-coverage/coverlet#1938)
- Fix When using "is" with "or" in pattern matching, branch coverage is
lower than normal
[#​1979](coverlet-coverage/coverlet#1979)
- Fix silent zero coverage on .NET Framework since 8.0.0
[#​1985](coverlet-coverage/coverlet#1985) by
@​tobiwae
- Fix Race condition between ProcessExit hit-file write and out-of-proc
coverage read causes EndOfStreamException
[#​1987](coverlet-coverage/coverlet#1987)
[#​1988](coverlet-coverage/coverlet#1988) by
@​bkoelman
- Fix Regression TypeInitializationException when targeting .NET
Framework - Could not load type
'System.Collections.Concurrent.ConcurrentBag
[#​2010](coverlet-coverage/coverlet#2010)
- Fix use --config-file CLI arg in coverlet.MTP
[#​2030](coverlet-coverage/coverlet#2030) by
alexthornton1
- Fix silently empty coverage for shared-framework assemblies missing
from compileLibraries
[#​2032](coverlet-coverage/coverlet#2032) by
@​Eljees

[Diff between 10.0.1 and
10.1.0](coverlet-coverage/coverlet@v10.0.1...v10.1.0)

Commits viewable in [compare
view](coverlet-coverage/coverlet@v10.0.1...v10.1.0).
</details>

Updated
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
from 4.15.0 to 4.16.0.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.16.0

## What's Changed
* Add 4.15.0 release notes by @​iarekk in
AzureAD/microsoft-identity-web#4050
* Post-release 4.15.0: mark APIs shipped and bump version by @​iarekk in
AzureAD/microsoft-identity-web#4060
* Add Sidecar 1.1.2 changelog by @​soodt in
AzureAD/microsoft-identity-web#4070
* Fix FIC telemetry enrichment during credential warm-up and assertion
cache hits by @​neha-bhargava in
AzureAD/microsoft-identity-web#4072
* Update agentic docs to cover current behavior by @​Avery-Dunn in
AzureAD/microsoft-identity-web#4077
* Bump the notsecurity group with 4 updates by @​dependabot[bot] in
AzureAD/microsoft-identity-web#4074


**Full Changelog**:
AzureAD/microsoft-identity-web@4.15.0...4.16.0

Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.15.0...4.16.0).
</details>

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants