Skip to content

Fix agent cache isolation by blueprint and agent - #4076

Open
Nilesh Choudhary (4gust) wants to merge 5 commits into
masterfrom
4gust-agentic-fmi-paths
Open

Nilesh Choudhary (4gust) wants to merge 5 commits into
masterfrom
4gust-agentic-fmi-paths

Conversation

@4gust

@4gust Nilesh Choudhary (4gust) commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Fix agent cache isolation by blueprint and agent

  • You've read the Contributor Guide and Code of Conduct.
  • You've included unit or integration tests for your change, where applicable.
  • You've included inline docs for your change, where applicable.
  • There's an open issue for the PR that you are making. If you'd like to propose a new feature or change, please open an issue to discuss the change or find an existing issue.

Prevent cross-blueprint reuse of cached agent clients and tokens.

Description

Use one blueprint+agent hash for both caches. The four-step live E2E and 73 unit tests pass; the separate same-blueprint/two-agent E2E awaits its second fixture.

Fixes: N/A (no linked issue).

Partition agent client and token caches by the selected blueprint configuration and parent identity. Preserve named credential selection for app-only and UserFIC acquisition, including refresh tokens and account lookups, without changing refresh semantics.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@4gust
Nilesh Choudhary (4gust) requested a review from a team as a code owner September 29, 2026 11:51
keyBuilder.Append(credentialId);
if (mergedOptions.AgentCachePartition is not null)
{
keyBuilder.Append(":agent-parent:");

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do we care about having even more CCA objects when they all share a cache? If the tokens are to be distinguished in the cache, then we should use MSAL extensiblity like WithCacheComponents("blueprint", id) ?

}

[Fact]
public void GetApplicationKey_AgentParentPartitions_DoNotMutateOriginalOptions()

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we have an E2E test with 1 blueprint and 2 agents please? We should clearly see that all operations are safe, by parsing the token and asserting the agentic claims.

@bgavrilMS Bogdan Gavril (bgavrilMS) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Need E2E test

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The sole earlier PR implementation at dde08d3 is superseded by the reviewed implementation. Retain the reviewed tree unchanged while preserving both histories.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@4gust Nilesh Choudhary (4gust) changed the title Fix agent cache isolation by blueprint configuration Fix agent cache isolation by blueprint and agent Sep 30, 2026
Comment thread tests/E2E Tests/AgentApplications/AutonomousAgentTests.cs Outdated
Comment thread src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs Outdated
Apply the pair partition after caller options and callbacks. Cover query and callback overrides, remove the unconfigured E2E case, and restore the original READMEs.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants