Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,7 @@ public ActiveDirectoryAuthenticationProvider(ActiveDirectoryAuthenticationProvid

/// <summary>
/// The Entra ID application client id used by this provider instance. Exposed as <c>internal</c> for tests.
/// The client id is used in the redirect URI when WAM broker mode is enabled, so it must match the client id configured
/// The client id is used in the redirect URI when WAM broker mode is enabled, so it must match the client id configured
/// in the app registration for the Entra ID application to successfully broker with WAM on Windows.
/// </summary>
internal string ApplicationClientId => _applicationClientId;
Expand Down Expand Up @@ -182,7 +182,7 @@ public override void BeforeUnload(SqlAuthenticationMethod authentication)
// PublicClientAppKey cache (IWin32WindowFunc is part of its equality), so the same logical
// identity ends up with two IPublicClientApplication instances depending on which setter
// the caller used. Mark [Obsolete] in a future release once we have a migration window.

/// <include file='../doc/ActiveDirectoryAuthenticationProvider.xml' path='docs/members[@name="ActiveDirectoryAuthenticationProvider"]/SetIWin32WindowFunc/*'/>
public void SetIWin32WindowFunc(Func<System.Windows.Forms.IWin32Window> iWin32WindowFunc) => _iWin32WindowFunc = iWin32WindowFunc;
#endif
Expand Down Expand Up @@ -373,7 +373,7 @@ previousPw is byte[] previousPwBytes &&
{
#pragma warning disable CS0618 // Type or member is obsolete
result = await app.AcquireTokenByUsernamePassword(scopes, parameters.UserId, parameters.Password)
#pragma warning disable CS0618 // Type or member is obsolete
#pragma warning restore CS0618 // Type or member is obsolete
Comment thread
paulmedynski marked this conversation as resolved.
.WithCorrelationId(parameters.ConnectionId)
.ExecuteAsync(cancellationToken: cts.Token)
.ConfigureAwait(false);
Expand Down Expand Up @@ -873,7 +873,6 @@ private static TokenCredentialData CreateTokenCredentialInstance(TokenCredential
if (tokenCredentialKey._clientId is not null)
{
defaultAzureCredentialOptions.ManagedIdentityClientId = tokenCredentialKey._clientId;
defaultAzureCredentialOptions.SharedTokenCacheUsername = tokenCredentialKey._clientId;
Comment thread
paulmedynski marked this conversation as resolved.
defaultAzureCredentialOptions.WorkloadIdentityClientId = tokenCredentialKey._clientId;
}

Expand Down Expand Up @@ -901,14 +900,24 @@ private static TokenCredentialData CreateTokenCredentialInstance(TokenCredential
return new TokenCredentialData(cred, GetHash(secret));
}

TokenCredentialOptions tokenCredentialOptions = new() { AuthorityHost = new Uri(tokenCredentialKey._authority) };

if (tokenCredentialKey._tokenCredentialType == typeof(ManagedIdentityCredential))
{
return new TokenCredentialData(new ManagedIdentityCredential(tokenCredentialKey._clientId, tokenCredentialOptions), GetHash(secret));
Comment thread
paulmedynski marked this conversation as resolved.
// A null or empty client id indicates a system-assigned managed identity; a
// non-empty client id selects a specific user-assigned managed identity.
ManagedIdentityId managedIdentityId = string.IsNullOrEmpty(tokenCredentialKey._clientId)
? ManagedIdentityId.SystemAssigned
: ManagedIdentityId.FromUserAssignedClientId(tokenCredentialKey._clientId);
ManagedIdentityCredentialOptions managedIdentityCredentialOptions = new(managedIdentityId)
{
AuthorityHost = new Uri(tokenCredentialKey._authority)
};

return new TokenCredentialData(new ManagedIdentityCredential(managedIdentityCredentialOptions), GetHash(secret));
}
else if (tokenCredentialKey._tokenCredentialType == typeof(ClientSecretCredential))
{
TokenCredentialOptions tokenCredentialOptions = new() { AuthorityHost = new Uri(tokenCredentialKey._authority) };
Comment thread
paulmedynski marked this conversation as resolved.

return new TokenCredentialData(new ClientSecretCredential(tokenCredentialKey._audience, tokenCredentialKey._clientId, secret, tokenCredentialOptions), GetHash(secret));
}
else if (tokenCredentialKey._tokenCredentialType == typeof(WorkloadIdentityCredential))
Expand Down
Loading