[6.1.7] APIScan remediation: remove obsolete SharedTokenCacheUsername, migrate obsolete ManagedIdentityCredential ctor - #4449
Merged
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
…e obsolete ManagedIdentityCredential ctor (#4421) Cherry-pick of #4421 into release/6.1 (6.1.7). On this branch the provider lives in the Microsoft.Data.SqlClient project rather than the Microsoft.Data.SqlClient.Extensions.Azure project. - Remove the obsolete DefaultAzureCredentialOptions.SharedTokenCacheUsername assignment (and its now-unneeded CS0618 pragma wrapper). - Migrate the obsolete ManagedIdentityCredential(string, TokenCredentialOptions) constructor to ManagedIdentityCredential(ManagedIdentityCredentialOptions). The masked-CS0618-pragma fix from #4421 does not apply here: the pragma is already balanced (restore) on this branch. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
paulmedynski
force-pushed
the
dev/automation/pr-4421-to-6.1.7
branch
from
July 16, 2026 11:49
6160926 to
bbc6a58
Compare
Contributor
|
/azp run |
paulmedynski
marked this pull request as ready for review
July 16, 2026 11:51
paulmedynski
enabled auto-merge (squash)
July 16, 2026 11:51
|
Azure Pipelines: Successfully started running 2 pipeline(s). 3 pipeline(s) were filtered out due to trigger conditions. |
paulmedynski
approved these changes
Jul 16, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
Cherry-picks APIScan remediation into the release/6.1 branch by removing an obsolete Azure.Identity option usage and updating managed identity credential construction to the supported API, keeping the authentication behavior consistent with prior logic.
Changes:
- Removed the obsolete
DefaultAzureCredentialOptions.SharedTokenCacheUsernameassignment and its#pragma warningwrapper. - Migrated from the obsolete
ManagedIdentityCredential(string, TokenCredentialOptions)constructor toManagedIdentityCredential(ManagedIdentityCredentialOptions)usingManagedIdentityIdfor identity selection. - Minor whitespace cleanup.
priyankatiwari08
approved these changes
Jul 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Cherry-pick of #4421 into
release/6.1(6.1.7). On this branch the provider lives in theMicrosoft.Data.SqlClientproject (ActiveDirectoryAuthenticationProvider.cs) rather than theMicrosoft.Data.SqlClient.Extensions.Azureproject. Two of the three changes from #4421 apply here:Remove obsolete
SharedTokenCacheUsernameassignment (APIScan WI 42859 netstandard2.0 / WI 42860 net462 — same source line).DefaultAzureCredentialOptions.SharedTokenCacheUsernameis[Obsolete]+[EditorBrowsable(Never)]in the repo-pinned Azure.Identity (1.17.1) and undocumented on learn.microsoft.com.SharedTokenCacheCredentialis no longer inDefaultAzureCredential's default chain, so the assignment was a no-op. The client id is still propagated viaManagedIdentityClientIdandWorkloadIdentityClientIdfor the in-chain credentials.#pragma warning disable/restore CS0618that wrapped the assignment is removed with it.Migrate an obsolete API.
ManagedIdentityCredential(string clientId, TokenCredentialOptions)is[Obsolete]. Migrated to the supportedManagedIdentityCredential(ManagedIdentityCredentialOptions)constructor.The third change from #4421 — fixing a masked
CS0618pragma — does not apply on this branch: the corresponding#pragma warning restore CS0618is already balanced here, so no obsolete-member warnings were being masked.API changes / backwards compatibility
No public API changes. Behavior of the managed-identity path is preserved exactly:
string.IsNullOrEmpty(clientId)→ null-or-empty client id maps toManagedIdentityId.SystemAssigned, otherwiseManagedIdentityId.FromUserAssignedClientId(clientId)— matching the obsolete constructor's internal logic.AuthorityHostis carried over viaManagedIdentityCredentialOptions(which derives fromTokenCredentialOptions).TokenCredentialOptionslocal is moved into theClientSecretCredentialbranch, its only remaining consumer.Issues
APIScan work items WI 42859 / WI 42860 (obsolete
SharedTokenCacheUsername). Branch tracks WI 43668 remediation.Testing
Microsoft.Data.SqlClient(net8.0) rebuilds clean: 0 warnings / 0 errors — confirming the newManagedIdentityId/ManagedIdentityCredentialOptionsusage compiles and no obsolete-API (CS0618) warnings remain.AADAuthenticationTests(FunctionalTests, net8.0): 7 passed / 0 failed.WamBrokerTests+ AAD/provider unit tests (UnitTests, net8.0): 16 passed / 0 failed.