Skip to content

[6.1.7] APIScan remediation: remove obsolete SharedTokenCacheUsername, migrate obsolete ManagedIdentityCredential ctor - #4449

Merged
paulmedynski merged 1 commit into
release/6.1from
dev/automation/pr-4421-to-6.1.7
Jul 16, 2026
Merged

paulmedynski merged 1 commit into
release/6.1from
dev/automation/pr-4421-to-6.1.7

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

Description

Cherry-pick of #4421 into release/6.1 (6.1.7). On this branch the provider lives in the Microsoft.Data.SqlClient project (ActiveDirectoryAuthenticationProvider.cs) rather than the Microsoft.Data.SqlClient.Extensions.Azure project. Two of the three changes from #4421 apply here:

  1. Remove obsolete SharedTokenCacheUsername assignment (APIScan WI 42859 netstandard2.0 / WI 42860 net462 — same source line).

    • DefaultAzureCredentialOptions.SharedTokenCacheUsername is [Obsolete] + [EditorBrowsable(Never)] in the repo-pinned Azure.Identity (1.17.1) and undocumented on learn.microsoft.com.
    • SharedTokenCacheCredential is no longer in DefaultAzureCredential's default chain, so the assignment was a no-op. The client id is still propagated via ManagedIdentityClientId and WorkloadIdentityClientId for the in-chain credentials.
    • The now-unneeded #pragma warning disable/restore CS0618 that wrapped the assignment is removed with it.
  2. Migrate an obsolete API. ManagedIdentityCredential(string clientId, TokenCredentialOptions) is [Obsolete]. Migrated to the supported ManagedIdentityCredential(ManagedIdentityCredentialOptions) constructor.

The third change from #4421 — fixing a masked CS0618 pragma — does not apply on this branch: the corresponding #pragma warning restore CS0618 is already balanced here, so no obsolete-member warnings were being masked.

API changes / backwards compatibility

No public API changes. Behavior of the managed-identity path is preserved exactly:

  • Identity selection uses string.IsNullOrEmpty(clientId) → null-or-empty client id maps to ManagedIdentityId.SystemAssigned, otherwise ManagedIdentityId.FromUserAssignedClientId(clientId) — matching the obsolete constructor's internal logic.
  • AuthorityHost is carried over via ManagedIdentityCredentialOptions (which derives from TokenCredentialOptions).
  • The shared TokenCredentialOptions local is moved into the ClientSecretCredential branch, its only remaining consumer.

Issues

APIScan work items WI 42859 / WI 42860 (obsolete SharedTokenCacheUsername). Branch tracks WI 43668 remediation.

Testing

  • Microsoft.Data.SqlClient (net8.0) rebuilds clean: 0 warnings / 0 errors — confirming the new ManagedIdentityId / ManagedIdentityCredentialOptions usage compiles and no obsolete-API (CS0618) warnings remain.
  • AADAuthenticationTests (FunctionalTests, net8.0): 7 passed / 0 failed.
  • WamBrokerTests + AAD/provider unit tests (UnitTests, net8.0): 16 passed / 0 failed.

@github-actions github-actions Bot added this to the 6.1.7 milestone Jul 16, 2026
@github-project-automation github-project-automation Bot moved this to To triage in SqlClient Board Jul 16, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

…e obsolete ManagedIdentityCredential ctor (#4421)

Cherry-pick of #4421 into release/6.1 (6.1.7). On this branch the provider
lives in the Microsoft.Data.SqlClient project rather than the
Microsoft.Data.SqlClient.Extensions.Azure project.

- Remove the obsolete DefaultAzureCredentialOptions.SharedTokenCacheUsername
  assignment (and its now-unneeded CS0618 pragma wrapper).
- Migrate the obsolete ManagedIdentityCredential(string, TokenCredentialOptions)
  constructor to ManagedIdentityCredential(ManagedIdentityCredentialOptions).

The masked-CS0618-pragma fix from #4421 does not apply here: the pragma is
already balanced (restore) on this branch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@paulmedynski
paulmedynski force-pushed the dev/automation/pr-4421-to-6.1.7 branch from 6160926 to bbc6a58 Compare July 16, 2026 11:49
@paulmedynski paulmedynski changed the title [6.1.7 Cherry-pick - CONFLICTS] APIScan remediation: remove obsolete SharedTokenCacheUsername, fix masked CS0618 pragma, migrate obsolete ManagedIdentityCredential ctor APIScan remediation: remove obsolete SharedTokenCacheUsername, migrate obsolete ManagedIdentityCredential ctor Jul 16, 2026
@paulmedynski paulmedynski changed the title APIScan remediation: remove obsolete SharedTokenCacheUsername, migrate obsolete ManagedIdentityCredential ctor [6.1.7] APIScan remediation: remove obsolete SharedTokenCacheUsername, migrate obsolete ManagedIdentityCredential ctor Jul 16, 2026
@paulmedynski

Copy link
Copy Markdown
Contributor

/azp run

@paulmedynski paulmedynski moved this from To triage to In review in SqlClient Board Jul 16, 2026
@paulmedynski
paulmedynski marked this pull request as ready for review July 16, 2026 11:51
@paulmedynski
paulmedynski requested a review from a team as a code owner July 16, 2026 11:51
Copilot AI review requested due to automatic review settings July 16, 2026 11:51
@paulmedynski
paulmedynski enabled auto-merge (squash) July 16, 2026 11:51
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 2 pipeline(s).
3 pipeline(s) were filtered out due to trigger conditions.

@paulmedynski paulmedynski self-assigned this Jul 16, 2026
@paulmedynski paulmedynski added the Code Health 💊 Issues/PRs that are targeted to source code quality improvements. label Jul 16, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Cherry-picks APIScan remediation into the release/6.1 branch by removing an obsolete Azure.Identity option usage and updating managed identity credential construction to the supported API, keeping the authentication behavior consistent with prior logic.

Changes:

  • Removed the obsolete DefaultAzureCredentialOptions.SharedTokenCacheUsername assignment and its #pragma warning wrapper.
  • Migrated from the obsolete ManagedIdentityCredential(string, TokenCredentialOptions) constructor to ManagedIdentityCredential(ManagedIdentityCredentialOptions) using ManagedIdentityId for identity selection.
  • Minor whitespace cleanup.

@paulmedynski
paulmedynski merged commit 2629bea into release/6.1 Jul 16, 2026
281 checks passed
@paulmedynski
paulmedynski deleted the dev/automation/pr-4421-to-6.1.7 branch July 16, 2026 17:30
@github-project-automation github-project-automation Bot moved this from In review to Done in SqlClient Board Jul 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Code Health 💊 Issues/PRs that are targeted to source code quality improvements.

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

5 participants