Support configurable scheduler token audiences and government defaults - #806
Open
Bernd Verst (berndverst) wants to merge 1 commit into
Open
Bernd Verst (berndverst) wants to merge 1 commit into
Bernd Verst (berndverst) wants to merge 1 commit into
Conversation
Add ResourceId connection-string support and independent AuthorityHost forwarding. Preserve audience selection through DI, token refresh, and sandbox registration, with recording-credential regressions and government-cloud documentation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Bernd Verst (berndverst)
September 26, 2026 07:04
View session
Comment on lines
+85
to
+86
| { | ||
| } |
Copilot stopped reviewing on behalf of
Bernd Verst (berndverst) due to an error
September 26, 2026 07:24
Contributor
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR updates Azure Managed client/worker configuration to treat ResourceId as a normalized token audience with region-based defaults (including a behavior change for gov/DoD regions) and adds optional AuthorityHost support for SDK-created Azure Identity credentials, with expanded shared authentication test coverage and documentation.
Changes:
- Normalize
ResourceIdtoken audience handling with per-options-instance defaults, plus explicit-copy behavior for channel recreation/reconnect scenarios. - Add
AuthorityHostparsing to connection strings and flow it into Azure Identity credential options where applicable. - Add shared and sandbox authentication tests, and document the new behavior (README, release notes, changelog).
| File | Description |
|---|---|
| test/Worker/AzureManaged.Tests/Worker.AzureManaged.Tests.csproj | Includes shared auth test code and defines SCHEDULER_WORKER to compile worker-specific shared tests. |
| test/Worker/AzureManaged.Tests/SandboxAuthenticationTests.cs | Adds worker sandbox registration/auth reconnect tests validating audience + token cache behavior. |
| test/Worker/AzureManaged.Tests/DurableTaskSchedulerWorkerOptionsTests.cs | Updates tests for new default ResourceId behavior (no longer fixed to durabletask.io). |
| test/Worker/AzureManaged.Tests/DurableTaskSchedulerWorkerExtensionsTests.cs | Updates extension tests for new default ResourceId behavior. |
| test/Shared/AzureManaged/SchedulerAuthenticationTests.cs | Adds shared authentication tests (client/worker via #if) and a local gRPC test server & credential recorder. |
| test/Shared/AzureManaged.Tests/DurableTaskSchedulerConnectionStringTests.cs | Adds tests for AuthorityHost preservation/validation in connection string credential option creation. |
| test/Client/AzureManaged.Tests/SandboxAuthenticationTests.cs | Adds client sandbox management/auth tests validating audience + token cache behavior. |
| test/Client/AzureManaged.Tests/DurableTaskSchedulerClientOptionsTests.cs | Updates tests for new default ResourceId behavior. |
| test/Client/AzureManaged.Tests/DurableTaskSchedulerClientExtensionsTests.cs | Updates extension tests for new default ResourceId behavior. |
| test/Client/AzureManaged.Tests/Client.AzureManaged.Tests.csproj | Includes shared auth test code for the client test project. |
| src/Worker/AzureManaged/RELEASENOTES.md | Documents ResourceId normalization/default behavior change and AuthorityHost support. |
| src/Worker/AzureManaged/DurableTaskSchedulerWorkerOptions.cs | Implements per-instance default ResourceId, normalization, AuthorityHost credential options forwarding, and copy semantics. |
| src/Worker/AzureManaged/DurableTaskSchedulerWorkerExtensions.cs | Ensures ResourceId is copied from connection options when configuring via extensions. |
| src/Worker/AzureManaged.Sandboxes/DurableTaskSchedulerSandboxWorkerExtensions.cs | Documents shared audience behavior for worker + sandbox registration. |
| src/Shared/AzureManaged/DurableTaskSchedulerResourceId.cs | Adds shared default resolution + normalization for token audience URIs. |
| src/Shared/AzureManaged/DurableTaskSchedulerConnectionString.cs | Adds connection-string ResourceId property and AuthorityHost-aware credential options creation. |
| src/Client/AzureManaged/RELEASENOTES.md | Documents ResourceId normalization/default behavior change and AuthorityHost support. |
| src/Client/AzureManaged/DurableTaskSchedulerClientOptions.cs | Mirrors worker changes for client options (per-instance default, normalization, copy semantics, authority host forwarding). |
| src/Client/AzureManaged/DurableTaskSchedulerClientExtensions.cs | Ensures ResourceId is copied from connection options when configuring via extensions. |
| src/Client/AzureManaged.Sandboxes/SandboxActivitiesClientServiceCollectionExtensions.cs | Documents that sandbox management reuses the configured client channel/audience. |
| samples/on-demand-sandbox/README.md | Adds guidance for gov cloud audience + authority configuration. |
| README.md | Adds comprehensive documentation on token audiences, gov defaults, normalization, and AuthorityHost. |
| CHANGELOG.md | Captures behavior change and new connection-string support. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| @@ -1,6 +1,7 @@ | |||
| // Copyright (c) Microsoft Corporation. | |||
| // Licensed under the MIT License. | |||
|
|
|||
Comment on lines
+326
to
+333
| public override ValueTask<AccessToken> GetTokenAsync(TokenRequestContext requestContext, CancellationToken cancellationToken) | ||
| { | ||
| this.scopes.Enqueue(Assert.Single(requestContext.Scopes)); | ||
| return ValueTask.FromResult(new AccessToken( | ||
| "recorded-token", | ||
| expireFirstToken && this.scopes.Count == 1 ? DateTimeOffset.UtcNow.AddMinutes(-1) : DateTimeOffset.UtcNow.AddHours(1), | ||
| refreshFirstToken && this.scopes.Count == 1 ? DateTimeOffset.UtcNow.AddMinutes(-1) : null)); | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
What changed?
DurableTaskSchedulerClientOptions.ResourceIdandDurableTaskSchedulerWorkerOptions.ResourceIdproperties with shared normalization and per-options-instance defaults. No constructor or overload signatures change.ResourceIdconnection-string configuration for all authentication types, including forwarding through named client/worker builders. Preserve already-normalized values when copying options so meaningful repeated/.defaultURI segments are not stripped twice.https://durabletask.azure.usfor missing/null/empty audiences whenREGION_NAMEstarts withusgovorusdod, case-insensitively; retainhttps://durabletask.iootherwise. Explicit audiences always win.AuthorityHostconnection-string forwarding for SDK-created credentials that support it; omission preserves Azure Identity's defaults and environment configuration. Managed identity and developer-tool cloud configuration remain separate.Why is this change needed?
Applications need explicit/custom audiences and predictable government-cloud defaults without silently changing endpoints or credential authority. Existing
ResourceIdoptions were not normalized or forwarded from connection strings.Credential construction and authority-host rationale
The .NET SDK supports both caller-created credentials and SDK-created credentials. Credential construction from connection strings already existed before this PR; this PR does not introduce that ownership model.
UseDurableTaskScheduler(endpointAddress, taskHubName, credential, ...)or settingoptions.CredentialUseDurableTaskScheduler(connectionString, ...)/DurableTaskSchedulerClientOptions.FromConnectionString(...)AuthenticationAuthorityHostis passed into supported Azure Identity credential options before construction.UseSandboxWorker()ManagedIdentityCredentialEvidence at this PR's implementation commit:
DefaultAzureCredential,ManagedIdentityCredential,WorkloadIdentityCredential,EnvironmentCredential,AzureCliCredential,AzurePowerShellCredential,VisualStudioCredential,VisualStudioCodeCredential, andInteractiveBrowserCredential;Authentication=Nonereturns null.AuthorityHostonly for an explicit nonempty connection-string value. Omission preserves Azure Identity defaults, includingAZURE_AUTHORITY_HOSTwhere applicable.Therefore the optional connection-string authority support is retained. No SDK authority property is added for caller-supplied credentials. Managed identity, Azure CLI, Azure PowerShell, and anonymous authentication do not receive this authority override; developer tools may need their own cloud configuration. Neither
ResourceIdnorREGION_NAMEsets an authority or endpoint.Issues / work items
Breaking Change
Type: behavioral
Impact: Applications with
REGION_NAMEbeginning withusgovorusdodnow default to the government token audience. Explicit audiences are normalized, and whitespace-only or empty-after-normalization values now throw actionable argument errors.Migration: Set
ResourceId=https://durabletask.ioexplicitly on both client and worker, or in their connection strings, to retain the prior audience in government regions. Correct invalid audience values. Configure the credential authority and endpoint separately when targeting a different cloud.No binary or source breaking change: existing property and constructor signatures remain intact; the setter's nullability annotation is widened. Orchestration replay, serialization, protobuf fields, and token-cache implementation are unchanged.
Project checklist
CHANGELOG.mdand both AzureManagedRELEASENOTES.mdfilesAI-assisted code disclosure (required)
Was an AI tool used? (select one)
If AI was used:
AI verification (agent verification completed; human review pending):
Testing
Automated tests
REGION_NAME=USGOVVIRGINIA(332 repeat executions).dotnet format style --no-restore --verify-no-changeschecks passed for changed authentication source and new tests; build-time .NET/StyleCop analyzers ran.FINALNEWLINE: the existing.editorconfigrequiresinsert_final_newline=false, while StyleCop requires a final newline. Existing final-newline conventions were retained rather than changing unrelated repository configuration.git diff --checkpasses withcore.whitespace=cr-at-eol, preserving the changelog's existing CRLF format.Manual validation (only if runtime/behavior changed)
TokenCredential.GetTokenAsync; loopback gRPC servers exercise the configured client/worker channels and sandbox management/registration transports.Notes for reviewers