-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
identity: managedIdentityCredential expires-in/-on #24102
Conversation
Sometimes token lifetimes are tracked by absolute timestamps ("expires On") and sometimes using a time interval ("expires In"). The managedIdentityCredential AppTokenProvider implementation was inconsistent in its treatment, directly coercing an absolute timestamp to an interval. See #24003 for example downstream effects.
Thank you for your contribution nwf-msr! We will review the pull request and get back to you soon. |
Can you run |
sdk/identity/identity/src/credentials/managedIdentityCredential/index.ts
Outdated
Show resolved
Hide resolved
sdk/identity/identity/src/credentials/managedIdentityCredential/index.ts
Outdated
Show resolved
Hide resolved
…l/index.ts Co-authored-by: Jeff Fisher <[email protected]>
…l/index.ts Co-authored-by: Jeff Fisher <[email protected]>
Thanks for the feedback; JS is not my native tongue. :) Would you like me to squash the commits or will you do that when merging? |
I'll do it when merging |
Thanks again for your contribution! 😄 |
Release web 2023 01 01 (Azure#26545) * Add new api-version 2023-01-01 (Azure#22962) * Add new api-version 2023-01-01 * Change default package api-version * Updated workflowstate to be a reference (Azure#23084) * Fix OneDeploy request and response bodies (Azure#23224) * Fix OneDeploy request and response bodies * Fixing typo * Add Container Apps Environment Id in checknameavailability API (Azure#24102) Co-authored-by: Vishal Gupta <[email protected]> * Add minTlsCipherSuite property (Azure#24198) * Add minTlsCipherSuite property * Move to SiteConfig --------- Co-authored-by: Chris Rosenblatt <[email protected]> * Dapr configuration for a site (Azure#24606) * Dapr configuration for a site * removed dapr older definition * adding back old dapr definition * Modified 'Dapr' to 'DaprConfig' to resolve conflicts with older dapr definition * to initiate checks as re-run * fixed prettier check fail --------- Co-authored-by: Sushmitha Vangala <[email protected]> * Fix for JS SDK check failure for Dapr Config (Azure#25493) * Dapr configuration for a site * removed dapr older definition * adding back old dapr definition * Modified 'Dapr' to 'DaprConfig' to resolve conflicts with older dapr definition * to initiate checks as re-run * fixed prettier check fail * JS Sdk check fail fix --------- Co-authored-by: Sushmitha Vangala <[email protected]> * Release web 2023 01 01 (Azure#25157) * Adding locations/usages endpoint and example * Revert "Adding locations/usages endpoint and example" This reverts commit 4a1110765d08c5c96d65f884237313515d842586. * Adding back usages changes with up to date branch * Updates based on verification tools * Fixing spacing, adding missing comma * ran prettier-fix for formatting * Update for new QMS requirements with ZR * Using prettier to fix linter error * Adding ZR endpoint * Fixing duplicate operationId * QMS Usages * Validation changes * Updating schema * Updating for collection * fixing pr comments * Resolving comments * Updating description * Resolving comments --------- Co-authored-by: Rohini Sharma <[email protected]> * Release web 2023 01 01 (Azure#25629) * Adding locations/usages endpoint and example * Revert "Adding locations/usages endpoint and example" This reverts commit 4a1110765d08c5c96d65f884237313515d842586. * Adding back usages changes with up to date branch * Updates based on verification tools * Fixing spacing, adding missing comma * ran prettier-fix for formatting * Update for new QMS requirements with ZR * Using prettier to fix linter error * Adding ZR endpoint * Fixing duplicate operationId * QMS Usages * Validation changes * Updating schema * Updating for collection * fixing pr comments * Resolving comments * Updating description * Resolving comments * Removing quota type parameter --------- Co-authored-by: Rohini Sharma <[email protected]> * Adding workload profile & resource config to Site (Azure#25868) * Adding workload profile & resource config to Site * prettier fix * cosmetic fix * updating examples * prettier fix * Fix Python SDK failure for Dapr log level config (Azure#26198) * Rename log level enum for dapr * Fix Python SDK failure for Dapr log level config * Rename log level num for dapr (Azure#26374) * Rename log level num for dapr * Rename log level num for dapr * initial change to add ase regions (Azure#26333) * initial change to add ase regions * addressing comments * nit adding example as suggested * formatting code * add custom word * prettier everything * prettier everything * Revert "Fix OneDeploy request and response bodies (Azure#23224)" (Azure#26580) This reverts commit 7dfc303ee18440ee5eede155bb0d63797fbdc4bb. --------- Co-authored-by: Alex Karcher <[email protected]> Co-authored-by: dannysongg <[email protected]> Co-authored-by: Vishal Gupta <[email protected]> Co-authored-by: Vishal Gupta <[email protected]> Co-authored-by: Chris Rosenblatt <[email protected]> Co-authored-by: Chris Rosenblatt <[email protected]> Co-authored-by: SushmithaVReddy <[email protected]> Co-authored-by: Sushmitha Vangala <[email protected]> Co-authored-by: rohinisharma <[email protected]> Co-authored-by: Rohini Sharma <[email protected]> Co-authored-by: mukundnigam <[email protected]> Co-authored-by: Kirstyn Amperiadis <[email protected]> Co-authored-by: Haochi <[email protected]>
Packages impacted by this PR
@azure/identity
Issues associated with this PR
#24003
Describe the problem that is addressed by this PR
Sometimes token lifetimes are tracked by absolute timestamps ("expires On") and sometimes using a time interval ("expires In"). The managedIdentityCredential AppTokenProvider implementation was inconsistent in its treatment, directly coercing an absolute timestamp to an interval.
What are the possible designs available to address the problem? If there are more than one possible design, why was the one in this PR chosen?
It would be better if the SDK were consistent internally in its use of relative or absolute time, but that's a much taller ask.
Are there test cases added in this PR? (If not, why?)
No, but someone should.
Checklists