Skip to content

[12269] Test Helix Entra token refresh - #17510

Merged
missymessa merged 4 commits into
dotnet:mainfrom
missymessa:users/mjanecke/12269-token-refresh-test
Sep 10, 2026
Merged

missymessa merged 4 commits into
dotnet:mainfrom
missymessa:users/mjanecke/12269-token-refresh-test

Conversation

@missymessa

Copy link
Copy Markdown
Member

Summary

  • exercise the generated Helix API pipeline with an intentionally short-lived Entra token
  • prove the credential is called again after expiration
  • prove the outgoing Authorization header changes to the refreshed token

Validation

  • Build.cmd
  • HelixApiAuthenticationTests: 15 passed

https://dev.azure.com/dnceng/internal/_workitems/edit/12269

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a6ad3a92-2023-4c67-8948-f6d34de1a67c
Copilot AI lite review requested due to automatic review settings September 8, 2026 17:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is isolated to a test addition and the behavior it validates aligns with the stated PR intent, with only a minor maintainability suggestion noted.

Pull request overview

Adds a new Helix SDK test to exercise Entra ID token refresh behavior by using a short-lived TokenCredential and verifying the outgoing Authorization header changes after expiration, helping ensure the generated Helix API client properly reacquires tokens.

Changes:

  • Added a new unit test that sends two requests across a token-expiration boundary and validates the credential is invoked again.
  • Introduced a ShortLivedTokenCredential test helper that issues expiring tokens and tracks acquisition count.
File summaries
File Description
src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/HelixApiAuthenticationTests.cs Adds a token-expiration/refresh test using FakeHttpClient + HttpClientTransport, plus a short-lived credential helper.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 8, 2026 21:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is isolated to test code, aligns with the PR’s stated validation goals, and introduces no behavioral changes to production components.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Keep the expiration wait tied to the short-lived credential lifetime so the test remains valid when that lifetime changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 521e657d-a005-4f60-bcff-25a05ebcc390
Copilot AI review requested due to automatic review settings September 8, 2026 21:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is isolated to tests and the added coverage aligns with the stated validation goals, with only minor maintainability nits noted.

Review details

Suppressed comments (2)

Previously missed (1) — in code that hasn't changed since the last review.

src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/HelixApiAuthenticationTests.cs:190

  • Use HttpHeader.Names.Authorization instead of a string literal to avoid typos and keep the header name consistent with the production auth policy code.

This issue also appears on line 198 of the same file.

src/Microsoft.DotNet.Helix/Sdk.Tests/Microsoft.DotNet.Helix.Sdk.Tests/HelixApiAuthenticationTests.cs:198

  • Use HttpHeader.Names.Authorization instead of a string literal to avoid typos and keep the header name consistent with the production auth policy code.
        Assert.True(secondMessage.Request.Headers.TryGetValue("Authorization", out string secondAuthorization));
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 9, 2026 23:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is isolated to SDK tests and the new assertions directly validate the intended token refresh behavior without impacting production code.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants