Add configurable Azure Managed token audiences - #305
Bernd Verst (berndverst) wants to merge 2 commits into
Conversation
Normalize resource IDs across options, connection strings, and client/worker helpers; select government defaults per instance and forward supported credential authorities. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Fix the worker transport test to enable insecure credentials for its plaintext loopback connection.
Review effort: Lite
Findings: None
What changed in this PR
Adds configurable and normalized Azure Managed token audiences, including government-region defaults, connection-string support, authority forwarding, and Java client/worker API updates.
Changes:
- Adds audience resolution and normalization.
- Supports
ResourceIdandAuthorityHostconnection-string properties. - Adds audience-aware overloads, documentation, and regression tests.
| File | Reviewed changes |
|---|---|
README.md |
Documents audience and authority configuration. |
CHANGELOG.md |
Records the new functionality. |
azuremanaged/src/test/java/com/microsoft/durabletask/azuremanaged/ResourceIdTest.java |
Tests audience selection and normalization. |
azuremanaged/src/test/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerWorkerOptionsTest.java |
Updates worker audience assertions. |
azuremanaged/src/test/java/com/microsoft/durabletask/azuremanaged/ConnectionStringAuthenticationTest.java |
Tests connection-string authentication and authority handling. |
azuremanaged/src/test/java/com/microsoft/durabletask/azuremanaged/AudienceTransportTest.java |
Tests transport reconnect behavior; the worker plaintext setup requires insecure credentials to be enabled. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/ResourceId.java |
Resolves and normalizes token audiences. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerWorkerOptions.java |
Applies audience configuration to workers. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerWorkerExtensions.java |
Adds audience-aware worker overloads. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerConnectionString.java |
Parses audience and authority settings. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerClientOptions.java |
Applies audience configuration to clients. |
azuremanaged/src/main/java/com/microsoft/durabletask/azuremanaged/DurableTaskSchedulerClientExtensions.java |
Adds audience-aware client overloads. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Token audience selection at a glanceThis PR lets Java clients and workers select the appropriate public, US Government, or custom token audience, while keeping credential authority and the service endpoint independent. Authority detail: Caller-supplied |
Remove the unused authority-test parameter and project its argument source to the two required fields. Explicitly allow insecure credentials for the worker loopback transport test. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Addressed the review-overview suggestion in e35b693: the worker branch of The 31 focused authentication/transport tests passed, and the SpotBugs test report contains no findings. |

Issue describing the changes in this PR
Implement configurable token audiences throughout the Java Azure Managed SDK, following:
Pull request checklist
CHANGELOG.md.Additional information
Audience selection and compatibility
setResourceIdoptions with shared normalization and add optional trailingresourceIdoverloads for client/workercreate*BuilderanduseDurableTaskScheduler. All existing signatures remain available.ResourceIdfor every authentication type. It is a token audience URI, not an ARM resource path.https://durabletask.azure.usonly for case-insensitiveREGION_NAMEprefixesusgovorusdod; otherwise retainhttps://durabletask.io. This intentionally changes the government-region default. No audience is inferred from the endpoint./.defaultsuffix; reject values that become empty. Preserve URI casing and avoid repeated normalization when converting connection strings to options.Authority remains separate
Caller-supplied
TokenCredentialobjects retain their own authority configuration. Connection strings construct credentials, so optionalAuthorityHostis forwarded to the supported Azure Identity 1.18.1 builders: DefaultAzure, Environment, WorkloadIdentity, and InteractiveBrowser. Omission/empty values leave Azure Identity defaults untouched, includingAZURE_AUTHORITY_HOSTwhere supported. Managed identity uses the hosting environment's identity endpoint; developer tools need their own cloud configuration. Neither audience selection norREGION_NAMEmodifies the endpoint or authority.Validation
gradlew.bat :azuremanaged:build :client:test -PskipSigning -x downloadProtoFiles: passed on JDK 21, with the existing Java 8 main / Java 11 test source-target settings.REGION_NAME=UsGoVVirginia; also forced actual-environment scope verification withREGION_NAME=UsDoDCentraland ran the final suite with the region unset.Scope/authority assertions use recording credentials and mocked credential builders; transport tests use a local gRPC server. No live Azure public/government authentication or cloud end-to-end deployment was tested. The existing proto download task was excluded from final validation to avoid unrelated generated-source changes.