Skip to content

Add configurable Azure Managed token audiences - #305

Open
Bernd Verst (berndverst) wants to merge 2 commits into
mainfrom
berndverst-configurable-token-audience
Open

Bernd Verst (berndverst) wants to merge 2 commits into
mainfrom
berndverst-configurable-token-audience

Conversation

@berndverst

Copy link
Copy Markdown
Member

Issue describing the changes in this PR

Implement configurable token audiences throughout the Java Azure Managed SDK, following:

Pull request checklist

  • Documentation changes are included: README, government-cloud usage example, and public API Javadocs.
  • My changes are added to the CHANGELOG.md.
  • I have added the required unit and local transport regression tests. Live cloud authentication was not exercised.

Additional information

Audience selection and compatibility

  • Extend existing setResourceId options with shared normalization and add optional trailing resourceId overloads for client/worker create*Builder and useDurableTaskScheduler. All existing signatures remain available.
  • Support connection-string ResourceId for every authentication type. It is a token audience URI, not an ARM resource path.
  • Explicit nonempty values take precedence. Missing/null/empty values select https://durabletask.azure.us only for case-insensitive REGION_NAME prefixes usgov or usdod; otherwise retain https://durabletask.io. This intentionally changes the government-region default. No audience is inferred from the endpoint.
  • Normalize surrounding whitespace, trailing slashes, and one case-insensitive /.default suffix; reject values that become empty. Preserve URI casing and avoid repeated normalization when converting connection strings to options.
  • Resolve defaults per options/connection-string instance and retain scopes across refreshes, channel recreation, and gRPC reconnects. Do not change token caching/concurrency, lazy acquisition, anonymous authentication, transport selection, or caller-owned channels.
  • This Java module has no separate async or sandbox management/registration authentication surface. No dependency or package versions change.

Authority remains separate

Caller-supplied TokenCredential objects retain their own authority configuration. Connection strings construct credentials, so optional AuthorityHost is forwarded to the supported Azure Identity 1.18.1 builders: DefaultAzure, Environment, WorkloadIdentity, and InteractiveBrowser. Omission/empty values leave Azure Identity defaults untouched, including AZURE_AUTHORITY_HOST where supported. Managed identity uses the hosting environment's identity endpoint; developer tools need their own cloud configuration. Neither audience selection nor REGION_NAME modifies the endpoint or authority.

Validation

  • gradlew.bat :azuremanaged:build :client:test -PskipSigning -x downloadProtoFiles: passed on JDK 21, with the existing Java 8 main / Java 11 test source-target settings.
  • 139 Azure Managed tests and 482 core unit tests passed; no failures or errors.
  • Azure Managed Javadocs and SpotBugs main/test checks passed; both SpotBugs XML reports contain zero findings.
  • Forced all 139 Azure Managed tests with REGION_NAME=UsGoVVirginia; also forced actual-environment scope verification with REGION_NAME=UsDoDCentral and ran the final suite with the region unset.
  • Recording credentials verify actual requested scopes across 28 audience cases × 12 public configuration paths, token refresh/cache reuse, all nine authenticated connection-string types, legacy overloads, invalid inputs, anonymous access, per-instance selection, and connection-string conversion.
  • Loopback gRPC tests verify two distinct transport connections retain the government audience across reconnects, without changing the token cache. Caller-owned channel lifetime remains unchanged.

Scope/authority assertions use recording credentials and mocked credential builders; transport tests use a local gRPC server. No live Azure public/government authentication or cloud end-to-end deployment was tested. The existing proto download task was excluded from final validation to avoid unrelated generated-source changes.

Normalize resource IDs across options, connection strings, and client/worker helpers; select government defaults per instance and forward supported credential authorities.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@berndverst
Bernd Verst (berndverst) requested a review from a team as a code owner September 26, 2026 07:04
Copilot AI lite review requested due to automatic review settings September 26, 2026 07:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Fix the worker transport test to enable insecure credentials for its plaintext loopback connection.

Review effort: Lite
Findings: None

What changed in this PR

Adds configurable and normalized Azure Managed token audiences, including government-region defaults, connection-string support, authority forwarding, and Java client/worker API updates.

Changes:

  • Adds audience resolution and normalization.
  • Supports ResourceId and AuthorityHost connection-string properties.
  • Adds audience-aware overloads, documentation, and regression tests.
File Reviewed changes
README.md Documents audience and authority configuration.
CHANGELOG.md Records the new functionality.
azuremanaged/​src/​test/​java/​com/​microsoft/​durabletask/​azuremanaged/​ResourceIdTest.java Tests audience selection and normalization.
azuremanaged/​src/​test/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerWorkerOptionsTest.java Updates worker audience assertions.
azuremanaged/​src/​test/​java/​com/​microsoft/​durabletask/​azuremanaged/​ConnectionStringAuthenticationTest.java Tests connection-string authentication and authority handling.
azuremanaged/​src/​test/​java/​com/​microsoft/​durabletask/​azuremanaged/​AudienceTransportTest.java Tests transport reconnect behavior; the worker plaintext setup requires insecure credentials to be enabled.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​ResourceId.java Resolves and normalizes token audiences.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerWorkerOptions.java Applies audience configuration to workers.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerWorkerExtensions.java Adds audience-aware worker overloads.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerConnectionString.java Parses audience and authority settings.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerClientOptions.java Applies audience configuration to clients.
azuremanaged/​src/​main/​java/​com/​microsoft/​durabletask/​azuremanaged/​DurableTaskSchedulerClientExtensions.java Adds audience-aware client overloads.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@berndverst

Copy link
Copy Markdown
Member Author

Token audience selection at a glance

This PR lets Java clients and workers select the appropriate public, US Government, or custom token audience, while keeping credential authority and the service endpoint independent.

Diagram of explicit ResourceId precedence, usgov/usdod region defaults, one-time normalization and validation, stable scopes across refresh and reconnect, and independent credential authority and service endpoint configuration.

Authority detail: Caller-supplied TokenCredential instances retain their own authority configuration. Connection strings also construct credentials; optional AuthorityHost is forwarded only for DefaultAzure, Environment, WorkloadIdentity, and InteractiveBrowser. Managed identity and developer-tool cloud configuration remain separate.

Remove the unused authority-test parameter and project its argument source to the two required fields. Explicitly allow insecure credentials for the worker loopback transport test.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@berndverst

Copy link
Copy Markdown
Member Author

Addressed the review-overview suggestion in e35b693: the worker branch of AudienceTransportTest now explicitly sets setAllowInsecureCredentials(true), matching the client setup for the plaintext loopback server. The current worker transport already chooses plaintext from the http:// endpoint; this makes the test intent explicit without changing production transport behavior.

The 31 focused authentication/transport tests passed, and the SpotBugs test report contains no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants