Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Append v2 to endpoint when using a Microsoft authority under OIDC protocol mode #6256

Merged
merged 21 commits into from
Aug 1, 2023
Merged
Show file tree
Hide file tree
Changes from 9 commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
8ed0bd0
First commit
shylasummers Jul 21, 2023
14e15b8
Change files
shylasummers Jul 24, 2023
988c75e
Changed "metdata" to "metadata"
shylasummers Jul 25, 2023
005eaee
Remove changes from 988c75e
shylasummers Jul 25, 2023
f60c28e
Merge branch 'dev' into oidc-known-authorities
shylasummers Jul 25, 2023
dbcae8d
Addressed comments
shylasummers Jul 26, 2023
2e37891
Merge branch 'oidc-known-authorities' of https://github.com/AzureAD/m…
shylasummers Jul 26, 2023
3377bf0
Removed unnecessary export
shylasummers Jul 26, 2023
2fe7d3d
Merge branch 'dev' into oidc-known-authorities
shylasummers Jul 27, 2023
3a349a5
Remove changes in favor of adding tests later
shylasummers Jul 31, 2023
394f37a
Merge branch 'dev' into oidc-known-authorities
shylasummers Jul 31, 2023
ed22784
Changed endpoint check from protocol mode to authority
shylasummers Jul 31, 2023
ad7a5e4
Merge branch 'oidc-known-authorities' of https://github.com/AzureAD/m…
shylasummers Jul 31, 2023
d0e84f8
Removed unnecessary export
shylasummers Jul 31, 2023
48794cb
Delete @azure-msal-browser-7241828b-7956-4b89-a345-913b05a23ac5.json
shylasummers Jul 31, 2023
c831fff
Update @azure-msal-common-7e065849-b972-405d-ab85-674138d67aa2.json
shylasummers Jul 31, 2023
ce1bacd
Merge branch 'dev' into oidc-known-authorities
shylasummers Aug 1, 2023
e0c4be7
Merge branch 'dev' into oidc-known-authorities
shylasummers Aug 1, 2023
42c860d
Improved runtime of isAliasOfKnownMicrosoftAuthority
shylasummers Aug 1, 2023
41c0abf
Merge branch 'oidc-known-authorities' of https://github.com/AzureAD/m…
shylasummers Aug 1, 2023
9fd5307
Removed console.log
shylasummers Aug 1, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"type": "prerelease",
"comment": "Throws error when using OIDC protocol mode with a known Microsoft authority",
"packageName": "@azure/msal-browser",
"email": "[email protected]",
"dependentChangeType": "patch"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"type": "prerelease",
"comment": "Throws error when using OIDC protocol mode with a known Microsoft authority",
"packageName": "@azure/msal-common",
"email": "[email protected]",
"dependentChangeType": "patch"
}
11 changes: 10 additions & 1 deletion lib/msal-browser/src/config/Configuration.ts
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,8 @@ import {
AzureCloudInstance,
AzureCloudOptions,
ApplicationTelemetry,
ClientConfigurationError
ClientConfigurationError,
EndpointMetadata
} from "@azure/msal-common";
import { BrowserUtils } from "../utils/BrowserUtils";
import {
Expand Down Expand Up @@ -340,6 +341,14 @@ export function buildConfiguration(
throw ClientConfigurationError.createCannotAllowNativeBrokerError();
}

// Throw an error if using a known Microsoft authority with OIDC compliance mode
if(userInputAuth?.authority && userInputAuth?.protocolMode === ProtocolMode.OIDC) {
shylasummers marked this conversation as resolved.
Show resolved Hide resolved
const knownMSAuthorities = Object.keys(EndpointMetadata);
if(knownMSAuthorities.includes(userInputAuth.authority)) {
throw ClientConfigurationError.createCannotSetOIDCProtocolModeError();
}
}

const overlayedConfig: BrowserConfiguration = {
auth: {
...DEFAULT_AUTH_OPTIONS,
Expand Down
18 changes: 17 additions & 1 deletion lib/msal-browser/test/config/Configuration.spec.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ import {
DEFAULT_IFRAME_TIMEOUT_MS,
} from "../../src/config/Configuration";
import { TEST_CONFIG, TEST_URIS } from "../utils/StringConstants";
import { LogLevel, Constants, AzureCloudInstance, ProtocolMode, ServerResponseType } from "@azure/msal-common";
import { LogLevel, Constants, AzureCloudInstance, ProtocolMode, ServerResponseType, ClientConfigurationError } from "@azure/msal-common";
import sinon from "sinon";
import { BrowserCacheLocation } from "../../src/utils/BrowserConstants";

Expand Down Expand Up @@ -283,4 +283,20 @@ describe("Configuration.ts Class Unit Tests", () => {
);
expect(console.warn).toBeCalled();
});
it("Setting ProtocolMode to OIDC when using a known Microsoft authority throws an error", async () => {
expect(() =>
buildConfiguration(
{
auth: {
clientId: TEST_CONFIG.MSAL_CLIENT_ID,
authority: TEST_CONFIG.validAuthority,
protocolMode: ProtocolMode.OIDC
},
},
true
)
).toThrowError(
ClientConfigurationError
);
});
});
1 change: 1 addition & 0 deletions lib/msal-common/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ export {
} from "./authority/AuthorityOptions";
export { AuthorityFactory } from "./authority/AuthorityFactory";
export { AuthorityType } from "./authority/AuthorityType";
export { EndpointMetadata } from "./authority/AuthorityMetadata";
export { ProtocolMode } from "./authority/ProtocolMode";
export { OIDCOptions } from "./authority/OIDCOptions";
// Broker
Expand Down
Loading