You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
refactor: add drift detection caused by env vars - #291
This pull request introduces robust detection and handling of identity drift when using environment variable authentication tokens in the Fabric CLI. It ensures that all tokens belong to the same identity and tenant, and that session consistency is maintained. The implementation includes new validation logic, improved error messaging, and updates to the logout process. Documentation has also been updated to explain the new behavior.
Identity drift detection and enforcement:
Added _validate_direct_token_identity method in fab_auth.py to verify that all environment variable tokens (FAB_TOKEN, FAB_TOKEN_ONELAKE, FAB_TOKEN_AZURE) belong to the same identity and tenant, and match the current session; otherwise, the CLI logs out and raises an error.
Updated _get_access_token_from_env_vars_if_exist to call the new identity validation method before using tokens.
Improved error handling for missing FAB_TOKEN_AZURE and provided clearer error messages for token-related issues. [1][2]
Session and logout handling:
Introduced a logout_session method in fab_auth.py to centralize logout logic, including clearing caches and context, and updated all relevant code paths to use this method instead of duplicating logout logic. [1][2][3]
Ensured that on identity drift, the CLI logs out and clears session state before raising errors.
Token acquisition flow improvements:
Refactored token acquisition logic in acquire_token to defer environment variable token retrieval until after checking other identity types, and to properly set tenant and principal IDs when acquiring tokens interactively. [1][2][3]
Documentation updates:
Updated docs/essentials/env_vars.md to document the new identity drift detection behavior, including troubleshooting steps and caveats for different authentication modes.
Testing and maintenance:
Updated test helper to clear the new FAB_SPN_FEDERATED_TOKEN environment variable for completeness.
Validate direct access token env vars against the active session identity
(tenant/principal baseline), logging out and failing on mismatch. Persist
the user principal on interactive login so same-tenant principal drift is
caught, and unify the Azure CLI drift path on logout_session().
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Record the direct access token tenant/principal as the baseline on first
use when no prior identity exists, so any later identity change (including
a swap to a different direct token) is detected as drift and logs out,
matching Azure CLI authentication mode. Treats all identity changes as
drift regardless of source.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Guard the Azure scope in _get_access_token_from_env_vars_if_exist with a membership check before decoding so a missing FAB_TOKEN_AZURE raises a FabricCLIError (azure_token_required) instead of a raw KeyError that terminated the REPL.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
_validate_direct_token_identity decoded every present FAB_TOKEN* env var with full validation (including expiry), so an expired non-selected token (e.g. FAB_TOKEN_AZURE) blocked commands using a different, still-valid token. Decode identity claims with verify_exp=False in the drift loop while keeping full expiry validation for the selected token.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…n drift
User sessions restored from disk or refreshed only via silent acquisition could lack a recorded FAB_PRINCIPAL_ID. Environment tokens for a different user in the same tenant then passed the session-identity comparison and were pinned without logout. Record the principal after both silent and interactive acquisition, and recover the cached principal before accepting an environment-token baseline.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
When multiple accounts are cached, recover the principal from the account whose home tenant matches the recorded session tenant instead of the first account.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
A principal-only baseline update also resets navigation to the tenant root. If a tenant is already configured, no principal is recorded, and the current context is a workspace, the first direct-token request discards that workspace even though the tenant has not changed. Subsequent relative paths resolve from root, and context persistence can save the reset. Refresh navigation only when establishing the tenant baseline, not when merely recording its principal.
Preserve actionable Azure CLI error for missing JWT claims
src/fabric_cli/core/fab_auth.py:938
The Azure CLI caller also uses this decoder before _check_azure_cli_identity(). A token missing tid or oid now raises _JWTIdentityClaimsError, bypassing the existing message that tells users to run az login. In _acquire_token_from_azure_cli(), catch _JWTIdentityClaimsError before FabricCLIError and raise FabricCLIError with azure_cli_identity_claims_missing() and ERROR_AUTHENTICATION_FAILED. This preserves the actionable error without weakening direct-token validation.
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces robust detection and handling of identity drift when using environment variable authentication tokens in the Fabric CLI. It ensures that all tokens belong to the same identity and tenant, and that session consistency is maintained. The implementation includes new validation logic, improved error messaging, and updates to the logout process. Documentation has also been updated to explain the new behavior.
Identity drift detection and enforcement:
_validate_direct_token_identitymethod infab_auth.pyto verify that all environment variable tokens (FAB_TOKEN,FAB_TOKEN_ONELAKE,FAB_TOKEN_AZURE) belong to the same identity and tenant, and match the current session; otherwise, the CLI logs out and raises an error._get_access_token_from_env_vars_if_existto call the new identity validation method before using tokens.FAB_TOKEN_AZUREand provided clearer error messages for token-related issues. [1] [2]Session and logout handling:
logout_sessionmethod infab_auth.pyto centralize logout logic, including clearing caches and context, and updated all relevant code paths to use this method instead of duplicating logout logic. [1] [2] [3]Token acquisition flow improvements:
acquire_tokento defer environment variable token retrieval until after checking other identity types, and to properly set tenant and principal IDs when acquiring tokens interactively. [1] [2] [3]Documentation updates:
docs/essentials/env_vars.mdto document the new identity drift detection behavior, including troubleshooting steps and caveats for different authentication modes.Testing and maintenance:
FAB_SPN_FEDERATED_TOKENenvironment variable for completeness.