Add configurable Azure Managed token audiences and credential authority - #374
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
All reviewed changes have corresponding coverage and no unresolved blocking issues were identified.
Review effort: Lite
Findings: None
What changed in this PR
Adds configurable Azure Managed token audiences, authority forwarding, government-cloud defaults, normalization, tests, and documentation.
Changes:
- Adds
ResourceIdsupport across options, builders, factories, and connection strings. - Adds optional
AuthorityHostforwarding for supported credentials. - Adds regression coverage and Azure Government guidance.
| File | Summary |
|---|---|
packages/durabletask-js-azuremanaged/test/unit/resource-id.spec.ts |
Tests audience defaults and normalization. |
packages/durabletask-js-azuremanaged/test/unit/resource-id-reconnect.spec.ts |
Tests persistence across recovery and restart. |
packages/durabletask-js-azuremanaged/test/unit/options.spec.ts |
Tests regional audience isolation. |
packages/durabletask-js-azuremanaged/test/unit/credential-factory.spec.ts |
Tests credential authority forwarding. |
packages/durabletask-js-azuremanaged/test/unit/connection-string.spec.ts |
Tests connection-string parsing. |
packages/durabletask-js-azuremanaged/src/worker-builder.ts |
Adds worker audience APIs. |
packages/durabletask-js-azuremanaged/src/options.ts |
Implements audience defaults and normalization. |
packages/durabletask-js-azuremanaged/src/credential-factory.ts |
Forwards authority configuration. |
packages/durabletask-js-azuremanaged/src/connection-string.ts |
Parses ResourceId and AuthorityHost. |
packages/durabletask-js-azuremanaged/src/client-builder.ts |
Adds client audience APIs. |
packages/durabletask-js-azuremanaged/README.md |
Documents public APIs and cloud configuration. |
packages/durabletask-js-azuremanaged/CHANGELOG.md |
Records release notes and migration guidance. |
examples/azure-managed/README.md |
Adds government-cloud configuration guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Token audience and authority logicThe SDK accepts caller-created credentials and constructs credentials from connection strings. Authority stays on caller-created credentials; optional Generated with Microsoft Copilot; checked against this PR's implementation. |
Replace backtracking slash-trimming regexes with a bounded suffix check and index scans. Cover slash-heavy inputs and scope preservation across all authentication paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Summary
What changed?
.resourceId()/.setResourceId()APIs with normalization and per-options defaults; add connection-stringResourceIdand an optional fourthresourceIdargument to the client and worker convenience factories. Existing calls remain valid.https://durabletask.azure.usfor case-insensitiveREGION_NAMEprefixesusgov/usdod; otherwise retainhttps://durabletask.io. Explicit audiences take precedence. Do not infer audiences from service endpoints or other cloud regions./.defaultsuffix, then trim remaining trailing slashes. Preserve URI casing and reject nonempty values that normalize to empty, including whitespace-only connection-string values.AuthorityHostforwarding to supported SDK-created Azure Identity credentials. Omission preserves Azure Identity defaults, including environment authority configuration where applicable. Caller-supplied credentials own their authority; managed identity and developer-tool cloud configuration remain separate.Why is this change needed?
Issues / work items
Project checklist
packages/durabletask-js-azuremanaged/CHANGELOG.mdREGION_NAMEenvironments now default to the government audience. Explicit malformed audiences fail during configuration instead of generating invalid token scopes.ResourceId=https://durabletask.ioor.resourceId("https://durabletask.io")to retain public-cloud authentication in a government-region environment. Configure authority/cloud and the endpoint independently.AI-assisted code disclosure (required)
Was an AI tool used? (select one)
If AI was used:
AI verification (required if AI was used; completed by the agent):
Testing
Automated tests
worker-startup,worker-stream-recovery,worker-response-delivery-grpc).npm run build:coreandnpm run build:azuremanagedpassed, including TypeScript compilation/declaration generation.npm run lint, new-test Prettier checks, andgit diff --checkpassed.Manual validation (only if runtime/behavior changed)
Notes for reviewers
ResourceIdvalues so whitespace-only input is not mistaken for empty input, and successive layers do not strip meaningful repeated/.defaultURI segments.