| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Coverage Report •
|
||||||||||||||||||||||||||||||
Sorry, something went wrong.
There was a problem hiding this comment.
This PR refactors Azure authentication helpers to adjust how async credentials are selected and to align bearer token provider setup with the (synchronous) get_async_azure_credential() implementation.
Changes:
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| src/ContentProcessor/src/libs/utils/credential_util.py | Removes await when retrieving the async credential for the async token provider. |
| src/ContentProcessor/src/libs/utils/azure_credential_utils.py | Removes await in async token provider and adds APP_ENV-based fallback credential selection in async credential helper. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
There was a problem hiding this comment.
Copilot reviewed 5 out of 5 changed files in this pull request and generated no new comments.
Suppressed comments (3)src/ContentProcessor/src/libs/utils/azure_credential_utils.py:198
# All async CLI credentials failed. Select the final credential based on the
# environment: production uses Managed Identity, while development uses
# DefaultAzureCredential. Defaults to production when APP_ENV is not set.
app_env = os.getenv("APP_ENV", "prod").lower()
if app_env == "prod":
src/ContentProcessor/src/libs/utils/azure_credential_utils.py:199
app_env = os.getenv("APP_ENV", "prod").lower()
if app_env == "prod":
client_id = os.getenv("AZURE_CLIENT_ID")
infra/main.bicep:564
DeploymentName: deployment().name
SecurityControl: 'Ignore'
}
Sorry, something went wrong.
There was a problem hiding this comment.
Copilot reviewed 5 out of 5 changed files in this pull request and generated no new comments.
Suppressed comments (3)src/ContentProcessor/src/libs/utils/azure_credential_utils.py:198
Also, the trailing comment says DefaultAzureCredential is "only used in development", but this branch triggers for any non-"prod" value (staging/test/etc.), so the comment is inaccurate.
app_env = os.getenv("APP_ENV", "prod").lower()
if app_env == "prod":
client_id = os.getenv("AZURE_CLIENT_ID")
if client_id:
logging.info(
src/tests/ContentProcessor/utils/test_azure_credential_utils_extended.py:113
for key in ["WEBSITE_SITE_NAME", "AZURE_CLIENT_ID", "MSI_ENDPOINT",
"IDENTITY_ENDPOINT", "KUBERNETES_SERVICE_HOST"]:
monkeypatch.delenv(key, raising=False)
monkeypatch.setenv("APP_ENV", "dev")
src/ContentProcessor/src/libs/utils/credential_util.py:50
To avoid drift, consider delegating to libs.utils.azure_credential_utils.get_async_azure_credential() from this function (or otherwise consolidating these two nearly-identical modules).
Returns:
A callable suitable for SDK clients that accept a token provider.
"""
credential = get_async_azure_credential()
return identity_get_async_bearer_token_provider(
credential, "https://cognitiveservices.azure.com/.default"
Sorry, something went wrong.
There was a problem hiding this comment.
Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.
Suppressed comments (1)src/ContentProcessor/src/libs/utils/azure_credential_utils.py:198
app_env = os.getenv("APP_ENV", "prod").lower()
if app_env == "prod":
client_id = os.getenv("AZURE_CLIENT_ID")
if client_id:
logging.info(
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Purpose
This pull request updates the Azure credential selection logic to improve environment-specific authentication and fixes the usage of the get_async_azure_credential function in token provider setup. The most important changes are:
Azure Credential Selection Logic:
Token Provider Setup:
Does this introduce a breaking change?
Golden Path Validation
Deployment Validation
What to Check
Verify that the following are valid
Other Information