FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

fix: Added token validation on API to avoid security issues by Prajwal-Microsoft · Pull Request #709 · microsoft/content-processing-solution-accelerator · GitHub

fix: Added token validation on API to avoid security issues - #709

Open
Prajwal-Microsoft wants to merge 7 commits into
devfrom
auth-fix
Open

Prajwal-Microsoft wants to merge 7 commits into
devfrom
auth-fix

Conversation

Copy link
Copy Markdown
Contributor

Purpose

  • This pull request updates GitHub Actions workflows to use specific commit SHAs for all third-party actions, replacing version tags. This enhances security and reliability by ensuring that workflows always use the exact intended version of each action, preventing unexpected changes from upstream updates. Additionally, a cooldown configuration was added for Dependabot updates.

Workflow Security and Reliability Improvements:

  • All uses: statements in workflow files now reference actions by commit SHA instead of tags, including actions/checkout, azure/login, docker/build-push-action, docker/setup-buildx-action, Azure/setup-azd, lycheeverse/lychee-action, github/codeql-action, microsoft/template-validation-action, amannn/action-semantic-pull-request, actions/setup-python, and actions/stale. This ensures deterministic builds and mitigates risks from upstream changes. [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [18] [19] [20] [21] [22] [23] [24] [25] [26] [27] [28] [29] [30] [31]

Dependabot Configuration:

  • Added a cooldown section with a default of 7 days to the .github/dependabot.yml file, controlling the frequency of grouped updates for uv dependencies.

Does this introduce a breaking change?

  • Yes
  • No

Golden Path Validation

  • I have tested the primary workflows (the "golden path") to ensure they function correctly without errors.

Deployment Validation

  • I have validated the deployment process successfully and all services are running as expected with this change.

What to Check

Verify that the following are valid

  • ...

Other Information

github-actions Bot commented Sep 28, 2026 •
edited
Loading

Copy link
Copy Markdown

Coverage Report •
FileStmtsMissCoverMissing
TOTAL122516786% 
report-only-changed-files is enabled. No files were changed during this commit :)

Tests Skipped Failures Errors Time
244 0 💤 0 ❌ 0 🔥 3.550s ⏱️

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Copilot review overview

🟡 Changes recommended

Unresolved authentication, deployment-enforcement, error-handling, and Dependabot configuration issues remain.

Review effort: Lite
Findings: 1 · 8 · 1

Open (10) What changed in this PR

Adds API bearer-token support, Microsoft Entra authentication configuration, workflow action pinning, and Dependabot cooldown settings.

Changes:

  • Added token-aware upload and deployment scripts.
  • Added authentication setup scripts and documentation.
  • Pinned GitHub Actions to commit SHAs.
  • Added Dependabot cooldown configuration.
File Summary
src/​ContentProcessorAPI/​samples/​upload_files.sh Adds optional bearer-token uploads.
src/​ContentProcessorAPI/​samples/​upload_files.ps1 Adds optional bearer-token uploads.
infra/​scripts/​post_deployment.sh Adds authenticated schema registration.
infra/​scripts/​post_deployment.ps1 Adds authenticated schema registration.
infra/​scripts/​configure_app_authentication.sh Configures Entra authentication.
infra/​scripts/​configure_app_authentication.ps1 Configures Entra authentication.
docs/​DeploymentGuide.md Documents authentication deployment steps.
docs/​ConfigureAppAuthentication.md Documents authentication setup.
.github/​workflows/​validate-bicep-params.yml Pins workflow actions.
.github/​workflows/​test.yml Pins workflow actions.
.github/​workflows/​test-automation.yml Pins workflow actions.
.github/​workflows/​test-automation-v2.yml Pins workflow actions.
.github/​workflows/​telemetry-template-check.yml Pins checkout action.
.github/​workflows/​stale-bot.yml Pins stale action.
.github/​workflows/​scheduled-Dependabot-PRs-Auto-Merge.yml Pins checkout action.
.github/​workflows/​pylint.yml Pins workflow actions.
.github/​workflows/​pr-title-checker.yml Pins PR validation action.
.github/​workflows/​job-docker-build.yml Pins Docker and Azure actions.
.github/​workflows/​job-deploy.yml Pins deployment actions.
.github/​workflows/​job-deploy-windows.yml Pins Windows deployment actions.
.github/​workflows/​job-deploy-linux.yml Pins Linux deployment actions.
.github/​workflows/​job-cleanup-deployment.yml Pins Azure login action.
.github/​workflows/​deploy.yml Pins deployment actions.
.github/​workflows/​codeql.yml Pins CodeQL actions.
.github/​workflows/​build-docker-image.yml Pins Docker build actions.
.github/​workflows/​broken-links-checker.yml Pins link-checking actions.
.github/​workflows/​azure-dev.yaml Pins Azure deployment actions.
.github/​workflows/​azd-template-validation.yml Pins validation actions.
.github/​dependabot.yml Adds Dependabot cooldown configuration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +12 to +16
# TIMING: This is a manual post-deployment step. Run it immediately after the
# post-deployment schema-registration script. Until it completes, the API has
# external ingress and is reachable without authentication, so do not defer it.
# It is intentionally not wired into the azd provisioning hooks, to avoid
# deployment-time failures.
Comment thread .github/dependabot.yml
Comment thread infra/scripts/post_deployment.ps1 Outdated
Comment thread infra/scripts/post_deployment.sh Outdated
Comment thread docs/DeploymentGuide.md Outdated
Copilot AI review requested due to automatic review settings September 28, 2026 16:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Comment thread infra/scripts/post_deployment.ps1 Outdated
Comment thread infra/scripts/post_deployment.sh Outdated
Copilot AI lite review requested due to automatic review settings September 30, 2026 04:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Comment thread docs/DeploymentGuide.md
Comment thread docs/DeploymentGuide.md
The committed blob used CRLF, causing 'bash infra/scripts/configure_app_authentication.sh' to fail on Linux/macOS/WSL/CI with \$'\r': command not found before any Azure command runs. Convert to LF so the documented invocation works cross-platform.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings October 1, 2026 06:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Comment thread docs/DeploymentGuide.md

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL