This pull request updates both the PowerShell (configure_app_authentication.ps1) and Bash (configure_app_authentication.sh) scripts that configure Azure app authentication. The main focus is to improve reliability and compatibility when registering redirect URIs and allowed client applications, by switching from problematic CLI commands to direct Microsoft Graph API calls using az rest. The update also ensures proper registration for ID token issuance and Easy Auth callback, and handles older Azure CLI extension limitations for Container Apps authentication.
Key improvements and fixes:
App Registration and Redirect URI Handling:
Replaces unreliable az ad app update --set spa=... commands with Microsoft Graph PATCH requests via az rest to set SPA redirect URIs, using temporary files to avoid shell quoting issues. [1][2]
Adds a Microsoft Graph PATCH to enable ID token issuance for implicit grants and registers the Easy Auth callback as a Web redirect URI, ensuring compatibility with Container Apps Easy Auth. [1][2]
Container Apps Authentication Policy:
Replaces the use of az containerapp auth microsoft update --allowed-client-applications (which may be unavailable in older CLI versions) with a process that fetches the current auth config, updates the allowed applications list, and PUTs the config back via az rest. The PowerShell script manipulates the JSON in PowerShell, while the Bash script uses jq for the merge. [1][2]
Does this introduce a breaking change?
Yes
No
Golden Path Validation
I have tested the primary workflows (the "golden path") to ensure they function correctly without errors.
Deployment Validation
I have validated the deployment process successfully and all services are running as expected with this change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
This pull request updates both the PowerShell (configure_app_authentication.ps1) and Bash (configure_app_authentication.sh) scripts that configure Azure app authentication. The main focus is to improve reliability and compatibility when registering redirect URIs and allowed client applications, by switching from problematic CLI commands to direct Microsoft Graph API calls using az rest. The update also ensures proper registration for ID token issuance and Easy Auth callback, and handles older Azure CLI extension limitations for Container Apps authentication.
Key improvements and fixes:
App Registration and Redirect URI Handling:
Container Apps Authentication Policy:
Does this introduce a breaking change?
Golden Path Validation
Deployment Validation
What to Check
Verify that the following are valid
Other Information