Skip to content

fix: Update authorization header handling for same-origin proxy in API request - #366

Merged
Prajwal-Microsoft merged 2 commits into
devfrom
psl-wafauth
Oct 7, 2026
Merged

Prajwal-Microsoft merged 2 commits into
devfrom
psl-wafauth

Conversation

@KanchanN-Microsoft

Copy link
Copy Markdown
Contributor

Purpose

This pull request introduces changes to improve authentication handling and reverse proxy configuration for both the chat-app and scenario-app frontends. The main goals are to support secure token forwarding when using a same-origin proxy, ensure proper audience validation for Azure AD tokens, and correctly propagate authorization headers through Nginx. Below are the most important changes:

Authentication Header Handling:

  • Updated both chat-app and scenario-app frontend code (EnhancedChatPanel.tsx, api.ts) to dynamically set the authentication header to X-Backend-Authorization when requests are proxied through the same origin, otherwise using the standard Authorization header. This ensures tokens are securely forwarded through the frontend proxy. [1] [2] [3] [4]

Reverse Proxy Configuration:

  • Modified Nginx startup scripts (startup.sh) for both apps to forward the Authorization header from X-Backend-Authorization to the backend, ensuring authentication tokens are properly relayed to backend services. [1] [2] [3]
  • Added proxy_redirect rules in Nginx to correctly rewrite backend redirects to the frontend domain, improving compatibility with backend responses. [1] [2]

Azure AD Authentication Audience Validation:

  • Updated Azure AD configuration scripts (configure_auth.ps1, configure_auth.sh) to include both the client ID and api://<client_id> as allowed audiences, ensuring tokens issued for either identifier are accepted by the backend. [1] [2]

These changes collectively enhance authentication security and reliability when deploying behind a reverse proxy and using Azure AD for authentication.

Does this introduce a breaking change?

  • Yes
  • No

How to Test

  • Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
  • Test the code

What to Check

Verify that the following are valid

  • ...

Other Information

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Relative /chat-api URLs are misclassified, causing authenticated widget and TTS requests to lose their bearer tokens.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Improves token forwarding through same-origin Nginx proxies and expands Azure AD audience validation.

Changes:

  • Selects proxy-specific authorization headers.
  • Forwards credentials and rewrites backend redirects in Nginx.
  • Accepts client ID and api:// token audiences.
File Description
chat-app/​frontend/​startup.sh Configures proxy authentication and redirects.
chat-app/​frontend/​src/​lib/​api.ts Selects request authorization header.
chat-app/​frontend/​src/​components/​EnhancedChatPanel.tsx Selects TTS authorization header.
scenario-app/​frontend/​startup.sh Configures scenario and chat proxies.
scenario-app/​frontend/​src/​lib/​api.ts Selects request authorization header.
scenario-app/​frontend/​src/​components/​EnhancedChatPanel.tsx Selects TTS authorization header.
infra/​scripts/​post-provision/​configure_auth.sh Expands allowed audiences in Bash provisioning.
infra/​scripts/​post-provision/​configure_auth.ps1 Expands allowed audiences in PowerShell provisioning.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread chat-app/frontend/src/components/EnhancedChatPanel.tsx
Comment thread chat-app/frontend/src/lib/api.ts
Copilot AI balanced review requested due to automatic review settings October 6, 2026 14:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Scenario requests misclassify equivalent same-origin URLs, potentially dropping authentication at the proxy.

Review effort: Balanced
Findings: None

Resolved since last review (2)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Detect equivalent same-origin bases before selecting authorization header

scenario-app/​frontend/​src/​components/​EnhancedChatPanel.tsx:148

This equality check also misses equivalent same-origin bases with a trailing slash or relative path. The TTS request then uses Authorization, which the proxy overwrites from the missing custom header, causing an authenticated request to arrive without credentials. Use URL-origin comparison consistently with the chat frontend.

Medium severity Use URL-origin comparison for same-origin authorization handling

scenario-app/​frontend/​src/​lib/​api.ts:68

Same-origin detection by string equality misclassifies equivalent bases such as https://host/ or /. In that case this sends Authorization, but the same-origin Nginx proxy replaces upstream Authorization from the absent X-Backend-Authorization header, so authenticated API calls reach the backend without a token. Resolve the base URL and compare origins as the chat frontend does.

@Prajwal-Microsoft
Prajwal-Microsoft merged commit 5e031bb into dev Oct 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants