Skip to content

chore: Dev to Main - #367

Open
PadhiAjit-Microsoft wants to merge 6 commits into
mainfrom
dev
Open

PadhiAjit-Microsoft wants to merge 6 commits into
mainfrom
dev

Conversation

@PadhiAjit-Microsoft

Copy link
Copy Markdown
Contributor

Purpose

  • This pull request introduces several improvements to authentication handling and proxy configuration for both the chat and scenario applications. The main focus is on supporting same-origin deployments by using a custom X-Backend-Authorization header for bearer tokens, updating backend proxy settings to forward this header, and broadening allowed audiences for Azure Active Directory authentication. Additionally, dependencies have been updated for security and compatibility.

Authentication and Proxy Header Handling

  • Updated frontend code (EnhancedChatPanel.tsx and api.ts) to use X-Backend-Authorization instead of Authorization for bearer tokens when the API is hosted on the same origin, improving security and compatibility with various deployment scenarios. [1] [2] [3] [4]
  • Modified Nginx proxy configuration in startup.sh to forward the Authorization header from X-Backend-Authorization, ensuring backend services receive the correct authentication information. [1] [2] [3]

Azure AD Authentication Configuration

  • Broadened the list of allowed audiences for Azure Active Directory authentication to include both the client ID and api://<client_id>, improving compatibility with different token issuers. [1] [2]

Dependency Updates

  • Upgraded PyJWT[crypto] to version 2.15.0 in both backend requirements.txt files for enhanced security and compatibility. [1] [2]

Proxy Redirect Improvements

  • Added proxy_redirect rules in Nginx configuration to handle redirects correctly when proxying API requests. [1] [2]

These changes collectively enhance authentication robustness, deployment flexibility, and maintain up-to-date dependencies across both applications.

Does this introduce a breaking change?

  • Yes
  • No

How to Test

  • Get the code
git clone [repo-address]
cd [repo-name]
git checkout [branch-name]
npm install
  • Test the code

What to Check

Verify that the following are valid

  • ...

Other Information

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Scenario API origin checks misclassify valid relative, empty, or trailing-slash same-origin URLs.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates authentication and proxy handling for same-origin deployments across both applications.

Changes:

  • Routes bearer tokens through X-Backend-Authorization for same-origin APIs.
  • Expands Microsoft Entra allowed audiences.
  • Updates PyJWT and Nginx redirect handling.
File Description
scenario-app/​frontend/​startup.sh Forwards authentication through scenario proxies.
scenario-app/​frontend/​src/​lib/​api.ts Selects bearer header by API origin.
scenario-app/​frontend/​src/​components/​EnhancedChatPanel.tsx Updates TTS authentication headers.
scenario-app/​backend/​requirements.txt Updates PyJWT.
infra/​scripts/​post-provision/​configure_auth.sh Expands allowed audiences in Bash provisioning.
infra/​scripts/​post-provision/​configure_auth.ps1 Expands allowed audiences in PowerShell provisioning.
chat-app/​frontend/​startup.sh Adds authentication forwarding and redirect handling.
chat-app/​frontend/​src/​lib/​api.ts Selects bearer header by resolved origin.
chat-app/​frontend/​src/​components/​EnhancedChatPanel.tsx Updates TTS authentication headers.
chat-app/​backend/​requirements.txt Updates PyJWT.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +147 to +148
const isSameOriginProxy =
typeof window !== 'undefined' && apiBase === window.location.origin;
Comment on lines +67 to +68
const isSameOriginProxy =
typeof window !== 'undefined' && base === window.location.origin;

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants