Repository navigation
chore: Dev to Main - #367
Open
PadhiAjit-Microsoft wants to merge 6 commits into
Open
PadhiAjit-Microsoft wants to merge 6 commits into
PadhiAjit-Microsoft wants to merge 6 commits into
Conversation
chore: Resolved the dependabot issues
fix: Update authorization header handling for same-origin proxy in API request
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Scenario API origin checks misclassify valid relative, empty, or trailing-slash same-origin URLs.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Updates authentication and proxy handling for same-origin deployments across both applications.
Changes:
- Routes bearer tokens through
X-Backend-Authorizationfor same-origin APIs. - Expands Microsoft Entra allowed audiences.
- Updates PyJWT and Nginx redirect handling.
| File | Description |
|---|---|
scenario-app/frontend/startup.sh |
Forwards authentication through scenario proxies. |
scenario-app/frontend/src/lib/api.ts |
Selects bearer header by API origin. |
scenario-app/frontend/src/components/EnhancedChatPanel.tsx |
Updates TTS authentication headers. |
scenario-app/backend/requirements.txt |
Updates PyJWT. |
infra/scripts/post-provision/configure_auth.sh |
Expands allowed audiences in Bash provisioning. |
infra/scripts/post-provision/configure_auth.ps1 |
Expands allowed audiences in PowerShell provisioning. |
chat-app/frontend/startup.sh |
Adds authentication forwarding and redirect handling. |
chat-app/frontend/src/lib/api.ts |
Selects bearer header by resolved origin. |
chat-app/frontend/src/components/EnhancedChatPanel.tsx |
Updates TTS authentication headers. |
chat-app/backend/requirements.txt |
Updates PyJWT. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+147
to
+148
| const isSameOriginProxy = | ||
| typeof window !== 'undefined' && apiBase === window.location.origin; |
Comment on lines
+67
to
+68
| const isSameOriginProxy = | ||
| typeof window !== 'undefined' && base === window.location.origin; |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Purpose
X-Backend-Authorizationheader for bearer tokens, updating backend proxy settings to forward this header, and broadening allowed audiences for Azure Active Directory authentication. Additionally, dependencies have been updated for security and compatibility.Authentication and Proxy Header Handling
EnhancedChatPanel.tsxandapi.ts) to useX-Backend-Authorizationinstead ofAuthorizationfor bearer tokens when the API is hosted on the same origin, improving security and compatibility with various deployment scenarios. [1] [2] [3] [4]startup.shto forward theAuthorizationheader fromX-Backend-Authorization, ensuring backend services receive the correct authentication information. [1] [2] [3]Azure AD Authentication Configuration
api://<client_id>, improving compatibility with different token issuers. [1] [2]Dependency Updates
PyJWT[crypto]to version2.15.0in both backendrequirements.txtfiles for enhanced security and compatibility. [1] [2]Proxy Redirect Improvements
proxy_redirectrules in Nginx configuration to handle redirects correctly when proxying API requests. [1] [2]These changes collectively enhance authentication robustness, deployment flexibility, and maintain up-to-date dependencies across both applications.
Does this introduce a breaking change?
How to Test
What to Check
Verify that the following are valid
Other Information