Skip to content

fix(apps): support AAD v1 issuers in Entra token validation#422

Merged
heyitsaamir merged 1 commit into
mainfrom
fix/aad-v1-issuer-token-validation
May 6, 2026
Merged

fix(apps): support AAD v1 issuers in Entra token validation#422
heyitsaamir merged 1 commit into
mainfrom
fix/aad-v1-issuer-token-validation

Conversation

@heyitsaamir

Copy link
Copy Markdown
Collaborator

Summary

Mirrors microsoft/teams.ts#556 in this codebase.

Some valid Microsoft Entra access tokens are issued with the Azure AD v1 issuer format (https://sts.windows.net/{tenantId}/) instead of the v2 issuer (https://login.microsoftonline.com/{tenantId}/v2.0). Today TokenValidator.for_entra only accepts the v2 form, causing valid v1 tokens to be rejected.

Changes

  • packages/apps/src/microsoft_teams/apps/auth/token_validator.py: when a tenant_id is provided, TokenValidator.for_entra now adds both the v2 ({login_endpoint}/{tenant_id}/v2.0) and v1 (https://sts.windows.net/{tenant_id}/) issuers to valid_issuers.
  • packages/apps/tests/test_token_validator.py:
    • Updated test_for_entra_initialization to assert both issuers are present.
    • Added test_validate_entra_token_v1_sts_issuer covering acceptance of a v1 sts.windows.net issuer through the full validation pipeline.

Note: Unlike the TS PR, this change does not introduce multi-tenant allowedTenantIds semantics, since the Python TokenValidator doesn't currently expose multi-tenant configuration. The fix is kept narrowly scoped to issuer format acceptance.

Reference: https://learn.microsoft.com/en-us/entra/identity-platform/access-tokens

Test plan

  • uv run pytest packages/apps/tests/test_token_validator.py -q — all 27 tests pass, including the new v1 issuer test.

…tion

Some valid Microsoft Entra access tokens are issued with the Azure AD v1
issuer format (https://sts.windows.net/{tenantId}/) instead of the v2
issuer (https://login.microsoftonline.com/{tenantId}/v2.0).

TokenValidator.for_entra now accepts both issuer formats when a
tenant_id is provided.

Mirrors microsoft/teams.ts#556.
Copilot AI review requested due to automatic review settings May 6, 2026 18:15
@heyitsaamir
heyitsaamir merged commit 662c119 into main May 6, 2026
11 checks passed
@heyitsaamir
heyitsaamir deleted the fix/aad-v1-issuer-token-validation branch May 6, 2026 18:38
corinagum added a commit that referenced this pull request May 27, 2026
## Summary

Brings `origin/main` into `release` for the **2.0.12** release. **No
carve-outs this time** — Quoted Replies (PR #321) is included.

`version.json`: `2.0.11` → `2.0.12`.

Aligns with teams.ts/teams.net cadence.

## What's in this release (delta from 2.0.11)

**Features**
- Quoted Replies & new quotes features (#321) — previously held back
- SuggestedActionSubmitActivity for `suggestedAction/submit` invoke
(#434)
- Default targeted replies for targeted inbound messages (#439)
- Reactions API marked GA (#427) — already shipped in 2.0.11 actually,
ignore if duplicate
- Prompt Preview support (#397)
- Sample: opt targeted-messages into slash commands (#430)
- Sample: a2a-in-teams (#401)
- Sample: proactive message update (#405)
- Allow custom HTTP client via `AppOptions` (#416)

**Security & fixes**
- Lock JsonWebToken trust-boundary contract (#432)
- Bump starlette 1.0.0 -> 1.1.0 for PYSEC-2026-161 / BadHost (#441)
- warn when bot starts without credentials (#435)
- fix(apps): support AAD v1 issuers in Entra token validation (#422)
- fix(apps): log inbound activities at info, warn on missing
Authorization (#425)
- fix(http-stream): wait for in-flight flush before sending final close
(#419)
- Mark reactions API as GA and fix sample remove flow (#427)
- Revert serviceUrl allowlist (ADO 5310460) (#415)
- Route `app.get_app_graph` + `ctx.*_graph` to sovereign endpoints via
`cloud.graph_scope` (#402)

**Deprecations / package changes**
- Remove ai, openai, mcpplugin, a2a, and devtools packages (#413)
- Restore and deprecate devtools package (#410)
- Deprecate ai, openai, mcpplugin, a2a packages (#406)
- Add agent framework example, remove chatprompt/mcp client samples
(#386)

**Dependency bumps**
- urllib3 2.6.3 → 2.7.0 (#426)
- python-multipart 0.0.26 → 0.0.27 (#424)
- microsoft-kiota-http 1.9.7 → 1.9.9 (#423)
- idna 3.11 → 3.15 (#431)
- starlette 1.0.0 → 1.1.0 (#441, security)
- /examples/tab/Web: qs, postcss, uuid, follow-redirects bumps

## Quoted Replies inclusion notes

- Teams client rendering is in-sync with the wire format as of
2026-05-06.
- APX QR rollout completed: Public 2026-04-10, GCCH/DoD/Gallatin
2026-04-14.
- Builder methods (`prepend_quote()`, `add_quote()`), `ctx.quote()`, and
the quote-aware `ctx.reply()` behavior are all present in this release.
- `examples/quoting` is included.

## Conflict resolution

The 2.0.11 release branch had the QR-removed shape for four files; took
`main`'s (QR-included) version for all of them:
- `examples/targeted-messages/src/main.py`
- `packages/api/src/microsoft_teams/api/activities/message/message.py`
- `packages/apps/src/microsoft_teams/apps/routing/activity_context.py`
- `packages/apps/tests/test_activity_context.py`

`version.json` conflict resolved to `2.0.12`.

## Test plan

- [x] `uv sync` clean
- [x] `poe check` (ruff format + lint) — clean
- [x] `poe test` — 609 passed
- [x] `pyright` — 0 errors, 0 warnings
- [ ] Pipeline build + test stages green on `release` after merge
- [ ] Publish pipeline run with **Public** → ESRP approval → PyPI
- [ ] `pip install microsoft-teams-apps==2.0.12` smoke install

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Aamir Jawaid <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
Co-authored-by: Shanmathi Mayuram Krithivasan <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants