Skip to content

Encrypting the Managed CleanRoom token cache file - #10303

Merged
Ethan Yang (necusjz) merged 3 commits into
Azure:mainfrom
DevBaburaj:feature/encryptedcache
Sep 10, 2026
Merged

Ethan Yang (necusjz) merged 3 commits into
Azure:mainfrom
DevBaburaj:feature/encryptedcache

Conversation

@DevBaburaj

@DevBaburaj DevBaburaj commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

🤖 PR Validation — ️✔️ All clear

Breaking Changes
️✔️ None

This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install azdev required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

@azure-client-tools-bot-prd

Copy link
Copy Markdown

Hi DevBaburaj,
Please write the description of changes which can be perceived by customers into HISTORY.rst.
If you want to release a new extension version, please update the version in pyproject.toml (or setup.py, if the extension has not migrated yet) as well.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 2 pipeline(s).

@yonzhan

Copy link
Copy Markdown
Collaborator

Managed CleanRoom

@DevBaburaj
DevBaburaj marked this pull request as ready for review September 9, 2026 11:15
Copilot AI lite review requested due to automatic review settings September 9, 2026 11:15
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new encrypted cache handling has likely runtime/upgrade-breakage issues (missing/failed msal_extensions path and plaintext-cache migration) that should be addressed before release.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the managedcleanroom Azure CLI extension to store its MSAL token cache using encrypted persistence (via msal-extensions), and bumps the extension version/history accordingly.

Changes:

  • Encrypt MSAL token cache load/save using msal_extensions persistence.
  • Add a build_persistence() helper to select encrypted persistence (with optional plaintext fallback).
  • Bump extension version to 1.0.0b8 and document the change in HISTORY.rst.
File summaries
File Description
src/managedcleanroom/azext_managedcleanroom/_msal_auth.py Switches token cache persistence to encrypted storage and introduces a persistence factory helper.
src/managedcleanroom/setup.py Version bump to 1.0.0b8.
src/managedcleanroom/HISTORY.rst Adds release notes for 1.0.0b8 describing token cache encryption.
Review details

Suppressed comments (1)

src/managedcleanroom/azext_managedcleanroom/_msal_auth.py:158

  • build_persistence currently imports msal_extensions outside the try, so fallback_to_plaintext never takes effect for the most likely failure mode (ImportError when msal-extensions isn't installed). In addition, except: is too broad and the warning doesn't capture the underlying exception, making failures hard to diagnose. Consider handling ImportError explicitly, catching Exception instead of bare-except, and logging exc_info for troubleshooting.
    from msal_extensions import build_encrypted_persistence, FilePersistence

    try:
        return build_encrypted_persistence(msal_token_cache_file)
    except:  # pylint: disable=bare-except
        if not fallback_to_plaintext:
            raise
        logger.warning("Encryption unavailable. Opting in to plain text.")
        return FilePersistence(msal_token_cache_file)
  • Files reviewed: 3/3 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/managedcleanroom/azext_managedcleanroom/_msal_auth.py
Comment thread src/managedcleanroom/azext_managedcleanroom/_msal_auth.py Outdated
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 2 pipeline(s).

@necusjz
Ethan Yang (necusjz) merged commit 24cc7ea into Azure:main Sep 10, 2026
24 checks passed
@azclibot

Copy link
Copy Markdown
Collaborator

[Release] Update index.json for extension [ managedcleanroom-1.0.0b8 ] : https://dev.azure.com/msazure/One/_build/results?buildId=180459932&view=results

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants