|
| 1 | +# -------------------------------------------------------------------------------------------- |
| 2 | +# Copyright (c) Microsoft Corporation. All rights reserved. |
| 3 | +# Licensed under the MIT License. See License.txt in the project root for license information. |
| 4 | +# -------------------------------------------------------------------------------------------- |
| 5 | + |
| 6 | +import json |
| 7 | +import os |
| 8 | +import unittest |
| 9 | +from unittest.mock import patch |
| 10 | + |
| 11 | +from azure.cli.core.auth.agentic_session import ( |
| 12 | + COPILOT_AGENT_SESSION_ID, |
| 13 | + build_agentic_session_params, |
| 14 | + merge_access_token_claims, |
| 15 | +) |
| 16 | + |
| 17 | + |
| 18 | +class TestBuildAgenticSessionParams(unittest.TestCase): |
| 19 | + |
| 20 | + def test_returns_none_when_env_not_set(self): |
| 21 | + with patch.dict(os.environ, {}, clear=True): |
| 22 | + session_id, claims = build_agentic_session_params() |
| 23 | + self.assertIsNone(session_id) |
| 24 | + self.assertIsNone(claims) |
| 25 | + |
| 26 | + def test_returns_none_when_env_is_empty_string(self): |
| 27 | + with patch.dict(os.environ, {COPILOT_AGENT_SESSION_ID: ""}): |
| 28 | + session_id, claims = build_agentic_session_params() |
| 29 | + self.assertIsNone(session_id) |
| 30 | + self.assertIsNone(claims) |
| 31 | + |
| 32 | + def test_returns_session_id_and_claims(self): |
| 33 | + with patch.dict(os.environ, {COPILOT_AGENT_SESSION_ID: "sess-456"}): |
| 34 | + session_id, claims = build_agentic_session_params() |
| 35 | + self.assertEqual(session_id, "sess-456") |
| 36 | + parsed = json.loads(claims) |
| 37 | + self.assertEqual(parsed["access_token"]["xms_cli_sid"]["values"], ["sess-456"]) |
| 38 | + |
| 39 | +def _agentic_claims(session_id="s1"): |
| 40 | + return json.dumps({"access_token": {"xms_cli_sid": {"values": [session_id]}}}) |
| 41 | + |
| 42 | + |
| 43 | +class TestMergeAccessTokenClaims(unittest.TestCase): |
| 44 | + |
| 45 | + # --- Validation --- |
| 46 | + |
| 47 | + def test_raises_when_new_claims_is_none(self): |
| 48 | + with self.assertRaises(ValueError): |
| 49 | + merge_access_token_claims(None, None) |
| 50 | + |
| 51 | + def test_raises_when_new_access_token_is_null(self): |
| 52 | + new = json.dumps({"access_token": None}) |
| 53 | + with self.assertRaises(ValueError): |
| 54 | + merge_access_token_claims(None, new) |
| 55 | + |
| 56 | + # --- Merging --- |
| 57 | + |
| 58 | + def test_merges_into_none(self): |
| 59 | + result = merge_access_token_claims(None, _agentic_claims("s1")) |
| 60 | + claims = json.loads(result) |
| 61 | + self.assertEqual(len(claims), 1) |
| 62 | + self.assertEqual(len(claims["access_token"]), 1) |
| 63 | + self.assertEqual(claims["access_token"]["xms_cli_sid"], {"values": ["s1"]}) |
| 64 | + |
| 65 | + def test_merges_into_existing(self): |
| 66 | + existing = json.dumps({"access_token": {"nbf": {"essential": True, "value": "999"}}}) |
| 67 | + result = merge_access_token_claims(existing, _agentic_claims("s1")) |
| 68 | + merged = json.loads(result) |
| 69 | + self.assertEqual(len(merged), 1) |
| 70 | + self.assertEqual(len(merged["access_token"]), 2) |
| 71 | + self.assertEqual(merged["access_token"]["nbf"], {"essential": True, "value": "999"}) |
| 72 | + self.assertEqual(merged["access_token"]["xms_cli_sid"], {"values": ["s1"]}) |
| 73 | + |
| 74 | + def test_preserves_non_access_token_keys(self): |
| 75 | + existing = json.dumps({ |
| 76 | + "access_token": {"nbf": {"essential": True}}, |
| 77 | + "id_token": {"auth_time": {"essential": True}} |
| 78 | + }) |
| 79 | + result = merge_access_token_claims(existing, _agentic_claims()) |
| 80 | + merged = json.loads(result) |
| 81 | + self.assertEqual(len(merged), 2) |
| 82 | + self.assertEqual(len(merged["access_token"]), 2) |
| 83 | + self.assertEqual(merged["id_token"], {"auth_time": {"essential": True}}) |
| 84 | + self.assertEqual(merged["access_token"]["nbf"], {"essential": True}) |
| 85 | + self.assertEqual(merged["access_token"]["xms_cli_sid"], {"values": ["s1"]}) |
| 86 | + |
| 87 | + def test_new_claims_overwrites_existing_key(self): |
| 88 | + existing = json.dumps({"access_token": {"xms_cli_sid": {"values": ["old"]}}}) |
| 89 | + result = merge_access_token_claims(existing, _agentic_claims("new")) |
| 90 | + merged = json.loads(result) |
| 91 | + self.assertEqual(len(merged), 1) |
| 92 | + self.assertEqual(len(merged["access_token"]), 1) |
| 93 | + self.assertEqual(merged["access_token"]["xms_cli_sid"], {"values": ["new"]}) |
| 94 | + |
| 95 | + def test_creates_access_token_when_missing_in_existing(self): |
| 96 | + existing = json.dumps({"id_token": {"auth_time": {"essential": True}}}) |
| 97 | + result = merge_access_token_claims(existing, _agentic_claims()) |
| 98 | + merged = json.loads(result) |
| 99 | + self.assertEqual(len(merged), 2) |
| 100 | + self.assertEqual(len(merged["access_token"]), 1) |
| 101 | + self.assertEqual(merged["id_token"], {"auth_time": {"essential": True}}) |
| 102 | + self.assertEqual(merged["access_token"]["xms_cli_sid"], {"values": ["s1"]}) |
| 103 | + |
| 104 | + def test_handles_null_access_token_in_existing(self): |
| 105 | + existing = json.dumps({"access_token": None}) |
| 106 | + result = merge_access_token_claims(existing, _agentic_claims()) |
| 107 | + merged = json.loads(result) |
| 108 | + self.assertEqual(len(merged), 1) |
| 109 | + self.assertEqual(len(merged["access_token"]), 1) |
| 110 | + self.assertEqual(merged["access_token"]["xms_cli_sid"], {"values": ["s1"]}) |
| 111 | + |
| 112 | + |
| 113 | +class TestUserCredentialAgenticSession(unittest.TestCase): |
| 114 | + """Verify that UserCredential.acquire_token merges agentic claims and passes |
| 115 | + client_session param when COPILOT_AGENT_SESSION_ID is set.""" |
| 116 | + |
| 117 | + def _build_user_credential(self, enable_broker=False): |
| 118 | + """Build a UserCredential with mocked MSAL app.""" |
| 119 | + from unittest.mock import MagicMock, PropertyMock |
| 120 | + from azure.cli.core.auth.msal_credentials import UserCredential |
| 121 | + |
| 122 | + cred = object.__new__(UserCredential) |
| 123 | + |
| 124 | + cred._msal_app = MagicMock() |
| 125 | + cred._msal_app.client_id = "test-client-id" |
| 126 | + cred._msal_app._enable_broker = enable_broker |
| 127 | + type(cred._msal_app).authority = PropertyMock(return_value=MagicMock( |
| 128 | + instance="login.microsoftonline.com", |
| 129 | + tenant="test-tenant", |
| 130 | + is_adfs=False, |
| 131 | + )) |
| 132 | + cred._account = { |
| 133 | + "home_account_id": "uid.utid", |
| 134 | + "username": "user@test.com", |
| 135 | + } |
| 136 | + return cred |
| 137 | + |
| 138 | + @patch.dict(os.environ, {COPILOT_AGENT_SESSION_ID: "agent-sess-1"}) |
| 139 | + def test_non_broker_passes_data_only(self): |
| 140 | + """Non-broker path: client_session in data for ext_cache_key, no claims_challenge.""" |
| 141 | + cred = self._build_user_credential(enable_broker=False) |
| 142 | + cred._msal_app.acquire_token_silent_with_error.return_value = { |
| 143 | + "access_token": "agent-tagged-token", |
| 144 | + "token_type": "Bearer", |
| 145 | + "expires_in": 3600, |
| 146 | + } |
| 147 | + |
| 148 | + result = cred.acquire_token(["https://management.azure.com/.default"]) |
| 149 | + |
| 150 | + self.assertEqual(result["access_token"], "agent-tagged-token") |
| 151 | + |
| 152 | + call_kwargs = cred._msal_app.acquire_token_silent_with_error.call_args |
| 153 | + self.assertIsNone(call_kwargs.kwargs.get("claims_challenge")) |
| 154 | + self.assertEqual(call_kwargs.kwargs["data"], {"client_session": "agent-sess-1"}) |
| 155 | + self.assertEqual(call_kwargs.kwargs["params"], {"client_session": "agent-sess-1"}) |
| 156 | + |
| 157 | + @patch.dict(os.environ, {COPILOT_AGENT_SESSION_ID: "agent-sess-1"}) |
| 158 | + def test_broker_passes_claims_and_data(self): |
| 159 | + """Broker path: claims_challenge with xms_cli_sid AND client_session in data.""" |
| 160 | + cred = self._build_user_credential(enable_broker=True) |
| 161 | + cred._msal_app.acquire_token_silent_with_error.return_value = { |
| 162 | + "access_token": "agent-tagged-token", |
| 163 | + "token_type": "Bearer", |
| 164 | + "expires_in": 3600, |
| 165 | + } |
| 166 | + |
| 167 | + result = cred.acquire_token(["https://management.azure.com/.default"]) |
| 168 | + |
| 169 | + self.assertEqual(result["access_token"], "agent-tagged-token") |
| 170 | + |
| 171 | + call_kwargs = cred._msal_app.acquire_token_silent_with_error.call_args |
| 172 | + claims = json.loads(call_kwargs.kwargs["claims_challenge"]) |
| 173 | + self.assertEqual(claims["access_token"]["xms_cli_sid"]["values"], ["agent-sess-1"]) |
| 174 | + self.assertEqual(call_kwargs.kwargs["data"], {"client_session": "agent-sess-1"}) |
| 175 | + self.assertEqual(call_kwargs.kwargs["params"], {"client_session": "agent-sess-1"}) |
| 176 | + |
| 177 | + @patch.dict(os.environ, {}, clear=True) |
| 178 | + def test_no_agentic_params_without_env(self): |
| 179 | + """When COPILOT_AGENT_SESSION_ID is not set, no agentic params are added.""" |
| 180 | + cred = self._build_user_credential(enable_broker=False) |
| 181 | + cred._msal_app.acquire_token_silent_with_error.return_value = { |
| 182 | + "access_token": "normal-token", |
| 183 | + "token_type": "Bearer", |
| 184 | + "expires_in": 3600, |
| 185 | + } |
| 186 | + |
| 187 | + result = cred.acquire_token(["https://management.azure.com/.default"]) |
| 188 | + |
| 189 | + self.assertEqual(result["access_token"], "normal-token") |
| 190 | + |
| 191 | + call_kwargs = cred._msal_app.acquire_token_silent_with_error.call_args |
| 192 | + self.assertIsNone(call_kwargs.kwargs.get("claims_challenge")) |
| 193 | + self.assertNotIn("params", call_kwargs.kwargs) |
| 194 | + |
| 195 | + @patch.dict(os.environ, {COPILOT_AGENT_SESSION_ID: "agent-sess-2"}) |
| 196 | + def test_broker_merges_with_existing_claims(self): |
| 197 | + """Broker path: agentic claims are merged with existing claims_challenge.""" |
| 198 | + cred = self._build_user_credential(enable_broker=True) |
| 199 | + cred._msal_app.acquire_token_silent_with_error.return_value = { |
| 200 | + "access_token": "token", |
| 201 | + "token_type": "Bearer", |
| 202 | + "expires_in": 3600, |
| 203 | + } |
| 204 | + |
| 205 | + existing_claims = json.dumps({"access_token": {"nbf": {"essential": True, "value": "999"}}}) |
| 206 | + cred.acquire_token(["scope"], claims_challenge=existing_claims) |
| 207 | + |
| 208 | + call_kwargs = cred._msal_app.acquire_token_silent_with_error.call_args |
| 209 | + claims = json.loads(call_kwargs.kwargs["claims_challenge"]) |
| 210 | + self.assertEqual(claims["access_token"]["nbf"], {"essential": True, "value": "999"}) |
| 211 | + self.assertEqual(claims["access_token"]["xms_cli_sid"]["values"], ["agent-sess-2"]) |
| 212 | + |
| 213 | + |
| 214 | +if __name__ == '__main__': |
| 215 | + unittest.main() |
0 commit comments