Skip to content

Commit

Permalink
Enable EnableAadSigningKeyIssuerValidation (#6459)
Browse files Browse the repository at this point in the history
  • Loading branch information
schmittjoseph authored and github-actions committed Apr 18, 2024
1 parent 84f4d7e commit 27e4c58
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
using Microsoft.Diagnostics.Monitoring.Tool.FunctionalTests.Runners;
using Microsoft.Diagnostics.Monitoring.WebApi;
using Microsoft.IdentityModel.Tokens;
using Microsoft.IdentityModel.Validators;
using System.IdentityModel.Tokens.Jwt;
using System.Security.Claims;
using System.Threading;
Expand Down Expand Up @@ -90,6 +91,9 @@ public async Task GenerateKey(OutputFormat? format)
ValidateActor = false,
ValidateLifetime = false,
};
// Required for CodeQL.
tokenValidationParams.EnableAadSigningKeyIssuerValidation();

ClaimsPrincipal claimsPrinciple = tokenHandler.ValidateToken(tokenStr, tokenValidationParams, out SecurityToken validatedToken);

Assert.True(claimsPrinciple.HasClaim(ClaimTypes.NameIdentifier, subject));
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.Diagnostics.Monitoring.WebApi;
using Microsoft.IdentityModel.Tokens;
using Microsoft.IdentityModel.Validators;

namespace Microsoft.Diagnostics.Tools.Monitor.Auth.ApiKey
{
Expand Down Expand Up @@ -31,6 +32,10 @@ public static void ConfigureApiKeyTokenValidation(this JwtBearerOptions options,
ValidateActor = false,
ValidateLifetime = false,
};

// Required for CodeQL.
tokenValidationParameters.EnableAadSigningKeyIssuerValidation();

options.TokenValidationParameters = tokenValidationParameters;
}
}
Expand Down

0 comments on commit 27e4c58

Please sign in to comment.