Skip to content

Replace Windows Live authentication with Microsoft - #2403

Open
niemyjski wants to merge 11 commits into
mainfrom
issue/microsoft-authentication
Open

niemyjski wants to merge 11 commits into
mainfrom
issue/microsoft-authentication

Conversation

@niemyjski

@niemyjski niemyjski commented Jul 27, 2026 •

Copy link
Copy Markdown
Member

Replace Windows Live authentication with Microsoft Identity Platform v2 and Microsoft Graph in the API and both login UIs. Reuse the existing OAuth client and require authenticated linking when Microsoft email matches an existing account: Graph email alone does not establish account ownership. Svelte now displays the API’s recovery instructions through the shared OAuth error path on login, signup, and account linking.

Validation: 811 frontend tests pass, including eight focused OAuth cases and a real fetch-client regression; Svelte validation (zero type errors/warnings), production build, Release backend build (zero warnings/errors), five isolated auth-handler tests, Angular lint/build, and four Angular callback-state tests pass. Local integration also passed: six Microsoft endpoint, 51 adjacent auth endpoint, and four OpenAPI snapshot tests. Latest main is integrated. Current-head hosted API, client, E2E, Docker, version, and CLA checks pass.

Limitations: The local Aspire API, Svelte app, and Angular server were healthy. Local browser login/logout with seeded credentials passed, and an empty Microsoft exchange returned the expected 422. A separate localhost browser check with a mocked 403 verified the recovery message on login and signup. The Angular browser was blocked by its development certificate in the in-app browser; its state guard has focused tests and a production build. Real Microsoft consent/callback verification requires an Entra app registration and remains the product acceptance gate before merging, despite green CI and a clean merge state.

Approved breaking changes: /api/v2/auth/live is replaced by /api/v2/auth/microsoft; the bundled Windows Live client ID is removed. Existing users must sign in through another method or password recovery before linking Microsoft. Login stays hidden until configured.

Implementation and setup
  • New Microsoft accounts receive email verification only after invitation processing, and only while still unverified; subsequent sign-ins preserve verification state. A matching invitation verifies the address without sending an expired link. Legacy identities are removed only after authenticated linking or sign-in through an already linked Microsoft identity.
  • Invitation tokens and return URLs are preserved. Both UIs reject missing or mismatched Microsoft callback state; Angular consumes the nonce after a valid exchange. The secure-random compatibility fallback remains. Failed exchanges show an actionable message without replacing the current session or navigating.
  • OAuth secrets are omitted from generated UI configuration and startup logs. HTTP samples and API snapshots cover the replacement endpoint.
  • Register an Entra application supporting organizational and personal accounts. Add each UI origin as a Web redirect URI, grant delegated Graph User.Read, and create a client secret. Set MicrosoftId=<client-id>;MicrosoftSecret=<secret>; in EX_ConnectionStrings__OAuth.
  • Focused check: npm run test:unit -- --run src/lib/features/auth/microsoft.test.ts. Pre-push checks: npm run validate and npm run build.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 68278822f5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/Exceptionless.Web/Api/Endpoints/AuthEndpoints.cs
Comment thread src/Exceptionless.Web/ClientApp.angular/app/auth/auth.js Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 716f6d7911

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/Exceptionless.Web/Api/Endpoints/AuthEndpoints.cs
@niemyjski niemyjski self-assigned this Jul 30, 2026
@niemyjski
niemyjski force-pushed the issue/microsoft-authentication branch from d3d23d0 to ec96f56 Compare September 11, 2026 03:30
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-22T19:24:38.099964Z b497839 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@niemyjski
niemyjski force-pushed the issue/microsoft-authentication branch from fc0f025 to a4c506a Compare September 16, 2026 00:39

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a4c506a146

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/Exceptionless.Web/Api/Handlers/AuthHandler.cs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bfaa57a3cd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/Exceptionless.Web/Api/Handlers/AuthHandler.cs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3fdd94da54

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/Exceptionless.Web/ClientApp.angular/app/auth/auth.js
@github-actions

Copy link
Copy Markdown

Code Coverage

Package Line Rate Branch Rate Complexity Health
Exceptionless.Web 85% 70% 8135 ✔
Exceptionless.Insulation 37% 35% 286 ❌
Exceptionless.Core 76% 68% 10538 ✔
Exceptionless.AppHost 38% 41% 147 ❌
Summary 79% (26405 / 33423) 68% (12290 / 18075) 19106 ✔

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant