feat: add opt-in Service Fabric HTTP options - #967
Open
Nilesh Choudhary (4gust) wants to merge 5 commits into
Open
Nilesh Choudhary (4gust) wants to merge 5 commits into
Nilesh Choudhary (4gust) wants to merge 5 commits into
Conversation
MSAL-owned secure transport accepts unopened custom clients via explicit options. None preserves legacy behavior. HTTPS proxies are authenticated separately. Per-call options are out of scope. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Nilesh Choudhary (4gust)
September 24, 2026 09:28
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
A critical proxy TLS hostname issue and a moderate proxy-key normalization issue remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds opt-in, isolated Service Fabric HTTP configuration with certificate pinning, proxy support, retries, cleanup, public typing, tests, and documentation.
Changes:
- Introduces and exports
ServiceFabricHttpOptions. - Adds owned-session transport with validation and TLS safeguards.
- Expands managed identity coverage and documents compatibility.
Review findings include one critical proxy TLS hostname issue and one moderate proxy-key normalization issue.
| File | Summary |
|---|---|
tests/test_mi.py |
Adds Service Fabric transport, security, cleanup, and compatibility coverage. |
msal/managed_identity.py |
Implements options, validation, transport, proxy, and TLS behavior; contains the noted findings. |
msal/__init__.py |
Exports the new public options type. |
docs/index.rst |
Documents configuration, security, and compatibility. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Add explicit TLS 1.2 fixture minimums, exact DER proxy-certificate comparison, and a distinct-hostname SNI regression while preserving production pinning. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Nilesh Choudhary (4gust)
September 24, 2026 10:38
View session
Co-authored-by: 4gust <107404295+4gust@users.noreply.github.com>
Copilot started reviewing on behalf of
Nilesh Choudhary (4gust)
September 24, 2026 12:25
View session
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Nilesh Choudhary (4gust)
September 24, 2026 14:37
View session
Delegate endpoint certificate pinning to native urllib3 connections while retaining independent HTTPS proxy authentication. Preserve proxy URL normalization and Requests TLS context isolation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Nilesh Choudhary (4gust)
September 25, 2026 11:05
View session
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Add an optional
service_fabric_http_optionsdictionary toManagedIdentityClient, allowing consumers such as Azure Identity to use MSAL's Service Fabric transport without creating, opening, or exposing arequests.Session.msal.ServiceFabricHttpOptionswith five optional fields:headers,proxies,trust_env,timeout, andmax_retries.Consumption
Every dictionary field is optional.
{}uses no custom headers/proxies,trust_env=False,(5, 30)connect/read timeouts, and no retries. Explicit retries cover only connection failures before request transmission.Compatibility and scope
This is an opt-in API, not an automatic repair for unchanged Azure Identity callers. Omitting the parameter or passing
Noneretains the existing Service Fabric requirement for a Requests session. Azure Identity must passservice_fabric_http_options={}wherever it constructs the MSAL client to adopt this path; an MSAL dependency bump alone does not enable it.No existing required arguments, dependency declarations, or package versions change. General per-call HTTP configuration and the alternative callback API are intentionally outside this PR.
Related: #952, #964, and Azure/azure-sdk-for-python#48708.
Security behavior
Secret, including through proxies and on reconnects.SecretorHost; validate selected proxies before credential-bearing parser errors can escape.trust_env=Truefollows Requests proxy/CA selection without bypassing endpoint pinning.Validation
Final Windows/Python 3.12 revision:
Remaining release validation: native additional Python versions, Linux/macOS, an installed historical MSAL baseline, and native older-runtime dependency combinations. The explicit strict-verification test on Python 3.12 is not a claim of native Python 3.13/3.14 execution.