[Identity] az identity federated-credential create/update: Add support for claims matching expressions#31436
Conversation
…1-PREVIEW API version
️✔️AzureCLI-FullTest
|
|
Hi @Sruuujaaan, |
|
| rule | cmd_name | rule_message | suggest_message |
|---|---|---|---|
| identity federated-credential create | cmd identity federated-credential create added parameter claims_matching_expression_value |
||
| identity federated-credential create | cmd identity federated-credential create added parameter claims_matching_expression_version |
||
| identity federated-credential create | cmd identity federated-credential create update parameter audiences: added property aaz_type=AAZListArg |
||
| identity federated-credential create | cmd identity federated-credential create update parameter audiences: added property type=List<String> |
||
| identity federated-credential create | cmd identity federated-credential create update parameter federated_credential_name: added property aaz_type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter federated_credential_name: added property type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter federated_credential_name: updated property name from federated_credential_name to name |
||
| identity federated-credential create | cmd identity federated-credential create update parameter identity_name: added property aaz_type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter identity_name: added property type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter issuer: added property aaz_type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter issuer: added property type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter resource_group_name: added property aaz_type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter resource_group_name: added property type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter resource_group_name: updated property name from resource_group_name to resource_group |
||
| identity federated-credential create | cmd identity federated-credential create update parameter subject: added property aaz_type=string |
||
| identity federated-credential create | cmd identity federated-credential create update parameter subject: added property type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete removed property confirmation |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter federated_credential_name: added property aaz_type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter federated_credential_name: added property type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter federated_credential_name: updated property name from federated_credential_name to name |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter identity_name: added property aaz_type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter identity_name: added property type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter resource_group_name: added property aaz_type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter resource_group_name: added property type=string |
||
| identity federated-credential delete | cmd identity federated-credential delete update parameter resource_group_name: updated property name from resource_group_name to resource_group |
||
| identity federated-credential list | cmd identity federated-credential list added parameter pagination_limit |
||
| identity federated-credential list | cmd identity federated-credential list added parameter pagination_token |
||
| identity federated-credential list | cmd identity federated-credential list added parameter skiptoken |
||
| identity federated-credential list | cmd identity federated-credential list added parameter top |
||
| identity federated-credential list | cmd identity federated-credential list update parameter identity_name: added property aaz_type=string |
||
| identity federated-credential list | cmd identity federated-credential list update parameter identity_name: added property type=string |
||
| identity federated-credential list | cmd identity federated-credential list update parameter resource_group_name: added property aaz_type=string |
||
| identity federated-credential list | cmd identity federated-credential list update parameter resource_group_name: added property type=string |
||
| identity federated-credential list | cmd identity federated-credential list update parameter resource_group_name: updated property name from resource_group_name to resource_group |
||
| identity federated-credential show | cmd identity federated-credential show update parameter federated_credential_name: added property aaz_type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter federated_credential_name: added property type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter federated_credential_name: updated property name from federated_credential_name to name |
||
| identity federated-credential show | cmd identity federated-credential show update parameter identity_name: added property aaz_type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter identity_name: added property type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter resource_group_name: added property aaz_type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter resource_group_name: added property type=string |
||
| identity federated-credential show | cmd identity federated-credential show update parameter resource_group_name: updated property name from resource_group_name to resource_group |
||
| identity federated-credential update | cmd identity federated-credential update added parameter claims_matching_expression_value |
||
| identity federated-credential update | cmd identity federated-credential update added parameter claims_matching_expression_version |
||
| identity federated-credential update | cmd identity federated-credential update added parameter generic_update_add |
||
| identity federated-credential update | cmd identity federated-credential update added parameter generic_update_force_string |
||
| identity federated-credential update | cmd identity federated-credential update added parameter generic_update_remove |
||
| identity federated-credential update | cmd identity federated-credential update added parameter generic_update_set |
||
| identity federated-credential update | cmd identity federated-credential update update parameter audiences: added property aaz_type=AAZListArg |
||
| identity federated-credential update | cmd identity federated-credential update update parameter audiences: added property type=List<String> |
||
| identity federated-credential update | cmd identity federated-credential update update parameter federated_credential_name: added property aaz_type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter federated_credential_name: added property type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter federated_credential_name: updated property name from federated_credential_name to name |
||
| identity federated-credential update | cmd identity federated-credential update update parameter identity_name: added property aaz_type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter identity_name: added property type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter issuer: added property aaz_type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter issuer: added property type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter resource_group_name: added property aaz_type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter resource_group_name: added property type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter resource_group_name: updated property name from resource_group_name to resource_group |
||
| identity federated-credential update | cmd identity federated-credential update update parameter subject: added property aaz_type=string |
||
| identity federated-credential update | cmd identity federated-credential update update parameter subject: added property type=string |
|
Thank you for your contribution! We will review the pull request and get back to you soon. |
|
The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR. Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions). pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>
|
…eview tags and fixed linting
az identity federated-credential create: Add support for claims matching expressions with 2025-01-31-PREVIEW API version
az identity federated-credential create: Add support for claims matching expressions with 2025-01-31-PREVIEW API versionaz identity federated-credential create: & az identity federated-credential update: Add support for claims matching expressions with 2025-01-31-PREVIEW API version
az identity federated-credential create: & az identity federated-credential update: Add support for claims matching expressions with 2025-01-31-PREVIEW API versionaz identity federated-credential create/update: Add support for claims matching expressions with 2025-01-31-PREVIEW API version
az identity federated-credential create/update: Add support for claims matching expressions with 2025-01-31-PREVIEW API versionaz identity federated-credential create/update: Add support for claims matching expressions
|
/azp run |
|
Azure Pipelines successfully started running 3 pipeline(s). |
|
@Sruuujaaan Please take a look at these CI issues |
az identity federated-credential create/update: Add support for claims matching expressionsaz identity federated-credential create/update: Add support for claims matching expressions
|
/azp run |
|
Commenter does not have sufficient privileges for PR 31436 in repo Azure/azure-cli |
|
/azp run |
|
Azure Pipelines successfully started running 3 pipeline(s). |
|
May I ask what changes have been introduced in this PR? If so, please add the corresponding tests |
|
/azp run |
|
Commenter does not have sufficient privileges for PR 31436 in repo Azure/azure-cli |
|
/azp run |
|
Azure Pipelines successfully started running 3 pipeline(s). |
|
/azp run |
|
Azure Pipelines successfully started running 3 pipeline(s). |
|
@microsoft-github-policy-service agree |
| _default_audiences = ['api://AzureADTokenExchange'] | ||
| audiences = _default_audiences if not audiences else audiences |
There was a problem hiding this comment.
This issue #31598 is due to ignoring the default audience logic when migrating Code Gen. Could you submit a PR to resolve this issue? @Sruuujaaan
There was a problem hiding this comment.
This issue #31598 is due to ignoring the default audience logic when migrating Code Gen. Could you submit a PR to resolve this issue? @Sruuujaaan
PREVIEW API version
Related command
az identity federated-credential *
Description
This PR adds support for claims matching expressions (CME) in federated credentials command group using the 2025-01-31-PREVIEW API version. Linked workItem -> https://msazure.visualstudio.com/One/_workitems/edit/26876104
I've changed the federated credential commands to use the AAZ implementation by:
Testing Guide
TODO add detailed testing SS and commandsaz identity federated-credential create command using Claims Matching Expression is only enabled in below tenants, if you don't have access to these tenants, please reachout to me and I can get you added to them.

We need to test all the commands under

federated-credentialsubgroup to make sureaz identity federated-credential (create, update)commands now support creation using claims matching expression and no regression is observed inaz identity federated-credential (delete, list, show)commandsTest Commands

1] az identity federated-credential create
a] Create using Claims Matching Expression
b] Create using Subject

2] az identity federated-credential update

a] Update using Claims Matching Expression
b] Update using Subject

3] az identity federated-credential show

4] az identity federated-credential list

5] az identity federated-credential delete

History Notes
[Component Name 1] BREAKING CHANGE:
az command a: Make some customer-facing breaking change[Component Name 2]
az command b: Add some customer-facing featureThis checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.