You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7fe23fd
Browse filesBrowse the repository at this point in the historyBrowse files
Publish still forwards the A365 proxy app credentials on every call (the
CLI can't classify custom vs first-party before the platform does), but
now reconciles after publish: when the response shows no connector was
created, the unused proxy app is deleted so no orphaned credential lingers.
- Post-publish cleanup of the unused proxy app for first-party/Dataverse
servers, gated on the platform returning a connector id / redirect URI.
- Redirect-URI warning now fires only when a connector was actually
created but no URI came back, not on every first-party publish.
- Proxy required-resource-access grant applied only when a connector
exists; Public Clients grant unchanged.
- New --service-tree-id and --secret-lifetime-months options on publish,
threaded to both created Entra apps, mirroring register.
- Orphaned proxy app is deleted if Public Clients creation throws after
the proxy app was created.
- Dry-run output now describes proxy creation, permission/redirect config,
and cleanup.
- CHANGELOG entry references (#499).
Tests: proxy grant on both apps only when a connector exists, unused-proxy
deletion, orphan-cleanup-on-throw, option flow-through, and updated publish
option/dry-run assertions with documented requirement changes.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copy file name to clipboardExpand all lines: CHANGELOG.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ Agents provisioned before this release need `Agent365.Observability.OtelWrite` g
23
23
**Option B — CLI** (`a365 setup admin`) has been removed in this release. Use Option A above, or copy the PowerShell instructions printed in the `a365 setup all` summary output.
24
24
25
25
### Added
26
-
-`develop-mcp publish` now creates the A365 proxy Entra app and sends its credentials to the platform, so custom (non-Dataverse) MCP servers get a Power Platform connector created at publish time.
26
+
-`develop-mcp publish` now creates the A365 proxy Entra app and sends its credentials to the platform, so custom (non-Dataverse) MCP servers get a Power Platform connector created at publish time. The proxy app is removed again when the server turns out not to need a connector, and `--service-tree-id` / `--secret-lifetime-months` options are honored for it (#499).
27
27
- Setup and bootstrap now use Microsoft's first-party Agent 365 CLI application when it is present in your tenant, validating it without changing Microsoft's app registration, and fall back to a tenant-owned "Agent 365 CLI" app when it is not (#489).
28
28
- Log separator written at the start of each CLI invocation now redacts values for secret-bearing options (e.g. `--idp-client-secret`) so they are not written to the log file in plain text.
29
29
- Authentication context (tenant and user) is now logged at the `Information` level whenever the resolved sign-in identity changes, giving operators a clear audit trail in the log file of who the CLI is acting as, without exposing credentials.
description:"Publisher name for the MCP Server. Required for custom (user-created) MCP servers; ignored for 1p Microsoft-owned servers (e.g. msdyn_DataverseMCPServer) which always publish as 'Microsoft'.");
387
387
command.AddOption(publisherNameOption);
388
388
389
+
varserviceTreeIdOption=newOption<string?>("--service-tree-id",description:"ServiceTree ID for Entra app registration (required in Microsoft corporate tenants)");
390
+
command.AddOption(serviceTreeIdOption);
391
+
392
+
varsecretLifetimeMonthsOption=newOption<int?>(["--secret-lifetime-months","-l"],description:"Lifetime in months (1-24) for the generated client secret on the A365 proxy Entra app. Default is 2 years. Set a value smaller than the appManagementPolicies cap in your tenant.");
393
+
command.AddOption(secretLifetimeMonthsOption);
394
+
389
395
varyesOption=newOption<bool>(
390
396
["--yes","-y"],
391
397
description:"Skip the interactive 'Proceed with publish? (y/N)' confirmation.");
_logger.LogInformation("[DRY RUN] Would create Entra apps '{PublicClients}' and '{A365Proxy}' in tenant",$"{input.ServerName}-PublicClients",$"{input.ServerName}-A365Proxy");
92
-
_logger.LogInformation("[DRY RUN] Would call publish endpoint and back-fill PPMI scope on the created app");
102
+
_logger.LogInformation("[DRY RUN] Would call the publish endpoint and forward the A365 proxy app credentials so the platform can create the Power Platform connector for custom (non-Dataverse) servers");
103
+
_logger.LogInformation("[DRY RUN] Would back-fill the PPMI scope on the created apps, add the McpServer API permission and connector redirect URI to the A365 proxy app, and delete the proxy app when the publish response shows no connector was created");
_logger.LogError("Failed to create the Public Clients Entra app after the A365 proxy app was created; deleting the orphaned proxy app '{A365Proxy}'.",a365ProxyApp.AppName);
_logger.LogInformation("Publish returned no A365 proxy connector for '{ServerName}' (first-party / Dataverse server); removing the unused A365 proxy app '{A365Proxy}'.",input.ServerName,apps.A365AppName);
0 commit comments