-
Notifications
You must be signed in to change notification settings - Fork 207
Switching to Lab App for OBO testing #163
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
rayluo
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is good to see the test passes again. Thanks! As we discussed earlier, we would also want to understand the why. I leave a couple questions inline.
| os.getenv("LAB_OBO_CLIENT_SECRET"), "OBO app secret not found") | ||
| def test_acquire_token_obo(self): | ||
| # Some hardcoded, pre-defined settings | ||
| obo_client_id = "23c64cd8-21e4-41dd-9756-ab9e2c23f58c" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Per our earlier discussion, have we investigated why our previous test setup suddenly failed in the first place? Most of those previous settings were obtained from MSAL .Net's OBO test case, which seems to be still working?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
MSAL .Nets OBO test case is an app set up in Travis's personal tenant. He had preconfigured the apps to work with the lab account we use. There was a change in the cloud accounts returned by lab api recently. The account we end up using to run these tests was not consented on Travis's app. While we can grant this consent for the first app using interactive auth, we will have to rely on Travis to add consent to this account for the second confidential client app in this test case.
I confirmed with Travis that .NET test cases are failing too because of this change.
So, the best thing to do is move to using the accounts provided by lab so that they take care of this consent internally when they add new accounts that are returned by their API.
Aside, I am talking to Gladwin about how these API changes can be communicated so that we dont break the tests.
tests/test_e2e.py
Outdated
| @unittest.skipUnless( | ||
| os.getenv("OBO_CLIENT_SECRET"), | ||
| "Need OBO_CLIENT_SECRET from https://buildautomation.vault.azure.net/secrets/IdentityDivisionDotNetOBOServiceSecret") | ||
| os.getenv("LAB_OBO_CLIENT_SECRET"), "OBO app secret not found") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It is OK to switch to a different set of test setup, but then I would suggest to follow the previous implementation, to leave some hint for future troubleshooting (in case the test case would somehow fail again), and/or for auditing (i.e. to understand where those test settings come from).
rayluo
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for all the investigation!
No description provided.