Azure / Azure/data-api-builder

Support for Azure SQL Always Encrypted

Offen
#2,444 2 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
cri known-issue
Vorherrschende Sprache
C#
Sterne
1.5k
Forks
370
Ø Merge
3 T. 22 Std.
Gemergte PRs (30 T.)
9

Beschreibung

Can't find a reference in the documentation so posting the question here:

Does Data API Builder have support Azure SQL Always Encrypted?

I am running a test environment using the following connection string:
Server=tcp:blabla.database.windows.net,1433;Initial Catalog=blabla;
Persist Security Info=False;User ID=blabla;Password=blabla;MultipleActiveResultSets=False;
Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;Column Encryption Setting=enabled;

Get request:
https://{{host}}/api/HRAntwoorden

Returns an error 500, the most descriptive error in the logs of the container:
Azure.DataApiBuilder.Core.Resolvers.IQueryExecutor[0]
0f284a15-472f-4cbf-b7a5-e9b060f08c9b Query execution error due to:
'FOR JSON' clause is unsupported for encrypted columns.
Microsoft.Data.SqlClient.SqlException (0x80131904): 'FOR JSON' clause is unsupported for encrypted columns.

Environment details:
- Azure SQL Database with Always Encrypted enabled connected to Azure Keyvault
- Docker container behind an NGINX proxy:
mcr.microsoft.com/azure-databases/data-api-builder latest
- Table containing an encrypted column:
[AntwoordText] [varchar](max) COLLATE Latin1_General_BIN2 ENCRYPTED WITH (COLUMN_ENCRYPTION_KEY = [KEYNAME], ENCRYPTION_TYPE = Randomized, ALGORITHM = 'AEAD_AES_256_CBC_HMAC_SHA_256') NULL,

The setup is working from SSMS using the following tutorial:
https://medium.com/codex/advanced-database-encryption-with-sql-server-always-encrypted-2962e468d2ab

There seems to be some support for Always Encrypted, but DAB fails because it appends FOR JSON to the end of the SQL Query. Am I missing something? Thx in advance

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie beim IQueryExecutor-Logeintrag und reproduzieren Sie die bereitgestellte GET-Anforderung für eine Azure-SQL-Tabelle mit einer Always Encrypted-Spalte. Untersuchen Sie, wie die Abfrage die FOR JSON-Klausel verwendet, und vergleichen Sie das Verhalten mit der bereitgestellten Verbindungszeichenfolge und dem Schema. Die Aufgabe ist abgeschlossen, wenn das erwartete Support-Verhalten oder die Einschränkung für dieses Szenario festgestellt und verifiziert wurde.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, sql
Bereich
api, backend, databases
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
28/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.