Azure / Azure/data-api-builder

Support for Azure SQL Always Encrypted

Ouverte
#2,444 2 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
cri known-issue
Langage dominant
C#
Étoiles
1.5k
Forks
370
Merge moyen
3 j 22 h
PR mergées (30 j)
9

Description

Can't find a reference in the documentation so posting the question here:

Does Data API Builder have support Azure SQL Always Encrypted?

I am running a test environment using the following connection string:
Server=tcp:blabla.database.windows.net,1433;Initial Catalog=blabla;
Persist Security Info=False;User ID=blabla;Password=blabla;MultipleActiveResultSets=False;
Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;Column Encryption Setting=enabled;

Get request:
https://{{host}}/api/HRAntwoorden

Returns an error 500, the most descriptive error in the logs of the container:
Azure.DataApiBuilder.Core.Resolvers.IQueryExecutor[0]
0f284a15-472f-4cbf-b7a5-e9b060f08c9b Query execution error due to:
'FOR JSON' clause is unsupported for encrypted columns.
Microsoft.Data.SqlClient.SqlException (0x80131904): 'FOR JSON' clause is unsupported for encrypted columns.

Environment details:
- Azure SQL Database with Always Encrypted enabled connected to Azure Keyvault
- Docker container behind an NGINX proxy:
mcr.microsoft.com/azure-databases/data-api-builder latest
- Table containing an encrypted column:
[AntwoordText] [varchar](max) COLLATE Latin1_General_BIN2 ENCRYPTED WITH (COLUMN_ENCRYPTION_KEY = [KEYNAME], ENCRYPTION_TYPE = Randomized, ALGORITHM = 'AEAD_AES_256_CBC_HMAC_SHA_256') NULL,

The setup is working from SSMS using the following tutorial:
https://medium.com/codex/advanced-database-encryption-with-sql-server-always-encrypted-2962e468d2ab

There seems to be some support for Always Encrypted, but DAB fails because it appends FOR JSON to the end of the SQL Query. Am I missing something? Thx in advance

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par l’entrée de journal IQueryExecutor et reproduisez la requête GET fournie sur une table Azure SQL comportant une colonne Always Encrypted. Examinez la manière dont la requête utilise la clause FOR JSON et comparez le comportement avec la chaîne de connexion et le schéma fournis. Le travail est terminé lorsque le comportement de prise en charge attendu ou la limitation pour ce scénario a été établi et vérifié.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
azure, sql
Domaine
api, backend, databases
Type d'issue
Fonctionnalité
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Calme
Clarté
À clarifier
Accessibilité débutants
28/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.