Azure / Azure/data-api-builder
Support for Azure SQL Always Encrypted
- Langage dominant
- C#
- Étoiles
- 1.5k
- Forks
- 370
- Merge moyen
- 3 j 22 h
- PR mergées (30 j)
- 9
Description
Can't find a reference in the documentation so posting the question here:
Does Data API Builder have support Azure SQL Always Encrypted?
I am running a test environment using the following connection string:
Server=tcp:blabla.database.windows.net,1433;Initial Catalog=blabla;
Persist Security Info=False;User ID=blabla;Password=blabla;MultipleActiveResultSets=False;
Encrypt=True;TrustServerCertificate=False;Connection Timeout=30;Column Encryption Setting=enabled;
Get request:
https://{{host}}/api/HRAntwoorden
Returns an error 500, the most descriptive error in the logs of the container:
Azure.DataApiBuilder.Core.Resolvers.IQueryExecutor[0]
0f284a15-472f-4cbf-b7a5-e9b060f08c9b Query execution error due to:
'FOR JSON' clause is unsupported for encrypted columns.
Microsoft.Data.SqlClient.SqlException (0x80131904): 'FOR JSON' clause is unsupported for encrypted columns.
Environment details:
- Azure SQL Database with Always Encrypted enabled connected to Azure Keyvault
- Docker container behind an NGINX proxy:
mcr.microsoft.com/azure-databases/data-api-builder latest
- Table containing an encrypted column:
[AntwoordText] [varchar](max) COLLATE Latin1_General_BIN2 ENCRYPTED WITH (COLUMN_ENCRYPTION_KEY = [KEYNAME], ENCRYPTION_TYPE = Randomized, ALGORITHM = 'AEAD_AES_256_CBC_HMAC_SHA_256') NULL,
The setup is working from SSMS using the following tutorial:
https://medium.com/codex/advanced-database-encryption-with-sql-server-always-encrypted-2962e468d2ab
There seems to be some support for Always Encrypted, but DAB fails because it appends FOR JSON to the end of the SQL Query. Am I missing something? Thx in advance
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par l’entrée de journal IQueryExecutor et reproduisez la requête GET fournie sur une table Azure SQL comportant une colonne Always Encrypted. Examinez la manière dont la requête utilise la clause FOR JSON et comparez le comportement avec la chaîne de connexion et le schéma fournis. Le travail est terminé lorsque le comportement de prise en charge attendu ou la limitation pour ce scénario a été établi et vérifié.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- azure, sql
- Domaine
- api, backend, databases
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Calme
- Clarté
- À clarifier
- Accessibilité débutants
- 28/100