Azure / Azure/data-api-builder

[Enh]: Support Entra in Local Containers with `SQL_ACCESS_TOKEN`

Open
#3,252 0 comments 0 reactions 0 assignees View on GitHub
2.x
Dominant language
C#
Stars
1.5k
Forks
370
Avg merge
3d 22h
Merged PRs (30d)
9

Description

## What

Allow Data API builder to read a development token from `SQL_ACCESS_TOKEN` and assign it to `SqlConnection.AccessToken`.

> [!IMPORTANT]
> This feature is explicitly scoped to development mode. Never use in production.

## Why

When DAB runs in Docker, normal Entra credential chains often fail. Some SQL endpoints, such as Fabric SQL, require token authentication. This feature provides a development token override so containerized development works without changing production authentication.

## How

- No change to the configuration file.
- No change to the command-line.

### At connection creation:

```
if (development mode &&
not OBO &&
Entra authentication &&
SQL_ACCESS_TOKEN exists)
{
connection.AccessToken = SQL_ACCESS_TOKEN
connection.Pooling = false
}
```

> [!IMPORTANT]
> The env var is re-read on every connection open (never cached).

> [!NOTE]
> In a pooled scenario, you might not see a clean error. So, we disable pooling.

### Logging

When properly invoked:

```
[INFO] Using SQL_ACCESS_TOKEN for connection (development mode)
```

When prerequisites are not met:

```
[WARN] SQL_ACCESS_TOKEN set but requirements are not met — token ignored
```

### Rules

* only when the connection string uses Microsoft Entra authentication: `Active Directory Default`, `Active Directory Managed Identity`, `Active Directory Workload Identity` only.
* only when the `OBO` flow is not being used
* only when `SQL_ACCESS_TOKEN` exists
* only when `runtime.host.mode=development`
* always allow the engine to start
* let the database raise connection errors if the token is invalid
* do not cache the token, re-read it every time a connection is opened

Contributor guide

Open the contributing guide

Research direction

Start at the connection-creation path and trace development-mode, OBO, and Microsoft Entra authentication checks. Verify that SQL_ACCESS_TOKEN is re-read for every connection, pooling is disabled when used, and the specified info or warning is logged. Confirm that unmet prerequisites do not prevent startup and that invalid tokens are left for the database to reject.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, csharp, sql
Domain
authentication, backend-api-design, databases
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.