github / github/copilot-cli

web_search AADSTS7000215 regression — third occurrence in 3 days (was #1638)

Abierto
#1,715 3 comentarios 0 reacciones 0 asignados Ver en GitHub
area:authentication
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

## Regression of #1638 — web_search broken again

This is a recurrence of #1638, which was closed ~7 hours ago as resolved. The same `AADSTS7000215` error is back.

### Error

```
MCP server 'github-mcp-server': Azure AI Agent request failed:
error getting auth token: ClientSecretCredential authentication failed.
POST https://login.microsoftonline.com/398a6654-997b-47e9-b12b-9515b896b4de/oauth2/v2.0/token

RESPONSE 401: 401 Unauthorized
{
"error": "invalid_client",
"error_description": "AADSTS7000215: Invalid client secret provided.
Ensure the secret being sent in the request is the client secret value,
not the client secret ID, for a secret added to app
'59b26b74-50b7-4ea6-b43a-99ee3f991788'."
}
```

### Environment

- **CLI version:** `0.0.419`
- **OS:** Windows_NT
- **Model:** Claude Opus 4.6
- **Timestamp:** `2026-02-27T02:28:46Z`

### Timeline (3 occurrences in 3 days)

| # | Date | Event |
|---|------|-------|
| 1 | 2026-02-24 ~01:17Z | First reported in #1638 |
| 2 | 2026-02-24 ~20:56Z | @tommaso-moro confirmed fix |
| 3 | 2026-02-25 ~04:42Z | Regressed again (reported by @Meir017, @kevindesuyo) |
| 4 | 2026-02-25 ~13:25Z | @tommaso-moro confirmed second fix: *"secret was rotated but never updated in the vault that we federate from"* |
| 5 | 2026-02-26 ~23:51Z | @ssfdre38 verified working, #1638 closed |
| 6 | **2026-02-27 ~02:28Z** | **Broken again (this issue)** |

### Root Cause (per @tommaso-moro in #1638)

> "The `web_search` tool uses a secret that was rotated but never updated in the vault that we federate from to obtain the secret value."

### Impact

- `web_search` tool completely non-functional — all queries fail
- No user-side workaround exists
- `web_fetch` and all other `github-mcp-server` tools (repos, issues, PRs, code search) work fine — only the Azure AI Agent auth path is broken

### Recommendations to prevent recurrence

The manual secret rotation approach has failed 3 times in 3 days. Please consider:

1. **Azure Key Vault auto-rotation** — automate secret lifecycle so rotations propagate to the vault the MCP server federates from
2. **Managed Identity** — if the MCP server runs on Azure infra, eliminate client secrets entirely with `ManagedIdentityCredential`
3. **Health probe** — add a synthetic `web_search` heartbeat that alerts on auth failures before users hit them
4. **Error masking** — the raw error currently leaks internal tenant ID (`398a6654-...`), app registration ID (`59b26b74-...`), and Azure SDK troubleshooting URLs to all end users; these should be logged server-side only

cc @tommaso-moro

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.