microsoft / microsoft/api-guidelines
Make auth guidelines more explicit
Open
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 23.3k
- Forks
- 2.7k
- PR merge metrics
- No merged PRs in 30d
Description
We should add guidelines that require new services to start with managed identity, explicitly discourage the use of connection strings, etc. We're always telling that to service teams during reviews, but making it explicit would be helpful too.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file or test is named in the issue. Start by finding the existing authentication guidance and the section covering new services; done means the managed-identity requirement and connection-string discouragement are stated explicitly.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation, security
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100