microsoftgraph / microsoftgraph/msgraph-beta-sdk-python

Graph API response field format mismatch with SDK object field format

未关闭
#959 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

status:waiting-for-triage type:bug
主要语言
Python
星标
44
派生
16
平均合并
20 小时 39 分钟
30 天内合并 PR
3

描述

Describe the bug

The field in question is for Conditional Access Policies (https://graph.microsoft.com/v1.0/identity/conditionalAccess/policies): conditions.authenticationFlows.transferMethods. When specified in a policy, the graph API returns this field as a comma-separated string, e.g. "transferMethods": "deviceCodeFlow,authenticationTransfer". When parsed by this SDK in this format, ConditionalAccessPolicy.conditions.authentication_flows.transfer_methods get's incorrectly set to an empty array ([]).

The SDK expects the value of this field to be an array, rather than a comma-separated string. The following code demonstrates the incorrect and desired behaviors:

from kiota_serialization_json.json_parse_node import JsonParseNode
from msgraph_beta.generated.models.conditional_access_policy import ConditionalAccessPolicy

json_data = {
  "displayName": "Test Device Code & Authentication Transfers",
  "state": "enabled",
  "conditions": {
    ...
    "authenticationFlows": {
      "transferMethods": "deviceCodeFlow,authenticationTransfer"
    }
  },
  ...
}

msgraph_sdk_obj = JsonParseNode(json_data).get_object_value(ConditionalAccessPolicy())
# msgraph_sdk_obj.conditions.authentication_flows.transfer_methods == []

fixed_json_data = {
  ...
  "conditions": {
    ...
    "authenticationFlows": {
      "transferMethods": ["deviceCodeFlow", "authenticationTransfer"]
    }
  },
  ...
}

fixed_msgraph_sdk_obj = JsonParseNode(fixed_json_data).get_object_value(ConditionalAccessPolicy())
# fixed_msgraph_sdk_obj.conditions.authentication_flows.transfer_methods == [
#   <ConditionalAccessTransferMethods.DeviceCodeFlow: 'deviceCodeFlow'>,
#   <ConditionalAccessTransferMethods.AuthenticationTransfer: 'authenticationTransfer'>
# ]

The following screenshot shows that the API returns it in the comma-separated string format:

Image

So the issue still exists when using the msgraph-sdk API request instead of the JSON parser. e.g.

from msgraph_beta.graph_service_client import GraphServiceClient

GraphServiceClient(...).identity.conditional_access.policies.by_conditional_access_policy_id('conditionalAccessPolicy-id').get()

And in the Entra UI it looks like the following:

Image

I don't know whether this bug should be fixed in this SDK or in the Graph API itself.

Expected behavior
msgraph_sdk_cap_obj: ConditionalAccessPolicy

msgraph_sdk_cap_obj.conditions.authentication_flows.transfer_methods ==
[
  <ConditionalAccessTransferMethods.DeviceCodeFlow: 'deviceCodeFlow'>,
  <ConditionalAccessTransferMethods.AuthenticationTransfer: 'authenticationTransfer'>
]
# not []
How to reproduce

The code above can be used to reproduce.

SDK Version

1.31.0

Latest version known to work for scenario above?

No response

Known Workarounds

No response

Debug output
Click to expand for a full example JSON of a policy
{
  "@odata.context": "https://graph.microsoft.com/v1.0/$metadata#identity/conditionalAccess/policies/$entity",
  "@microsoft.graph.tips": "Use $select to choose only the properties your app needs, as this can lead to performance improvements. For example: GET identity/conditionalAccess/policies('<guid>')?$select=conditions,createdDateTime",
  "templateId": null,
  "displayName": "Test Device Code & Authentication Transfers",
  "state": "enabledForReportingButNotEnforced",
  "sessionControls": null,
  "conditions": {
    "userRiskLevels": [],
    "signInRiskLevels": [],
    "clientAppTypes": ["all"],
    "servicePrincipalRiskLevels": [],
    "insiderRiskLevels": null,
    "platforms": null,
    "locations": null,
    "devices": null,
    "clientApplications": null,
    "applications": {
      "includeApplications": ["None"],
      "excludeApplications": [],
      "includeUserActions": [],
      "includeAuthenticationContextClassReferences": [],
      "applicationFilter": null
    },
    "users": {
      "includeUsers": ["All"],
      "excludeUsers": [],
      "includeGroups": [],
      "excludeGroups": [],
      "includeRoles": [],
      "excludeRoles": [],
      "includeGuestsOrExternalUsers": null,
      "excludeGuestsOrExternalUsers": null
    },
    "authenticationFlows": {
      "transferMethods": "deviceCodeFlow,authenticationTransfer"
    }
  },
  "grantControls": {
    "operator": "OR",
    "builtInControls": ["block"],
    "customAuthenticationFactors": [],
    "termsOfUse": [],
    "authenticationStrength@odata.context": "https://graph.microsoft.com/v1.0/$metadata#identity/conditionalAccess/policies('e7a127d6-b745-47da-814e-f909748cff0d')/grantControls/authenticationStrength/$entity",
    "authenticationStrength": null
  }
}
Configuration

macOS, python 3.12

Other information

No response

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

使用 JsonParseNode、ConditionalAccessPolicy 和 transferMethods 示例值重现不匹配,然后将其与 GraphServiceClient 请求路径进行比较。跟踪 API 返回逗号分隔字符串时 conditions.authenticationFlows.transfer_methods 的解析过程;完成标准是 SDK 将返回的方法公开为预期的 ConditionalAccessTransferMethods 枚举列表。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
api
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。