microsoftgraph / microsoftgraph/msgraph-sdk-java
Version 6.2: "com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify." when graphClient.applications().byApplicationId("<my app id>") .patch(app) if try to add a new certificate
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 444
- Forks
- 154
- Avg merge
- 18h 28m
- Merged PRs (30d)
- 4
Description
Expected behavior
Perform request graphClient.applications().byApplicationId("") .patch(app) if try to add a new certificate and there are old configured certificates.
If there are not old configured certificates the call is successful!
The old issue with 6.1 version was java.time.format.DateTimeParseException: Text '2024-02-14T07:37:32' could not be parsed at index 19: https://github.com/microsoftgraph/msgraph-sdk-java/issues/1815
Actual behavior
2024-02-15 10:09:48 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
2024-02-15 10:09:52 INFO c.m.a.m.AcquireTokenSilentSupplier - Returning token from cache
2024-02-15 10:09:52 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify.
at com.microsoft.graph.models.odataerrors.ODataError.createFromDiscriminatorValue(ODataError.java:36)
at com.microsoft.kiota.serialization.JsonParseNode.getObjectValue(JsonParseNode.java:210)
at com.microsoft.kiota.http.OkHttpRequestAdapter.lambda$throwIfFailedResponse$0(OkHttpRequestAdapter.java:672)
at com.microsoft.kiota.ApiExceptionBuilder.(ApiExceptionBuilder.java:26)
at com.microsoft.kiota.http.OkHttpRequestAdapter.throwIfFailedResponse(OkHttpRequestAdapter.java:671)
at com.microsoft.kiota.http.OkHttpRequestAdapter.send(OkHttpRequestAdapter.java:279)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:297)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:281)
Steps to reproduce the behavior
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialList = app.getKeyCredentials(); // There are old KeyCredentials
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
Workaround by skipping odata
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialListOld = app.getKeyCredentials(); // There are old KeyCredentials
// create a new Key Credential List and add old Key Credentials as using getters and setters
List<KeyCredential> keyCredentialList = new ArrayList<>();
for (KeyCredential key : keyCredentialListOld) {
KeyCredential oldKey = new KeyCredential();
oldKey.setDisplayName(key.getDisplayName());
oldKey.setCustomKeyIdentifier(key.getCustomKeyIdentifier());
oldKey.setKeyId(key.getKeyId());
oldKey.setKey(key.getKey());
oldKey.setStartDateTime(key.getStartDateTime());
oldKey.setEndDateTime(key.getEndDateTime());
oldKey.setUsage(key.getUsage());
oldKey.setType(key.getType());
// Skip Odata Type
keyCredentialList.add(oldKey);
}
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at ApplicationItemRequestBuilder.patch and the KeyCredential serialization involved in the supplied reproduction. Reproduce the patch with existing credentials plus a new certificate, then compare it with the workaround that rebuilds credentials to skip OData metadata. Done means the original list can be patched successfully without that workaround.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- api
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100