microsoftgraph / microsoftgraph/msgraph-sdk-java
Version 6.2: "com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify." when graphClient.applications().byApplicationId("<my app id>") .patch(app) if try to add a new certificate
还没有人认领这个 Issue。
- 主要语言
- Java
- 星标
- 444
- 派生
- 154
- 平均合并
- 18 小时 28 分钟
- 30 天内合并 PR
- 4
描述
Expected behavior
Perform request graphClient.applications().byApplicationId("") .patch(app) if try to add a new certificate and there are old configured certificates.
If there are not old configured certificates the call is successful!
The old issue with 6.1 version was java.time.format.DateTimeParseException: Text '2024-02-14T07:37:32' could not be parsed at index 19: https://github.com/microsoftgraph/msgraph-sdk-java/issues/1815
Actual behavior
2024-02-15 10:09:48 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
2024-02-15 10:09:52 INFO c.m.a.m.AcquireTokenSilentSupplier - Returning token from cache
2024-02-15 10:09:52 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify.
at com.microsoft.graph.models.odataerrors.ODataError.createFromDiscriminatorValue(ODataError.java:36)
at com.microsoft.kiota.serialization.JsonParseNode.getObjectValue(JsonParseNode.java:210)
at com.microsoft.kiota.http.OkHttpRequestAdapter.lambda$throwIfFailedResponse$0(OkHttpRequestAdapter.java:672)
at com.microsoft.kiota.ApiExceptionBuilder.(ApiExceptionBuilder.java:26)
at com.microsoft.kiota.http.OkHttpRequestAdapter.throwIfFailedResponse(OkHttpRequestAdapter.java:671)
at com.microsoft.kiota.http.OkHttpRequestAdapter.send(OkHttpRequestAdapter.java:279)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:297)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:281)
Steps to reproduce the behavior
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialList = app.getKeyCredentials(); // There are old KeyCredentials
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
Workaround by skipping odata
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialListOld = app.getKeyCredentials(); // There are old KeyCredentials
// create a new Key Credential List and add old Key Credentials as using getters and setters
List<KeyCredential> keyCredentialList = new ArrayList<>();
for (KeyCredential key : keyCredentialListOld) {
KeyCredential oldKey = new KeyCredential();
oldKey.setDisplayName(key.getDisplayName());
oldKey.setCustomKeyIdentifier(key.getCustomKeyIdentifier());
oldKey.setKeyId(key.getKeyId());
oldKey.setKey(key.getKey());
oldKey.setStartDateTime(key.getStartDateTime());
oldKey.setEndDateTime(key.getEndDateTime());
oldKey.setUsage(key.getUsage());
oldKey.setType(key.getType());
// Skip Odata Type
keyCredentialList.add(oldKey);
}
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 ApplicationItemRequestBuilder.patch 以及所提供复现中涉及的 KeyCredential 序列化开始。使用现有凭据和新证书复现该 patch,然后将其与通过重建凭据来跳过 OData 元数据的变通方案进行比较。在不使用该变通方案的情况下能够成功对原始列表执行 patch,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- java
- 领域
- api
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100