microsoftgraph / microsoftgraph/msgraph-sdk-java
Version 6.2: "com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify." when graphClient.applications().byApplicationId("<my app id>") .patch(app) if try to add a new certificate
還沒有人認領這個 Issue。
- 主要語言
- Java
- 星號
- 444
- 分支
- 154
- 平均合併
- 18 小時 28 分鐘
- 30 天內合併 PR
- 4
描述
Expected behavior
Perform request graphClient.applications().byApplicationId("") .patch(app) if try to add a new certificate and there are old configured certificates.
If there are not old configured certificates the call is successful!
The old issue with 6.1 version was java.time.format.DateTimeParseException: Text '2024-02-14T07:37:32' could not be parsed at index 19: https://github.com/microsoftgraph/msgraph-sdk-java/issues/1815
Actual behavior
2024-02-15 10:09:48 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
2024-02-15 10:09:52 INFO c.m.a.m.AcquireTokenSilentSupplier - Returning token from cache
2024-02-15 10:09:52 INFO c.a.i.ClientCertificateCredential - Azure Identity => getToken() result for scopes [https://graph.microsoft.com/.default]: SUCCESS
com.microsoft.graph.models.odataerrors.ODataError: The value for the property "usage" in one of your credentials is invalid. Acceptable values are Sign, Verify.
at com.microsoft.graph.models.odataerrors.ODataError.createFromDiscriminatorValue(ODataError.java:36)
at com.microsoft.kiota.serialization.JsonParseNode.getObjectValue(JsonParseNode.java:210)
at com.microsoft.kiota.http.OkHttpRequestAdapter.lambda$throwIfFailedResponse$0(OkHttpRequestAdapter.java:672)
at com.microsoft.kiota.ApiExceptionBuilder.(ApiExceptionBuilder.java:26)
at com.microsoft.kiota.http.OkHttpRequestAdapter.throwIfFailedResponse(OkHttpRequestAdapter.java:671)
at com.microsoft.kiota.http.OkHttpRequestAdapter.send(OkHttpRequestAdapter.java:279)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:297)
at com.microsoft.graph.applications.item.ApplicationItemRequestBuilder.patch(ApplicationItemRequestBuilder.java:281)
Steps to reproduce the behavior
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialList = app.getKeyCredentials(); // There are old KeyCredentials
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
Workaround by skipping odata
TokenCredential tokenCredential = new ClientCertificateCredentialBuilder().tenantId(tenantId)
.clientId(clientId).pfxCertificate(pfxCertificatePath).clientCertificatePassword(pfxPassword)
.build();
String[] scopes = new String[] { "https://graph.microsoft.com/.default" };
GraphServiceClient graphClient = new GraphServiceClient(tokenCredential, scopes);
Application app = graphClient.applications().byApplicationId("<my app id>").get();
List<KeyCredential> keyCredentialListOld = app.getKeyCredentials(); // There are old KeyCredentials
// create a new Key Credential List and add old Key Credentials as using getters and setters
List<KeyCredential> keyCredentialList = new ArrayList<>();
for (KeyCredential key : keyCredentialListOld) {
KeyCredential oldKey = new KeyCredential();
oldKey.setDisplayName(key.getDisplayName());
oldKey.setCustomKeyIdentifier(key.getCustomKeyIdentifier());
oldKey.setKeyId(key.getKeyId());
oldKey.setKey(key.getKey());
oldKey.setStartDateTime(key.getStartDateTime());
oldKey.setEndDateTime(key.getEndDateTime());
oldKey.setUsage(key.getUsage());
oldKey.setType(key.getType());
// Skip Odata Type
keyCredentialList.add(oldKey);
}
X509Certificate certificate = ... //new certificate
KeyCredential newKey = new KeyCredential();
newKey.setType("AsymmetricX509Cert");
newKey.setUsage("Verify");
newKey.setKey(certificate.getEncoded());
keyCredentialList.add(newKey);
app.setKeyCredentials(keyCredentialList);
Application updatedApp = graphClient.applications().byApplicationId("<my app id>")
.patch(app);
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
研究方向
從 ApplicationItemRequestBuilder.patch 以及所提供重現中涉及的 KeyCredential 序列化開始。使用現有認證資訊和新憑證重現該 patch,然後將其與透過重建認證資訊來略過 OData 中繼資料的替代方案進行比較。在不使用該替代方案的情況下能夠成功對原始清單執行 patch,即表示完成。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- java
- 領域
- api
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100