microsoftgraph / microsoftgraph/msgraph-sdk-powershell

Token authentication breaks when using certain commands

Aperta
#2,437 4 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@insomniacc ci sta già lavorando.

Dal 4/6/2024.

Needs: Attention :wave:
Lingua principale
C#
Stelle
898
Fork
230
Merge medio
2g 5h
PR unite (30g)
31

Descrizione

Describe the bug
Running the following command breaks my authentication I'd previously configured with Connect-MgGraph:

Invoke-MGGraphRequest -uri "https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/`$count"

Subsequent commands using Get-Mg commands just fail with the following output for example:
Get-MgIdentityGovernanceAccessReviewDefinition_List: The server responded with a Request Error, Status: NotFound

The only way to proceed is to re-run Connect-MgGraph.
It seems that the authentication is being broken and the commands do not gracefully handle the issue / complain about authentication in an explicit way.

Expected behavior

  1. if authentication breaks, subsequent commands should throw an exception/error related to authentication.
  2. Issuing a get method with Invoke-MgGraphRequest should not break authentication set by Connect-MgGraph

Debug Output

PS > Invoke-MGGraphRequest -uri "https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/`$count" -debug
VERBOSE: GET https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/$count with 0-byte payload

Confirm
Continue with this operation?
[Y] Yes  [A] Yes to All  [H] Halt Command  [S] Suspend  [?] Help (default is "Y"): Y
DEBUG: GET /v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/$count HTTP/1.1
HTTP: api.accessreviews.identitygovernance.azure.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Microsoft Windows 10.0.19045; en-GB) PowerShell/7.2.16 Invoke-MgGraphRequest


VERBOSE: received 0-byte response of content type 

Confirm
Continue with this operation?
[Y] Yes  [A] Yes to All  [H] Halt Command  [S] Suspend  [?] Help (default is "Y"): Y
DEBUG: GET https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/$count
HTTP/1.1 404 Not Found
X-Powered-By: ASP.NET
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Tue, 14 Nov 2023 15:54:35 GMT
Content-Length: 0


Invoke-MgGraphRequest: GET https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions/<AccessReviewID>/instances/<InstanceID>/contactedReviewers/$count
HTTP/1.1 404 Not Found
X-Powered-By: ASP.NET
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Tue, 14 Nov 2023 15:54:35 GMT
Content-Length: 0


PS > $AccessReviews = Get-MgIdentityGovernanceAccessReviewDefinition -All -debug
DEBUG: [CmdletBeginProcessing]: - Get-MgIdentityGovernanceAccessReviewDefinition begin processing with parameterSet 'List'.
DEBUG: [Authentication]: - AuthType: 'AppOnly', TokenCredentialType: 'ClientSecret', ContextScope: 'Process', AppName: '90 Day Access Review'.
DEBUG: [Authentication]: - Scopes: [AccessReview.ReadWrite.Membership, Group.Read.All, AccessReview.ReadWrite.All, Group.Create, User.Read.All, Mail.Read, AccessReview.Read.All, Mail.Send, GroupMember.ReadWrite.All].
DEBUG: ============================ HTTP REQUEST ============================

HTTP Method:
GET

Absolute Uri:
https://api.accessreviews.identitygovernance.azure.com/v1.0/identityGovernance/accessReviews/definitions

Headers:
FeatureFlag                   : 00000043
Cache-Control                 : no-store, no-cache
User-Agent                    : Mozilla/5.0,(Windows NT 10.0; Microsoft Windows 10.0.19045; en-GB),PowerShell/7.2.16
Accept-Encoding               : gzip
SdkVersion                    : graph-powershell/2.9.0
client-request-id             : f24c7b00-e972-4e87-80f9-0c0235b570f1

Body:



DEBUG: ============================ HTTP RESPONSE ============================

Status Code:
NotFound

Headers:
X-Powered-By                  : ASP.NET
X-Content-Type-Options        : nosniff
Strict-Transport-Security     : max-age=31536000; includeSubDomains; preload
Date                          : Tue, 14 Nov 2023 15:56:30 GMT

Body:



Get-MgIdentityGovernanceAccessReviewDefinition_List: The server responded with a Request Error, Status: NotFound
DEBUG: [CmdletEndProcessing]: - Get-MgIdentityGovernanceAccessReviewDefinition end processing.

Module Version

> get-module Microsoft.Graph* | select Name,Version

Name                                            Version
----                                            -------
Microsoft.Graph                                 2.9.0
Microsoft.Graph.Applications                    2.9.0
Microsoft.Graph.Authentication                  2.9.0
Microsoft.Graph.Bookings                        2.9.0
Microsoft.Graph.Calendar                        2.9.0
Microsoft.Graph.ChangeNotifications             2.9.0
Microsoft.Graph.CloudCommunications             2.9.0
Microsoft.Graph.Compliance                      2.9.0
Microsoft.Graph.CrossDeviceExperiences          2.9.0
Microsoft.Graph.DeviceManagement                2.9.0
Microsoft.Graph.DeviceManagement.Actions        2.9.0
Microsoft.Graph.DeviceManagement.Administration 2.9.0
Microsoft.Graph.DeviceManagement.Enrollment     2.9.0
Microsoft.Graph.DeviceManagement.Functions      2.9.0
Microsoft.Graph.Devices.CloudPrint              2.9.0
Microsoft.Graph.Devices.CorporateManagement     2.9.0
Microsoft.Graph.Devices.ServiceAnnouncement     2.9.0
Microsoft.Graph.DirectoryObjects                2.9.0
Microsoft.Graph.Education                       2.9.0
Microsoft.Graph.Files                           2.9.0
Microsoft.Graph.Groups                          2.9.0
Microsoft.Graph.Identity.DirectoryManagement    2.9.0
Microsoft.Graph.Identity.Governance             2.9.0
Microsoft.Graph.Identity.Partner                2.9.0
Microsoft.Graph.Identity.SignIns                2.9.0
Microsoft.Graph.Mail                            2.9.0
Microsoft.Graph.Notes                           2.9.0
Microsoft.Graph.People                          2.9.0
Microsoft.Graph.PersonalContacts                2.9.0
Microsoft.Graph.Planner                         2.9.0
Microsoft.Graph.Reports                         2.9.0
Microsoft.Graph.SchemaExtensions                2.9.0
Microsoft.Graph.Search                          2.9.0
Microsoft.Graph.Security                        2.9.0
Microsoft.Graph.Sites                           2.9.0
Microsoft.Graph.Teams                           2.9.0
Microsoft.Graph.Users                           2.9.0
Microsoft.Graph.Users.Actions                   2.9.0
Microsoft.Graph.Users.Functions                 2.9.0

Environment Data
PSVersion 7.2.16

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.