microsoftgraph / microsoftgraph/msgraph-sdk-python

Event loop is closed using RemovePasswordPostRequestBody

オープン
#1,093 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

priority:p2 type:bug
主要言語
Python
スター
630
フォーク
96
平均マージ
15時間 20分
マージ済み PR(30日)
3

説明

Describe the bug

I am trying to delete multiple app secrets in Azure. One key is deleted but it does not advance. I can add secrets just fine. I can delete ONE secret typically. But deleting multiple secrets ends with "Event loop is closed".

Expected behavior

I can add secrets just fine. I can delete ONE secret -- typically. But multiple fail as above.

How to reproduce

This code reproduces the problem:

from msgraph import GraphServiceClient
from azure.identity import ClientSecretCredential
from creds import tenant_id, client_id, client_secret

from msgraph.generated.applications.item.remove_password.remove_password_post_request_body import RemovePasswordPostRequestBody

credential = ClientSecretCredential(
    tenant_id=tenant_id,
    client_id=client_id,
    client_secret=client_secret
)

from uuid import UUID

scopes = ['https://graph.microsoft.com/.default']
graph_client = GraphServiceClient(credential, scopes)

async def show_secrets():
    result = await graph_client.applications.by_application_id(OBJECT_ID).get()
    return result

async def delete_older_secrets():
    try:
        for one_secret in str_not_uuids:
            print(f"== {one_secret}")
            if one_secret == "__CURRENT__":
                print("passing current")
                continue 
            request_body = RemovePasswordPostRequestBody(key_id=UUID(one_secret),)
            result = await graph_client.applications.by_application_id(
                "OBJECT_ID"
            ).remove_password.post(request_body)
    except Exception as e:
        print(e)
    else:
        print('ok')


if __name__ == '__main__':
    import asyncio
    import operator
    all_secrets=asyncio.run(show_secrets())
    str_not_uuids=[str(x.key_id) for x in all_secrets.password_credentials]
    asyncio.run(delete_older_secrets())

SDK Version
pip freeze | grep -iE "graph|azure"
azure-common==1.1.28
azure-core==1.32.0
azure-graphrbac==0.61.2
azure-identity==1.19.0
cryptography==44.0.0
microsoft-kiota-authentication-azure==1.7.1
msgraph-beta-sdk==1.17.0
msgraph-core==1.2.0
msgraph-sdk==1.17.0
msrestazure==0.6.4.post1
Latest version known to work for scenario above?

unknown

Known Workarounds

I can use msal in a non asyncio loop:

import msal
import requests

def remove_application_secrets(tenant_id, client_id, client_secret, secret_ids):

    authority = f"[https://login.microsoftonline.com/{tenant_id}](https://login.microsoftonline.com/%7Btenant_id%7D)"
    app = msal.ConfidentialClientApplication(
    client_id,
    authority=authority,
    client_credential=client_secret

)

result = app.acquire_token_for_client(scopes=["[https://graph.microsoft.com/.default"]](https://graph.microsoft.com/.default%22]))

if "access_token" not in result:
    print(result.get("error"))
    print(result.get("error_description"))
    return

# Remove each secret
headers = {
'Authorization': 'Bearer ' + result['access_token'],
'Content-Type': 'application/json'
}


for secret_id in secret_ids:

try:

   url = f"[https://graph.microsoft.com/v1.0/applications/{object_id}/removePassword] 
   (https://graph.microsoft.com/v1.0/applications/%7Bobject_id%7D/removePassword)"

    payload = {"keyId": secret_id}
    response = requests.post(url, headers=headers, json=payload)
    if response.status_code == 204:
    print(f"Successfully removed secret with ID: {secret_id}")

else:

    print(f"Failed to remove secret {secret_id}. Status code: {response.status_code}")
    print(response.text)

except Exception as e:
    print(f"Error removing secret {secret_id}: {str(e)}")
    remove_application_secrets(

client_id=client_id,
tenant_id=tenant_id,
client_secret=client_secret,
secret_ids=['blah1', 'blah2']
)
Debug output

Event loop is closed

Configuration
cat /etc/os-release 
PRETTY_NAME="Ubuntu 24.04.1 LTS"
NAME="Ubuntu"
VERSION_ID="24.04"
VERSION="24.04.1 LTS (Noble Numbat)"
VERSION_CODENAME=noble
ID=ubuntu
ID_LIKE=debian
HOME_URL="https://www.ubuntu.com/"
SUPPORT_URL="https://help.ubuntu.com/"
BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/"
PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy"
UBUNTU_CODENAME=noble
LOGO=ubuntu-logo
Other information

No response

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

まず、レポートにある GraphServiceClient、ClientSecretCredential、remove_password.post を使って asyncio.run のフローを実行し、次にクライアントと credential が繰り返し呼び出された際にイベントループに紐付いたリソースをどのように管理するかを調査します。複数のアプリケーションシークレットの削除が "Event loop is closed" なしで完了し、その動作が回帰テストでカバーされていれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure, python
領域
api, authentication
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。