feat(teams): forward a custom token factory to the Teams SDK - #732
Merged
Merged
Conversation
Contributor
|
Someone is attempting to deploy a commit to the Vercel Team on Vercel. A member of the Team first needs to authorize it. |
TeamsAdapterConfig never forwarded a token field to the underlying @microsoft/teams.apps AppOptions.token, even though the Teams SDK already supports it as a "bring your own credentials" escape hatch (TokenCredentials['token']). The only non-secret auth path exposed was `federated`, which maps to managedIdentityClientId and only resolves via Azure-native managed-identity sources (IMDS, AppService, etc.) - unreachable from platforms like Vercel that can't reach Azure IMDS but still need to mint access tokens through an external mechanism (e.g. a workload-identity federation bridge). Add `token` to TeamsAdapterConfig and forward it in toAppOptions, matching the real TokenCredentials['token'] signature. Also omit clientSecret when a token factory is configured - TokenManager checks clientId+clientSecret before clientId+token, so a stray client-secret env var would otherwise silently override the token factory. Signed-off-by: CamdenA21 <camden@sandstone.ai>
CamdenA21
force-pushed
the
feat/teams-token-passthrough
branch
from
July 21, 2026 23:56
e6169bd to
ee11a86
Compare
… cover env-var path in tests - Note in the token JSDoc and docs that the Teams SDK prefers a generic CLIENT_SECRET env var over the token factory - Replace the unenforced "exactly one auth method" doc claim with the actual precedence (token > federated > appPassword) - Mention token in the certificate-auth error message - Add a config test covering TEAMS_APP_PASSWORD being ignored when a token factory is provided
bensabic
approved these changes
Jul 22, 2026
patrick-chinchill
added a commit
to Chinchill-AI/chat-sdk-python
that referenced
this pull request
Sep 30, 2026
…ereign allowlists (#221) Teams auth extension points: a custom token factory that beats every client-secret source, a webhook_verifier run on the exact raw body before parsing (replacing SDK JWT validation), a callable app_id resolved once in initialize(), and sovereign-cloud service-URL/Graph host allowlists. Upstream commits ported: e06b4b60 (vercel/chat#732, chat@4.35.0), portable parts of 139d337e (vercel/chat#930, chat@4.41.0; Vercel Connect N/A), Teams part of 7609d8f6 (vercel/chat#876, chat@4.40.0). Divergences: App subclass enforces token-factory precedence over CLIENT_SECRET (Python SDK credential order); ValueError instead of TeamsApiError for untrusted URLs; broader wildcard service-URL allowlist kept. Merged with #250: in verifier mode the Bot Framework issuer pre-check is bypassed, as upstream. Consumer impact: all new options are opt-in; an empty webhook body now returns 400 (was parsed as {}). Closes #221
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
TeamsAdapterConfignever forwards atokenfield through to the underlying@microsoft/teams.appsAppOptions.token, even though the Teams SDK already supports it as a genuine "bring your own credentials" escape hatch (TokenCredentials['token']).The only non-secret auth path currently exposed is
federated, which maps tomanagedIdentityClientIdand only resolves via Azure-native managed-identity sources (IMDS, AppService, CloudShell, MachineLearning, ServiceFabric). That's unreachable from serverless/edge runtimes (e.g. Vercel) that can't hit Azure IMDS but still need to mint access tokens through an external mechanism (e.g. a workload-identity federation bridge exchanging a platform-native OIDC token for an Azure AD token).We've been carrying a local patch on
@chat-adapter/teamsdoing exactly this forwarding to unblock a production Teams bot running on Vercel with a user-assigned managed identity. Opening this as a proper PR instead of staying on the patch indefinitely.Changes
TeamsAdapterConfig.token?: (scope: string | string[], tenantId?: string) => string | Promise<string>— matchesTokenCredentials['token']'s real signature.toAppOptionsforwardsconfig.tokenstraight through.clientSecretresolution now also short-circuits whentokenis provided (alongside the existingfederatedcheck) —TokenManager.initializeCredentialschecksclientId && clientSecretbeforeclientId && token, so a strayappPassword/TEAMS_APP_PASSWORDwould otherwise silently win over an explicitly configured token factory.config.test.tsand acreateTeamsAdapterfactory test inindex.test.ts.tokenconfig option and a third "Authentication methods" example inapps/docs/content/adapters/official/teams.mdx.@chat-adapter/teams: minor).Test plan
pnpm --filter @chat-adapter/teams test— 232/232 passing (including 4 new tests)pnpm --filter @chat-adapter/teams typecheck— cleanpnpm konsistent— no violationspnpm check— cleanpnpm knip— no new findings