Skip to content

Trace Parser Web: restrict authenticated agent destinations - #562

Open
ahmetziyayildirim wants to merge 1 commit into
fix/traceparser-import-statusfrom
fix/traceparser-agent-destinations
Open

ahmetziyayildirim wants to merge 1 commit into
fix/traceparser-import-statusfrom
fix/traceparser-agent-destinations

Conversation

@ahmetziyayildirim

Copy link
Copy Markdown
Collaborator

Summary

  • Validate and canonicalize supported environment identifiers at startup and when selecting or loading agent profiles.
  • Enforce the configured Power Platform cloud's HTTPS destination policy before acquiring or attaching tokens, including preauthorized and SDK response-derived requests.
  • Disable automatic redirects and fail closed for unsupported custom/local/experimental endpoints.
  • Preserve normal agent switching, add form feedback, document compatibility boundaries and expand offline regression coverage.

Stacked on #561; review against the current base for this focused web-only diff. No database, importer, DAB, credential, consent or infrastructure changes are included. Existing hosted-cloud configuration remains supported; review documented unsupported settings before deployment.

Validate startup and selected-agent identifiers, restrict every authenticated request to the configured Power Platform cloud, and reject redirects before following another destination. Preserve supported agent switching and cover token acquisition boundaries with offline regressions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7f085bfc-844d-4ec3-9391-b696cf6d0e6d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant