Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests#3935
Merged
Conversation
gladjohn
approved these changes
Jul 9, 2026
Contributor
|
BLOCKING MERGE |
gladjohn
reviewed
Jul 9, 2026
iarekk
force-pushed
the
iarekk/ado-net-framework-unit-tests
branch
from
July 10, 2026 13:27
24c9053 to
cad4c43
Compare
bgavrilMS
reviewed
Jul 10, 2026
Restores the 4-stage PR pipeline and extra unit-test coverage from #3933/#3934 (reverted in #3936), with two fixes so the managed-identity E2E test runs on every pool that consumes these tests: - TokenAcquirer MI test now reads the UAMI client id from IDWEB_MI_UAMI_CLIENTID, falling back to the Msal_Integration_tests identity (45344e7d) assigned to the Wilson pool used by the id4s-official pipeline. That pipeline needs no changes. - template-run-managed-identity-e2e-tests.yaml sets IDWEB_MI_UAMI_CLIENTID to the msiv2uami identity (6325cd32) assigned to the MSALMSIV2 pool, so the Id.Web PR pipeline and IdWeb OneBranch official MI job use it. Also re-adds the net472 dotnet test step that VSTest@2 cannot discover on hosted agents. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
iarekk
force-pushed
the
iarekk/ado-net-framework-unit-tests
branch
from
July 10, 2026 15:20
cad4c43 to
21422b3
Compare
gladjohn
approved these changes
Jul 10, 2026
iarekk
added a commit
that referenced
this pull request
Jul 13, 2026
The ADO PR pipeline now runs the full unit test matrix (incl. net462/472) after #3935, making the dotnetcore.yml GitHub Action redundant. Remove it and rely on the ADO check for PR validation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Jul 17, 2026
Merged
Closed
Open
Open
This was referenced Jul 19, 2026
Closed
Open
Merged
github-actions Bot
pushed a commit
to EelcoLos/nx-tinkering
that referenced
this pull request
Jul 21, 2026
Pinned [Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web) at 4.13.2. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Identity.Web's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._ ## 4.13.2 ## What's Changed * Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @iNinja in AzureAD/microsoft-identity-web#3915 * Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @iarekk in AzureAD/microsoft-identity-web#3935 * Post-release 4.13.0: changelog and public API shipped move by @neha-bhargava in AzureAD/microsoft-identity-web#3937 * Remove redundant 'Run unit tests' GitHub Action by @iarekk in AzureAD/microsoft-identity-web#3939 * Apply consistent redirect-URI validation on AccountController.SignIn by @iNinja in AzureAD/microsoft-identity-web#3940 * Fix duplicate logging of MsalUiRequiredException (in-repo copy of #3910) by @iarekk in AzureAD/microsoft-identity-web#3941 * Use MSAL's recent UserFIC API for agentic flows by @Avery-Dunn in AzureAD/microsoft-identity-web#3842 * Restore CustomizeHttpRequestMessage to run after the authorization header by @neha-bhargava in AzureAD/microsoft-identity-web#3943 * Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @dependabot[bot] in AzureAD/microsoft-identity-web#3909 * Revert #3909: keep OWIN Saml/WsFederation on 5.7.0 by @iarekk in AzureAD/microsoft-identity-web#3944 * Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @neha-bhargava in AzureAD/microsoft-identity-web#3947 * Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @neha-bhargava in AzureAD/microsoft-identity-web#3942 * Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @trwalke in AzureAD/microsoft-identity-web#3950 * Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3949 * Improve IDW10109 error handling for credential loading failures by @Avery-Dunn in AzureAD/microsoft-identity-web#3946 * Bump MSAL dependencies to 4.86.1 in central props by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3953 * Bump the notsecurity group with 3 updates by @dependabot[bot] in AzureAD/microsoft-identity-web#3954 **Full Changelog**: AzureAD/microsoft-identity-web@4.13.0...4.13.2 Commits viewable in [compare view](AzureAD/microsoft-identity-web@4.13.0...4.13.2). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Re-lands the pipeline work reverted in #3936 (#3933 + #3934), plus fixes the managed-identity (MI) E2E identity so the test passes on every pipeline that runs it.
1. Restore reverted work
MSALMSIV2pool.2. Pool-aware MI identity (the reason for the revert)
The MI E2E test hardcoded a UAMI client id. Each build pool has a different identity assigned, so a single constant can't work everywhere — the DevEx
id4s-officialpipeline (Wilson pool) failed with "Identity not found" when master carried themsiv2uamiid.Fix: the test reads the id from
IDWEB_MI_UAMI_CLIENTIDand falls back to the Wilson-pool identity:45344e7d(Msal_Integration_tests, Wilson pool) →id4s-officialneeds no changes.6325cd32(msiv2uami,MSALMSIV2pool), set intemplate-run-managed-identity-e2e-tests.yaml→ used by the Id.Web PR MI stage and the IdWeb OneBranch official MI job (both consume that template).3. .NET Framework unit tests
VSTest@2 can't discover the net462/net472 xUnit tests on hosted agents, so add
dotnet test -f net472steps mirroring the GitHub Action. Not running net462