.NET: [BREAKING] fix: use allow list for configuration keys - #8200
Vincent Biret (baywet) wants to merge 49 commits into
Conversation
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <223894421+github-code-quality[bot]@users.noreply.github.com>
This comment was marked as outdated.
This comment was marked as outdated.
…ect' Co-authored-by: Copilot Autofix powered by AI <223894421+github-code-quality[bot]@users.noreply.github.com>
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
…arer Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
…een net and netfx Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
There was a problem hiding this comment.
🔵 Needs a closer look
Sensitive list and expression-conversion APIs lack the counterparts promised to callers, and the new expression limit lacks regression coverage.
Review details
Suppressed comments (3)
Previously missed (3) — in code that hasn't changed since the last review.
dotnet/src/Microsoft.Agents.AI.Workflows.Declarative/Kit/IWorkflowContextExtensions.cs:170
- The PR says callers of
EvaluateListAsynccan use a corresponding sensitivity-aware API, but this method now throws for sensitive lists and no such overload exists. Callers cannot retrieve the list together with its sensitivity without reproducing internalDataValue.AsListconversion; add anEvaluateListWithSensitivityAsynccounterpart and its public API baselines.
dotnet/src/Microsoft.Agents.AI.Workflows.Declarative/Kit/IWorkflowContextExtensions.cs:281 - This sensitivity-aware conversion covers only the key/scope overload. The expression-based
ConvertValueAsync(targetType, expression, token)now throws on sensitive input throughEvaluateValueAsync, despite the PR directing callers to a corresponding sensitivity-aware API. Add an expression overload that evaluates with sensitivity, converts the value, and returns the metadata.
dotnet/src/Microsoft.Agents.AI.Declarative/PromptAgentFactory.cs:52 - The new default 10,000-character limit and the caller-supplied override are not covered by the added factory tests. Because this is explicitly potentially breaking behavior, add boundary coverage showing that the default rejects an oversized expression and that
maximumExpressionLengthpermits a configured larger expression.
- Files reviewed: 67/67 changed files
- Comments generated: 0 new
- Review effort level: Balanced
There was a problem hiding this comment.
MAF Automated Review — Iteration 2
Result: Findings reported
Scope: 205 net-new commit(s): 5b188dd80e46, 875bda6c45a2, 992d445c2bd3, d2842d459fc5, 9508b4b836b1, 2e5089ef033a, 181ce0d76ba8, 4d42029e169f, 935532d36e89, c1d1611a5936, e0e80921656a, c77957e2c7f5, 4dcba7b6ad03, 63e6c9a625bf, 13b3fee501e7, 5e0536c731a6, f6a012aeea9d, 630a55e4adce, e7571101db95, db6d13d1a349, 25f9ce8f29c8, a1ad47d76bc9, 4415be8b1ef3, 5331810ba472, 018056a524bf, 3ad2b0741e9d, b7deabb8bcf0, dcd1e62715ca, 6f654c3ab529, 501bd5274cf1, 1b4513dfa2f4, 8a546111de85, 4b2f3a33d53e, 2f38485fe0ce, 5be4c7896784, c457acaccf19, d7823b2f3343, b9dbe4f801a8, c37de519ba5c, 9a551d0f2aa1, a6eb2991ddcc, 5a8cef940916, 4d173b24007d, eddccc474c07, 3abfddffc556, e4309e5456c4, e1c849c4ad1a, c744b16af97b, 1ea1ed2ff719, 4e020838d701, c1f33dfca3b4, 595aa8a5f262, 249759787350, 119c795cceef, e0162ab4bea0, c47da07e2294, 14b9f1d7e9a4, a096549746f2, e844e8f5a007, c7694fe77c83, 8a23310d3f76, 93cc03e17441, 393fbf261844, f30187e974cb, ebaa4033cee9, ff15faf50578, 3ccb3aff1e86, 3c670707766a, df03d32151dc, 1cd06c5a2058, 926b4ecacdaa, b0bfd61c1383, db418ad75a1e, 567f1695711f, 21f6fe72c6e4, 3347c43ea886, 003ae93fd476, ae2876262194, 7abe2ff92b2f, 4d5c63a46a9e, 216e7616c884, 31bf0112506b, 4b4d849602d3, 7a82595cbd9e, 0ff9e40cd41d, f25257f78229, 61d6c2c23db5, 43e4b6a4ea90, 8728837f3c49, f39e460f7c14, 490d0dada9b8, 624f0cc3984e, 91b3c8b02248, e07c6bc75dcb, 272fc72571aa, c385c2de6e84, e6db0e729591, 842909cbfdeb, 33c16248c9b9, d2ae2e06a721, 36053be91a68, 81ee134c607c, 80f091513879, ed6386f434f2, a0c668f2a635, d95075f61e38, b45bcc3c5adb, cd9f4cc546df, a757aeb7ba50, 540919324a3a, 6ea65fb301b2, 8236fe0eb1c0, 007593ff0170, bf4d8dc02742, 6129a8c9a1a0, fe8497a92ac8, 52008e3c1ad2, 5d5fa5214765, d341515c0756, e584a9f39c20, 6da8680c7900, 5ce7f36b001d, 301a4ae38657, 0e277164c695, ab05d32e36fd, a876d142932f, 6c3c58a4b2d8, 386b512a6dff, 6ad7ba2f62dd, d99aa4dd8c2c, 7a230433a766, 557a061f16b1, 9f62ddbeee04, 66d74f38724c, 85fdd7fe95b8, 0ad2e4460cef, 070ed9313605, 0fb9e353a58b, 5391d56de579, 0626a59e556d, fca126db3759, 024eb654cf3c, 2678cd3eb4aa, 082b08ad6000, ee8e5f58273f, f17597b09b04, c97528b13084, c030fa3582b1, 6befdf8d0260, b57edf1e257c, 2c5abfa540aa, adacc409f9ff, 46a78b21f569, c5425a5acc22, b83b0e3b3b9d, c356df98a6c1, e24a1f2c408a, e1a901a5c73c, 5135f389ca47, ab8299beb0bd, 234236b5bb5a, 39238b567c88, 999dda7970fe, d90355fb8f5e, f187b6882630, 3b110ade39ea, 52e03cbd01ec, a3fc29dbd63a, 0c07eb6a3de3, 63aacbb5c215, 0275ebfd026e, a27a86f8f227, dcd2c4d1e0b0, fc61f4db90f5, 4a795f5e7744, 6d06022f17bc, 81c47e295d8e, 6817fbdbf70d, 3c8344163d57, d188e8e63348, 8559a7b2980b, 5e0f3a54f924, 200b78765d5a, 3b45c56e8894, bc57ce8857a5, 459fe6eca832, 132addeaddb4, dac7c3218b77, eded8aeb87d4, c2cfbd6031d7, e0ef49cde65e, bcb3ddb0fdd7, adae16a2f034, 5a19862fd0ae, c51a4dfd2ea8, 24253562ef2a, 9db22b889aeb, 5cbd19e4ce2e, 1b6b6f8bd30c, ec87bddcefca, 602d8bba1d40, 4152896ca397, c607b3cbc0fa, c8ff9eeb0423, 6fdf451fcedf
Model: gpt-5.6-sol-fast
Overview
The PR establishes deny-by-default configuration access, propagates sensitivity through parsed Power Fx references and persisted workflow state, and adds concrete egress guards with regression coverage. The incremental async conversion also removes synchronous waits from the live factory path and propagates cancellation. Two public API edits in that conversion nevertheless remove existing CLR entry points, causing avoidable compatibility failures beyond the documented behavioral hardening.
Reviewed the supplied incremental change set across correctness, security/reliability, architecture, and failure behavior.
2 verified findings remained after source verification (2 medium) across 2 files. Details are attached to the affected lines below.
Affected areas: dotnet/src/Microsoft.Agents.AI.Declarative/ChatClient/ChatClientPromptAgentFactory.cs, dotnet/src/Microsoft.Agents.AI.Declarative/Extensions/StringExpressionExtensions.cs
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Signed-off-by: Vincent Biret <vibiret@microsoft.com>
Motivation & Context
This change hardens declarative Power Fx configuration handling so agent and workflow definitions no longer receive broad access to host configuration or ambient process environment values by default. The goal is to align the .NET declarative pipeline with the safe-by-default posture used by Python and to prevent secrets from being accidentally surfaced through workflow messages or persisted state transitions.
Description & Review Guide
Envreferences.AllowProcessEnvironmentVariableFallbackis explicitly enabled.SendActivity,Question,AddConversationMessage,CopyConversationMessages, andInvokeAzureAgentinput messages.Set(...)disabled because it is not integrated with workflow scoped state/checkpoint sensitivity.AllowProcessEnvironmentVariableFallback = truein addition to allowing the variable name.FormatTemplateAsync,EvaluateValueAsync,EvaluateListAsync, or expression-basedConvertValueAsyncmay now receiveDeclarativeActionExceptionfor sensitive results; use the corresponding sensitivity-aware APIs when the value must be handled programmatically.10000unless the host configures a higher limit.Related Issue
No linked issue.
Contribution Checklist
breaking changelabel (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.Signed-off-by: Vincent Biret vibiret@microsoft.com