Files
David Garcia 2e774b2b6d Login: forward operator-chosen resource through Az PS + az cli
The three login scripts were minting only management.azure.com tokens
regardless of the resource the operator picked in the UI dropdown -
because none of the pieces in the chain honoured it. az cli was
similarly minting only its default ARM token. Now the operator's
choice reaches both toolchains end-to-end.

- server/scripts/login_azure.ps1
- server/scripts/login_azure_devicecode.ps1
- server/scripts/login_spn_azure.ps1
    Add `[string]$Resource='https://management.azure.com'` param.
    Get-AzAccessToken now runs with -ResourceUrl $Resource (previously
    hardcoded to https://management.azure.com or omitted, defaulting
    to ARM). After `az login` succeeds, also fetch a resource-specific
    token via `az account get-access-token --resource $Resource -o tsv`
    so both Az PS and az cli have a warm token cache for the chosen
    audience. Device-code hint now includes the exact
    `az account get-access-token --resource ...` line.

- server/Server.cpp
    handleNewSession reads req["resource"] (default ARM) into a local
    and forwards it as `-Resource '<escaped>'` on all three script
    invocations (credential/ROPC, device-code, SPN). Uses the existing
    escapePsString helper. Also stops the SPN meta-write from
    hardcoding management.azure.com - it now records the actual
    resource. The old ternary that always returned ARM is replaced
    with a plain default.

- client/CredentialLoginWindow.{h,cpp}
    Dropdown expanded from 2 to 6 entries (Management, Graph, Key
    Vault, Storage, SQL, Other...). currentData() carries the resource
    URL - same pattern SPNLoginWindow already uses. "Other..." reveals
    a free-text QLineEdit; a trailing "/.default" scope suffix is
    stripped so -ResourceUrl gets a v1 audience URL.

- client/DeviceCodeLoginWindow.cpp
    startFullServerSession() no longer hardcodes ARM - reads
    resourceInput->text() (the free-text field that was already in the
    UI but silently ignored). Empty falls back to ARM; a trailing
    /.default is stripped for the same reason.

- client/SPNLoginWindow.cpp
    authenticateViaPowerShell() no longer hardcodes ARM in req -
    forwards pendingResource (already populated from the dropdown at
    handler entry). Empty falls back to ARM defensively.
2026-07-29 06:50:37 -06:00
..