mirror of
https://github.com/dmcxblue/ANIMO
synced 2026-08-04 16:10:26 +00:00
The three login scripts were minting only management.azure.com tokens
regardless of the resource the operator picked in the UI dropdown -
because none of the pieces in the chain honoured it. az cli was
similarly minting only its default ARM token. Now the operator's
choice reaches both toolchains end-to-end.
- server/scripts/login_azure.ps1
- server/scripts/login_azure_devicecode.ps1
- server/scripts/login_spn_azure.ps1
Add `[string]$Resource='https://management.azure.com'` param.
Get-AzAccessToken now runs with -ResourceUrl $Resource (previously
hardcoded to https://management.azure.com or omitted, defaulting
to ARM). After `az login` succeeds, also fetch a resource-specific
token via `az account get-access-token --resource $Resource -o tsv`
so both Az PS and az cli have a warm token cache for the chosen
audience. Device-code hint now includes the exact
`az account get-access-token --resource ...` line.
- server/Server.cpp
handleNewSession reads req["resource"] (default ARM) into a local
and forwards it as `-Resource '<escaped>'` on all three script
invocations (credential/ROPC, device-code, SPN). Uses the existing
escapePsString helper. Also stops the SPN meta-write from
hardcoding management.azure.com - it now records the actual
resource. The old ternary that always returned ARM is replaced
with a plain default.
- client/CredentialLoginWindow.{h,cpp}
Dropdown expanded from 2 to 6 entries (Management, Graph, Key
Vault, Storage, SQL, Other...). currentData() carries the resource
URL - same pattern SPNLoginWindow already uses. "Other..." reveals
a free-text QLineEdit; a trailing "/.default" scope suffix is
stripped so -ResourceUrl gets a v1 audience URL.
- client/DeviceCodeLoginWindow.cpp
startFullServerSession() no longer hardcodes ARM - reads
resourceInput->text() (the free-text field that was already in the
UI but silently ignored). Empty falls back to ARM; a trailing
/.default is stripped for the same reason.
- client/SPNLoginWindow.cpp
authenticateViaPowerShell() no longer hardcodes ARM in req -
forwards pendingResource (already populated from the dropdown at
handler entry). Empty falls back to ARM defensively.