* Add "Continue with Microsoft" sign in for GitHub
Brokers a GitHub session from an Entra token the built-in `microsoft`
provider already holds, so someone signed in to Microsoft can reach
Copilot without a second browser round trip.
The flow is deliberately two exchanges. The first buys a `read:user`
discovery token, just enough to `GET /user` and show which GitHub account
the Entra identity maps to. Nothing is published until the user confirms
that identity. The second exchange then mints the scopes the caller
actually asked for. The discovery token is never persisted and never
published as a session.
Entra-brokered sessions live in memory for the life of the window and are
never written to the Keychain. What survives a reload is the user's
consent, recorded in global state as a GitHub label, a Microsoft label,
and the GitHub user id. A fresh window mints the session again from that
row, silently, re-verifying through discovery that the row still points
at the same account.
Rows are keyed by GitHub account label, because that is what VS Code
itself keys an account by: `getAccounts` collapses sessions by label and
the account preference is stored by label. The id is kept for one job
only, checking that the token GitHub just returned belongs to the account
the row names.
Signing out of the Microsoft account drops the sessions, since nothing
can renew them, but leaves the rows alone. The Microsoft account list is
a per-window cache that reads empty for a moment while it repopulates,
and the rows are global state shared by every window, so acting on a
blink of that list would sign the user out everywhere with no way back.
Dropping only the sessions self-heals: the next read mints them again
from the row that is still there.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* Fix CI: hygiene warnings and a missing test stub
The hygiene job fails on eslint warnings, and both warnings were in
entraTokenExchange.test.ts: an `in` operator check and a double-quoted
string outside of localization. The harness override is now a positive
`noExchangeEndpoint` boolean, and the assertion uses single quotes.
The browser test broke because main added @INativeManagedSettingsService
to the DefaultAccountProvider constructor. The signIn helper now stubs
both managed-settings services with their existing Null implementations.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* Address review comments on Microsoft-brokered sessions
Verify the granted token against the account the user confirmed, not just
the discovery token, and give that mismatch its own failure kind so a
restore only forgets a link when GitHub positively names somebody else.
Make a failed unlink write stick for the window that did it, so a sign out
cannot leave a row behind that silently signs the user back in.
Discard a token whose Microsoft account was signed out while the exchange
was in flight, settle every expired session rather than only those with
nothing to hand back, and warn when GitHub grants fewer scopes than asked.
Adds a provider-level test suite driven through the real getSessions.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
github-authentication: avoid persisting read-time account updates
Keep account and avatar hydration in memory without writing it back during session reads, preventing browser secret changes from re-entering the read path.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add authSessionAccountIcon proposed API and account avatar support
Introduces a new proposed API `authSessionAccountIcon` that allows authentication
providers to supply an icon URL (typically a profile avatar) for authentication
session accounts.
Changes:
- New proposed API: `AuthenticationSessionAccountInformation.iconUrl`
- GitHub authentication extension updated to fetch and provide user avatar URLs
- Activity bar and global composite bar updated to display account avatars
- Authentication service extended to propagate icon information
* Address Copilot review feedback
- Use removeAttribute('src') instead of empty string to avoid spurious requests
- Add alt='', aria-hidden='true', draggable=false to avatar img for accessibility
- Update iconUrl in addOrUpdateAccount when provider supplies/changes it
- Fetch avatarUrl for existing sessions that are missing iconUrl
* Address review feedback: account icon as Uri, avatar setting, Agents window consolidation
- Change AuthenticationSessionAccountInformation.iconUrl (string) to icon (Uri)
per review feedback, and use URI in the internal workbench type
- Revive the icon URI at the RPC boundaries (MainThread/ExtHost), typing the
proxies as Proxied<T>
- Persist the fetched avatar in stored GitHub auth sessions so it is not
refetched on every read
- Add workbench.accounts.showAvatar setting to show/hide account avatars
- Agents window: prefer the authentication session's account icon over the
hardcoded github.com avatar URL pattern and honor the new setting
* Fix Compile & Hygiene: tab indentation in extensionsApiProposals and remove unused import
* Fix DynamicAuthProvider test mock to match Proxied proxy typing
* auth - improve account avatar support
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Dmitriy Vasyura <dmitriv@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Revert PR #298277 changes since agents is no longer a separate app.
Removes sessions icon swap from the auth redirect page, the
agentSessionsWorkspace API usage, and the sessions-icon.svg asset.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Disabled protocol handlers and registry updates on Windows in portable mode.
Added API proposal to detect if VS Code is running in portable mode from extensions.
Skipped protocol redirect in GitHub authentication in portable mode.
For #271167
This makes it so our built-in extensions can mostly be built using `tsc` on the command line. Previously the extensions were picking up a lot of typing info from the root `node_modules` that meant they weren't truly independent
For #269213
This adds a new eslint rule for `as any` and `<any>({... })`. We'd like to remove almost all of these, however right now the first goal is to prevent them in new code. That's why with this first PR I simply add `eslint-disable` comments for all breaks
Trying to get this change in soon after branching off for release to hopefully minimize disruption during debt week work
A user reported that their proxy ZScaller has issues with Electron's fetch. More research needs to be done to understand why this is not playing nice wholistically...
... but, to unblock GitHub scenarios like Copilot, we add this setting to change the implementation of fetch used.
At some point, we need to have http.useElectronFetch setting be enabled by default and when that happens, this setting can be removed in favor of that.
cc @chrmarti @alexdima