* chat: offer Microsoft sign-in when an Entra account links to GitHub
Sign-in surfaces can now offer "Continue with Microsoft" only to users who can
actually use it: those with a Microsoft work or school account that GitHub links
to a GitHub account (for example an Enterprise Managed User).
The workbench checks this silently in the background, through two session
options that only the workbench can set (extensions' getSession requests have
every `_workbench*` option stripped):
- microsoft-authentication returns silent tokens for the broker's work and
school accounts, including ones not yet approved for VS Code, without
approving, caching, persisting or announcing anything.
- github-authentication exchanges those tokens for a `read:user` token, reads
the linked account, and revokes the token when the host and build allow it.
`chat.microsoftAuthentication.enabled` becomes `auto` / `always` / `never`,
defaulting to `never` and rolled out through experimentation (legacy `true` and
`false` keep their meaning). The chat setup dialog and the first-run onboarding
screen follow the result without ever waiting for it.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chat: forget a found Microsoft link when accounts change
Adding or removing a Microsoft account now forgets a previously found link
and probes again, so signing out can no longer leave "Continue with
Microsoft" offered. A probe still running when the accounts change has its
answer discarded, since it answers for accounts that may be gone. Token
refreshes, which only report `changed`, are ignored so they do not mint
GitHub tokens.
Also stop promising unconditional revocation of the probe's GitHub token,
and describe the setting as covering sign-in surfaces, including the
welcome screen.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: preserve enterprise credential namespaces
Use deterministic host and storage planning for the existing single enterprise URI. Retain original keychains and Microsoft account links across equivalent URI edits and restarts, reject storage collisions, and leave public GitHub usable when enterprise storage fails.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: derive enterprise storage keys instead of persisting them
Use a canonical URI-derived credential key and migrate the matching legacy tokens and Microsoft account links before starting the host engine. Keep legacy data until destination writes succeed, preserve canonical sign-out state, and retry incomplete migration without a registry or completion marker.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: preserve canonical logins during legacy migration
Read the canonical destination after inspecting legacy stores and recheck its token before copying. Cover concurrent canonical writes and assert exactly which credentials survive each failed migration write or cleanup.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: consolidate enterprise URI storage helpers
Rely on URI serialization for hostname casing, retain explicit scheme and trailing-slash normalization, and fold the single-host configuration helper into enterpriseStorage. Extend coverage for uppercase schemes, default ports, root paths, repeated slashes and escaped deployment paths.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: mark legacy storage migration for removal
Group temporary migration declarations and functions in a region scheduled for removal in 1.144, four releases after 1.140. Keep permanent URI and credential-key helpers outside the region.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: prefer canonical credentials over legacy aliases
Select legacy token and account-link sources only when their canonical component is absent. Clean up aliases for authoritative canonical values without overwriting them, while retaining unresolved sources for missing data. Cover canonical sign-out, concurrent canonical writes, partial migration, cleanup retry, and case-sensitive URI user-info.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* github-auth: allow Entra token exchange without a client secret
Some VS Code builds (e.g. OSS/dev builds) don't have a distro-configured
client secret for the Entra-to-GitHub token exchange. Previously this
threw and blocked sign-in entirely. Simplify resolveEndpoint() to return
a plain URL and stop requiring/sending client_secret in the exchange
request, so the exchange can proceed without one.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* github-auth: update Entra exchange documentation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: separate enterprise provider and engine lifecycles
Keep the single configured enterprise instance and native account identities, while owning engine replacement, registration-safe session events and cleanup separately. Isolate OAuth callbacks by host and preserve the current Microsoft-brokered flows.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: discard superseded enterprise startup failures
Version enterprise configuration updates so a failed initial update cannot enqueue an error state after a newer configuration succeeds. Cover both A-to-B and A-to-B-to-A races through extension activation while preserving current-error fallback and later recovery.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: serialize enterprise failures and session publication
Remove activation generation bookkeeping by handling failure state inside each queued update. Reconcile preparation-time session removals, additions and changes before publishing a replacement, with regression coverage for consecutive initialization failures and pending-host events.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: own event buffering at the registration boundary
Buffer initial provider events in the extension host until its registration RPC completes. Remove the extension-side wrapper, microtask readiness inference and construction factory; directly construct a host-bound session engine with a side-effect-free cached session inventory. Preserve broker flows and exercise registration ordering through core RPC tests.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: clarify disposal and registration ownership
Keep the bundled README focused on user setup. Name disposal cancellation explicitly, verify cleanup while an engine is still being prepared, and clarify why core captures session events before awaiting registration.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Add GitHub session issuer provenance
Expose optional session authorizationServer metadata through authIssuers and authentication RPCs, populate it for GitHub sessions, and route in-repository consumers from the selected session. Keep existing single-host configuration and account-selection behavior.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* authentication: Preserve public static-token MCP sessions
Keep issuer validation on the enterprise MCP path and preserve the fixed public endpoint for static-token authentication. Cover definition creation and resolution using StaticGitHubAuthenticationService.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* i18n: Register workbench GitHub service translations
Register the service's new localized authentication error with the workbench translation project so the CI translation-reminder rule passes.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Managed (EMU) accounts can't access the education.github.com endpoint, so
evaluate the EMU heuristic up front and skip the fetch entirely for them,
setting edu to 'none'. Telemetry schema is unchanged.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* github-auth: Express token expiry in milliseconds
Rename the token exchange duration to expiresAfter and convert OAuth seconds at the exchange boundary.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* microsoft-authentication: Include token expiry in sessions
Expose MSAL's token expiration through the proposed authentication session expiration API as a positive millisecond duration.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Propagate authentication session lifetimes through AHP and use the Copilot SDK token provider for renewable Entra-backed GitHub sessions. Centralize static and provider-backed credential behavior behind one owner and reuse shared expiry helpers throughout authentication replay.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the default account available while authentication providers replace a
removed session with a new candidate in the same event. Add privacy-safe logs
to distinguish interactive and secret-storage replacements.
Fixes#333197
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add "Continue with Microsoft" sign in for GitHub
Brokers a GitHub session from an Entra token the built-in `microsoft`
provider already holds, so someone signed in to Microsoft can reach
Copilot without a second browser round trip.
The flow is deliberately two exchanges. The first buys a `read:user`
discovery token, just enough to `GET /user` and show which GitHub account
the Entra identity maps to. Nothing is published until the user confirms
that identity. The second exchange then mints the scopes the caller
actually asked for. The discovery token is never persisted and never
published as a session.
Entra-brokered sessions live in memory for the life of the window and are
never written to the Keychain. What survives a reload is the user's
consent, recorded in global state as a GitHub label, a Microsoft label,
and the GitHub user id. A fresh window mints the session again from that
row, silently, re-verifying through discovery that the row still points
at the same account.
Rows are keyed by GitHub account label, because that is what VS Code
itself keys an account by: `getAccounts` collapses sessions by label and
the account preference is stored by label. The id is kept for one job
only, checking that the token GitHub just returned belongs to the account
the row names.
Signing out of the Microsoft account drops the sessions, since nothing
can renew them, but leaves the rows alone. The Microsoft account list is
a per-window cache that reads empty for a moment while it repopulates,
and the rows are global state shared by every window, so acting on a
blink of that list would sign the user out everywhere with no way back.
Dropping only the sessions self-heals: the next read mints them again
from the row that is still there.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* Fix CI: hygiene warnings and a missing test stub
The hygiene job fails on eslint warnings, and both warnings were in
entraTokenExchange.test.ts: an `in` operator check and a double-quoted
string outside of localization. The harness override is now a positive
`noExchangeEndpoint` boolean, and the assertion uses single quotes.
The browser test broke because main added @INativeManagedSettingsService
to the DefaultAccountProvider constructor. The signIn helper now stubs
both managed-settings services with their existing Null implementations.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* Address review comments on Microsoft-brokered sessions
Verify the granted token against the account the user confirmed, not just
the discovery token, and give that mismatch its own failure kind so a
restore only forgets a link when GitHub positively names somebody else.
Make a failed unlink write stick for the window that did it, so a sign out
cannot leave a row behind that silently signs the user back in.
Discard a token whose Microsoft account was signed out while the exchange
was in flight, settle every expired session rather than only those with
nothing to hand back, and warn when GitHub grants fewer scopes than asked.
Adds a provider-level test suite driven through the real getSessions.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
github-authentication: avoid persisting read-time account updates
Keep account and avatar hydration in memory without writing it back during session reads, preventing browser secret changes from re-entering the read path.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add authSessionAccountIcon proposed API and account avatar support
Introduces a new proposed API `authSessionAccountIcon` that allows authentication
providers to supply an icon URL (typically a profile avatar) for authentication
session accounts.
Changes:
- New proposed API: `AuthenticationSessionAccountInformation.iconUrl`
- GitHub authentication extension updated to fetch and provide user avatar URLs
- Activity bar and global composite bar updated to display account avatars
- Authentication service extended to propagate icon information
* Address Copilot review feedback
- Use removeAttribute('src') instead of empty string to avoid spurious requests
- Add alt='', aria-hidden='true', draggable=false to avatar img for accessibility
- Update iconUrl in addOrUpdateAccount when provider supplies/changes it
- Fetch avatarUrl for existing sessions that are missing iconUrl
* Address review feedback: account icon as Uri, avatar setting, Agents window consolidation
- Change AuthenticationSessionAccountInformation.iconUrl (string) to icon (Uri)
per review feedback, and use URI in the internal workbench type
- Revive the icon URI at the RPC boundaries (MainThread/ExtHost), typing the
proxies as Proxied<T>
- Persist the fetched avatar in stored GitHub auth sessions so it is not
refetched on every read
- Add workbench.accounts.showAvatar setting to show/hide account avatars
- Agents window: prefer the authentication session's account icon over the
hardcoded github.com avatar URL pattern and honor the new setting
* Fix Compile & Hygiene: tab indentation in extensionsApiProposals and remove unused import
* Fix DynamicAuthProvider test mock to match Proxied proxy typing
* auth - improve account avatar support
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Dmitriy Vasyura <dmitriv@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Revert PR #298277 changes since agents is no longer a separate app.
Removes sessions icon swap from the auth redirect page, the
agentSessionsWorkspace API usage, and the sessions-icon.svg asset.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Disabled protocol handlers and registry updates on Windows in portable mode.
Added API proposal to detect if VS Code is running in portable mode from extensions.
Skipped protocol redirect in GitHub authentication in portable mode.
For #271167
This makes it so our built-in extensions can mostly be built using `tsc` on the command line. Previously the extensions were picking up a lot of typing info from the root `node_modules` that meant they weren't truly independent
For #269213
This adds a new eslint rule for `as any` and `<any>({... })`. We'd like to remove almost all of these, however right now the first goal is to prevent them in new code. That's why with this first PR I simply add `eslint-disable` comments for all breaks
Trying to get this change in soon after branching off for release to hopefully minimize disruption during debt week work