You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 83f3dac
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: sdk/identity/identity/CHANGELOG.md
-57Lines changed: 0 additions & 57 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,20 +1,5 @@
1
1
# Release History
2
2
3
-
## 4.14.0-beta.6 (Unreleased)
4
-
5
-
### Features Added
6
-
7
-
### Breaking Changes
8
-
9
-
### Bugs Fixed
10
-
11
-
- Fixed `AzurePipelinesCredential` to include only relevant details in error messages and logs when the OIDC token request fails. [#39774](https://github.com/Azure/azure-sdk-for-js/pull/39774)
12
-
- Fixed `InteractiveBrowserCredential` failing to authenticate when the user's default browser is already running and only permits a single instance. The browser is no longer launched with `newInstance`, which on macOS passed `open --new`. [#39814](https://github.com/Azure/azure-sdk-for-js/pull/39814)
13
-
14
-
### Other Changes
15
-
16
-
- Preserve caught errors as the cause when wrapping them. [#39423](https://github.com/Azure/azure-sdk-for-js/issues/39423)
17
-
18
3
## 4.13.2 (2026-08-12)
19
4
20
5
### Other Changes
@@ -23,27 +8,6 @@
23
8
- Replaced shell-based developer credential commands with safe, structured process execution. [#39279](https://github.com/Azure/azure-sdk-for-js/pull/39279)
24
9
- Migrated platform-specific module resolution to `#platform/*` imports. [#38309](https://github.com/Azure/azure-sdk-for-js/pull/38309)
25
10
26
-
## 4.14.0-beta.5 (2026-08-12)
27
-
28
-
### Other Changes
29
-
30
-
- Bumped the minimum `@azure/msal-node` dependency to `^5.1.5` so installs no longer resolve older `5.1.x` versions that pull in the vulnerable `uuid@8.3.0` transitive dependency. [#39425](https://github.com/Azure/azure-sdk-for-js/pull/39425)
31
-
- Replaced shell-based developer credential commands with safe, structured process execution. [#39279](https://github.com/Azure/azure-sdk-for-js/pull/39279)
32
-
33
-
## 4.14.0-beta.4 (2026-06-08)
34
-
35
-
### Bugs Fixed
36
-
37
-
- Fixed `AzureDeveloperCliCredential` to correctly parse error messages from Azure Developer CLI v1.23.7 and later, which previously caused raw JSON to surface in the credential error instead of the underlying error text. [#38416](https://github.com/Azure/azure-sdk-for-js/pull/38416)
38
-
- Fixed `handleMsalError` to preserve the original MSAL error via `cause` on `AuthenticationRequiredError`, allowing callers to access `.claims` on the underlying error. [#38722](https://github.com/Azure/azure-sdk-for-js/pull/38722)
39
-
40
-
## 4.14.0-beta.3 (2026-04-08)
41
-
42
-
### Other Changes
43
-
44
-
- Reduced bundle size by optimizing imports from `@azure/msal-node`, e.g. achieving a ~61kb reduction (from 851kb to 790kb) when importing `ClientCertificateCredential`. [#36942](https://github.com/Azure/azure-sdk-for-js/pull/36942)
45
-
- Updated `@azure/msal-node` to `^5.1.0` and `@azure/msal-browser` to `^5.5.0`. [#37836](https://github.com/Azure/azure-sdk-for-js/pull/37836)
46
-
47
11
## 4.13.1 (2026-03-18)
48
12
49
13
### Other Changes
@@ -54,27 +18,6 @@
54
18
- Updated `handleRedirectPromise` to use options object instead of string parameter
55
19
- Replaced deprecated `tokenQueryParameters` with `extraQueryParameters` in MSAL node flows
56
20
57
-
## 4.14.0-beta.2 (2026-02-10)
58
-
59
-
### Breaking Changes
60
-
61
-
- Renamed `enableAzureKubernetesTokenProxy` in `WorkloadIdentityCredentialOptions` to `enableAzureProxy`. [#36728](https://github.com/Azure/azure-sdk-for-js/pull/36728)
62
-
63
-
### Bugs Fixed
64
-
65
-
- Fixed an issue where `AzureDeveloperCliCredential` error messages included raw JSON output from `azd auth token` instead of clean, user-friendly messages. The credential now parses the JSON stderr output to extract and display only the error message. [#37268](https://github.com/Azure/azure-sdk-for-js/pull/37268)
66
-
- Fixed an issue where `IdentityClient` does not pass response in expected format for MSAL in empty response situations with additional logging. [#36906](https://github.com/Azure/azure-sdk-for-js/pull/36906)
67
-
68
-
### Other Changes
69
-
70
-
- Refactored and cleaned up `MsalClientOptions` to eliminate nested property duplication, replaced `getIdentityClientAuthorityHost` with `getAuthorityHost`, and removed deprecated `isNode` in favor of `isNodeLike`. [#36731](https://github.com/Azure/azure-sdk-for-js/pull/36731)
71
-
72
-
## 4.14.0-beta.1 (2025-11-06)
73
-
74
-
### Features Added
75
-
76
-
- Added Kubernetes token proxy support (identity binding mode) to `WorkloadIdentityCredential`. When enabled via the `enableAzureKubernetesTokenProxy ` option, the credential redirects token requests to an AKS-provided proxy to work around Entra ID's limit on federated identity credentials per managed identity. This feature is opt-in and only available when using `WorkloadIdentityCredential` directly (not supported by `DefaultAzureCredential` or `ManagedIdentityCredential`). [#36218](https://github.com/Azure/azure-sdk-for-js/pull/36218)
Copy file name to clipboardExpand all lines: sdk/identity/identity/README.md
+41-5Lines changed: 41 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -60,9 +60,41 @@ You can read more through the following links:
60
60
61
61
For advanced authentication workflows in the browser, we have a section where we showcase how to use the [@azure/msal-browser](https://www.npmjs.com/package/@azure/msal-browser) library directly to authenticate Azure SDK clients.
62
62
63
-
### Authenticate the client
63
+
### Authenticate the client in development environment
64
64
65
-
When debugging and executing code locally, it's typical for a developer to use their own account for authenticating calls to Azure services. There are several developer tools that can be used to perform this authentication in your development environment. For more information, see [Authentication during local development](https://learn.microsoft.com/azure/developer/javascript/sdk/authentication/overview#authentication-during-local-development).
65
+
While we recommend using managed identity in your Azure-hosted application, it's typical for a developer to use their own account for authenticating calls to Azure services when debugging and executing code locally. There are several developer tools that can be used to perform this authentication in your development environment.
66
+
67
+
#### Authenticate via the Azure Developer CLI
68
+
69
+
Developers coding outside of an IDE can also use the [Azure Developer CLI][azure_developer_cli] to authenticate. Applications using the `DefaultAzureCredential` or the `AzureDeveloperCliCredential` can then use this account to authenticate calls in their application when running locally.
70
+
71
+
To authenticate with the [Azure Developer CLI][azure_developer_cli], users can run the command `azd auth login`. For users running on a system with a default web browser, the Azure Developer CLI launches the browser to authenticate the user.
72
+
73
+
For systems without a default web browser, the `azd auth login --use-device-code` command uses the device code authentication flow.
74
+
75
+
#### Authenticate via the Azure CLI
76
+
77
+
Applications using the `AzureCliCredential`, whether directly or via the `DefaultAzureCredential`, can use the Azure CLI account to authenticate calls in the application when running locally.
78
+
79
+
To authenticate with the [Azure CLI][azure_cli], run the command `az login`. For users running on a system with a default web browser, the Azure CLI launches the browser to authenticate the user.
80
+
81
+
![Azure CLI Account Sign In][azureclilogin_image]
82
+
83
+
For systems without a default web browser, the `az login` command uses the device code authentication flow. The user can also force the Azure CLI to use the device code flow rather than launching a browser by specifying the `--use-device-code` argument.
Applications using the `AzurePowerShellCredential`, whether directly or via the `DefaultAzureCredential`, can use the account connected to Azure PowerShell to authenticate calls in the application when running locally.
90
+
91
+
To authenticate with [Azure PowerShell][azure_powershell], run the `Connect-AzAccount` cmdlet. By default, like the Azure CLI, `Connect-AzAccount` launches the default web browser to authenticate a user account.
If interactive authentication can't be supported in the session, then the `-UseDeviceAuthentication` argument forces the cmdlet to use a device code authentication flow instead, similar to the corresponding option in the Azure CLI credential.
96
+
97
+
### Authenticate the client in browsers
66
98
67
99
To authenticate Azure SDK clients within web browsers, we offer the `InteractiveBrowserCredential`, which can be set to use redirection or popups to complete the authentication flow. It's necessary to [create an Azure App Registration](https://learn.microsoft.com/entra/identity-platform/scenario-spa-app-registration) in the Azure portal for your web application first.
68
100
@@ -80,7 +112,7 @@ See [Credential Classes](#credential-classes).
80
112
81
113
### DefaultAzureCredential
82
114
83
-
`DefaultAzureCredential` simplifies authentication while developing apps that deploy to Azure by combining credentials used in Azure hosting environments with credentials used in local development. For more information, see [DefaultAzureCredential overview](https://aka.ms/azsdk/js/identity/credential-chains#defaultazurecredential-overview).
115
+
`DefaultAzureCredential` simplifies authentication while developing apps that deploy to Azure by combining credentials used in Azure hosting environments with credentials used in local development. For more information, see [DefaultAzureCredential overview](https://aka.ms/azsdk/js/identity/credential-chains#use-defaultazurecredential-for-flexibility).
84
116
85
117
#### Continuation policy
86
118
@@ -98,7 +130,7 @@ Azure Identity for JavaScript provides a plugin API that allows us to provide ce
98
130
99
131
## Examples
100
132
101
-
You can find more examples of using various credentials in [Azure Identity Examples Page](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/identity/identity/samples/AzureIdentityExamples.md).
133
+
You can find more examples of using various credentials in [Azure Identity Examples Page](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/identity/identity/samples/AzureIdentityExamples.md)
102
134
103
135
### Authenticate with `DefaultAzureCredential`
104
136
@@ -231,7 +263,7 @@ Not all credentials require this configuration. Credentials that authenticate th
|[`EnvironmentCredential`](https://learn.microsoft.com/javascript/api/@azure/identity/environmentcredential?view=azure-node-latest)| Authenticates a service principal or user via credential information specified in environment variables. |[example](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/identity/identity/samples/AzureIdentityExamples.md#authenticating-a-service-principal-with-environment-credentials)|
236
268
|[`ManagedIdentityCredential`](https://learn.microsoft.com/javascript/api/@azure/identity/managedidentitycredential?view=azure-node-latest)| Authenticates the managed identity of an Azure resource. |[example](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/identity/identity/samples/AzureIdentityExamples.md#authenticating-in-azure-with-managed-identity)|
237
269
|[`WorkloadIdentityCredential`](https://learn.microsoft.com/javascript/api/@azure/identity/workloadidentitycredential?view=azure-node-latest)| Supports [Microsoft Entra Workload ID](https://learn.microsoft.com/azure/aks/workload-identity-overview) on Kubernetes. |[example](https://github.com/Azure/azure-sdk-for-js/blob/main/sdk/identity/identity/samples/AzureIdentityExamples.md#authenticating-in-azure-with-workload-identity)|
@@ -336,7 +368,11 @@ If you encounter bugs or have suggestions, [open an issue](https://github.com/Az
336
368
To contribute to this library, read the [contributing guide](https://github.com/Azure/azure-sdk-for-js/blob/main/CONTRIBUTING.md) to learn more about how to build and test the code.
0 commit comments