-
Notifications
You must be signed in to change notification settings - Fork 2k
MS Entra authentication #448
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from 6 commits
Commits
Show all changes
22 commits
Select commit
Hold shift + click to select a range
428ab9a
MS Entra authentication
14b4ca5
Entra properties
ffa40fe
code refactor
70a7845
Merge remote-tracking branch 'upstream/main'
9b7aa99
Merge branch 'main' of https://github.com/spring-projects/spring-ai
36ab2c9
Merge branch 'main' of https://github.com/spring-projects/spring-ai
027430e
Merge branch 'main' of https://github.com/spring-projects/spring-ai
22e25f0
Merge branch 'main' of https://github.com/spring-projects/spring-ai
7c216a1
Merge branch 'main' of https://github.com/spring-projects/spring-ai
9cb2415
Merge branch 'main' of https://github.com/spring-projects/spring-ai
b23757c
Merge branch 'main' of https://github.com/spring-projects/spring-ai
a2a8969
merge
williamspindox 0ca12f7
Merge branch 'main' of https://github.com/spring-projects/spring-ai
3eff86b
spring-javaformat:apply
d7786c7
Merge branch 'main' of https://github.com/spring-projects/spring-ai
1cb3f49
Merge branch 'main' of https://github.com/spring-projects/spring-ai
3c2345b
Merge branch 'main' of https://github.com/spring-projects/spring-ai
ead3711
Merge branch 'main' of https://github.com/spring-projects/spring-ai
3fe103d
Merge branch 'main' of https://github.com/spring-projects/spring-ai
ee9b28a
Merge branch 'main' of https://github.com/spring-projects/spring-ai
9ef0bc5
Merge branch 'main' of https://github.com/spring-projects/spring-ai
7a1c9a2
Merge branch 'main' of https://github.com/spring-projects/spring-ai
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,7 +5,7 @@ | |
| * you may not use this file except in compliance with the License. | ||
| * You may obtain a copy of the License at | ||
| * | ||
| * https://www.apache.org/licenses/LICENSE-2.0 | ||
| * https://www.apache.org/licenses/LICENSE-2.0 | ||
| * | ||
| * Unless required by applicable law or agreed to in writing, software | ||
| * distributed under the License is distributed on an "AS IS" BASIS, | ||
|
|
@@ -22,6 +22,12 @@ | |
| import com.azure.core.credential.AzureKeyCredential; | ||
| import com.azure.core.util.ClientOptions; | ||
|
|
||
| import com.azure.core.credential.TokenCredential; | ||
| import com.azure.core.http.policy.HttpLogDetailLevel; | ||
| import com.azure.core.http.policy.HttpLogOptions; | ||
| import com.azure.core.management.AzureEnvironment; | ||
| import com.azure.core.management.profile.AzureProfile; | ||
| import com.azure.identity.ClientSecretCredentialBuilder; | ||
| import org.springframework.ai.azure.openai.AzureOpenAiChatClient; | ||
| import org.springframework.ai.azure.openai.AzureOpenAiEmbeddingClient; | ||
| import org.springframework.ai.model.function.FunctionCallback; | ||
|
|
@@ -46,13 +52,50 @@ public class AzureOpenAiAutoConfiguration { | |
| @ConditionalOnMissingBean | ||
| public OpenAIClient openAIClient(AzureOpenAiConnectionProperties connectionProperties) { | ||
|
|
||
| Assert.hasText(connectionProperties.getApiKey(), "API key must not be empty"); | ||
| Assert.hasText(connectionProperties.getEndpoint(), "Endpoint must not be empty"); | ||
| HttpLogOptions options = new HttpLogOptions(); | ||
|
||
| if (connectionProperties.getEnableLog()) { | ||
| HttpLogDetailLevel level = HttpLogDetailLevel.BODY_AND_HEADERS; | ||
| options.setLogLevel(level); | ||
| options.setPrettyPrintBody(true); | ||
| } | ||
|
|
||
| /* | ||
| * https://learn.microsoft.com/en-us/azure/databricks/dev-tools/service-prin-aad- | ||
| * token | ||
| */ | ||
| if ("entra".equals(connectionProperties.getAuthType())) { | ||
| Assert.hasText(connectionProperties.getEndpoint(), "Endpoint must not be empty"); | ||
| Assert.hasText(connectionProperties.getClientId(), "Client ID must not be empty"); | ||
| Assert.hasText(connectionProperties.getClientSecret(), "Client Secret must not be empty"); | ||
| Assert.hasText(connectionProperties.getTenantId(), "Tenant ID must not be empty"); | ||
|
|
||
| AzureProfile azureProfile = new AzureProfile(AzureEnvironment.AZURE); | ||
|
|
||
| TokenCredential tokenCredential = new ClientSecretCredentialBuilder() | ||
| .clientId(connectionProperties.getClientId()) | ||
| .clientSecret(connectionProperties.getClientSecret()) | ||
| .tenantId(connectionProperties.getTenantId()) | ||
| .authorityHost(azureProfile.getEnvironment().getActiveDirectoryEndpoint()) | ||
| .build(); | ||
|
|
||
| return new OpenAIClientBuilder().endpoint(connectionProperties.getEndpoint()) | ||
| .credential(new AzureKeyCredential(connectionProperties.getApiKey())) | ||
| .clientOptions(new ClientOptions().setApplicationId("spring-ai")) | ||
| .buildClient(); | ||
| return new OpenAIClientBuilder().httpLogOptions(options) | ||
| .endpoint(connectionProperties.getEndpoint()) | ||
| .credential(tokenCredential) | ||
| .clientOptions(new ClientOptions().setApplicationId("spring-ai")) | ||
| .buildClient(); | ||
| } | ||
| else { | ||
| Assert.hasText(connectionProperties.getApiKey(), "API key must not be empty"); | ||
| Assert.hasText(connectionProperties.getEndpoint(), "Endpoint must not be empty"); | ||
|
|
||
| AzureKeyCredential keyCredential = new AzureKeyCredential(connectionProperties.getApiKey()); | ||
|
|
||
| return new OpenAIClientBuilder().httpLogOptions(options) | ||
| .endpoint(connectionProperties.getEndpoint()) | ||
| .credential(keyCredential) | ||
| .clientOptions(new ClientOptions().setApplicationId("spring-ai")) | ||
| .buildClient(); | ||
| } | ||
| } | ||
|
|
||
| @Bean | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It's not related to MS Entra, but it avoid a WARNING during build.