Add Microsoft 365 actions, approvals, and delegated workflow execution - #1497
Merged
Paul Lizer (paullizer) merged 15 commits intoSep 20, 2026
Merged
Conversation
Introduce separate Calendar, Email, OneDrive, and SharePoint Online actions with delegated retrieval, source-sharing approvals, retained conversation evidence, and explicit workflow Run as authorization. Retire new combined Graph actions, enforce live capability checks, add cloud-aware retrieval and durable continuation safeguards, and document setup for version 0.261.029. Refs #1493 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
…indings Remove provider exception text from public alert decisions and historical run/notification projections. Preserve waiting responses, exception identity, budget retry behavior, and expected Cosmos outcomes. Add regression coverage and bump the app to 0.261.030. Refs #1493; CodeQL remediation for #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Move immutable context and fingerprint primitives below execution and connection owners. Inject the live Run as validator from both web and scheduler bootstrap, fail closed before credentials when unconfigured, and preserve pre/post-refresh checks. Add cold-import and revocation coverage and document the four intentional CodeQL findings. Refs #1493; remediation for #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Record the passing implementation-head CodeQL analysis, the concrete Protocol implementations and public exception consumers, and individual replies resolving all four remaining Advanced Security review threads. Documentation only; no runtime or version change. Refs #1493 and #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
12 tasks
Remove unsupported partition_key arguments from conditional Cosmos replacements while preserving body-derived partition routing and ETag checks. Keep async agent stream pulls and cleanup in one isolated context, preserve approval/sign-in handling, and log terminal failures safely. Add real-SDK and Semantic Kernel regressions and bump the application to 0.261.031. Refs #1493; follow-up for #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bind the selected source actions before kernel creation and pause for explicit delegated consent before model execution. Add session-bound PKCE sign-in through the registered login callback, resume the original chat, fix HTTPS callback construction and stale-CSRF recovery, and simplify Profile to source-level permission bundles. Preserve workflow Run as, action capabilities, and Commercial/Government/custom-cloud routing. Add backend and browser regressions; bump the app to 0.261.032. Refs #1493 and #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Validate that token responses contain the requested grants without applying the outbound scope allowlist or request-count limit to extra prior consent. Share the check across chat and workflow callbacks, retain cloud-qualified matching and narrow workflow authorization, and add real-MSAL regressions for Commercial, Government, and custom clouds. Bump the app to 0.261.033 and document the observed post-consent failure. Refs #1493 and #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Provide a separate Profile chat reconnect using the current user's verified PKCE flow without requiring a pending request or workflow configuration. Preserve the old cache on failure, avoid replay from Profile, and pass exact source scopes from Graph 401 responses into chat continuation. Keep policy, model-budget, service, and download-link errors distinct. Add backend/UI coverage and bump the app to 0.261.034. Refs #1493 and #1497. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Account for all 75 models with source-backed capacities, scoped profiles, explicit unknowns, and independent per-field resolution. Advance the application to 0.261.035. Refs #1493 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Separate model capacity from Response Length, preserve inherited metadata across editor saves, and expose safe validation errors without leaking credentials. Refs #1493 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Carry immutable budget metadata into actual Semantic Kernel requests, M365 streaming and resumed execution, retained-file analysis, and compatible tabular batching. Preserve provider-specific accounting and reject mismatched or oversized requests with actionable errors. Add real-catalog, real-agent, SDK wire-payload, context-isolation, and no-replay regressions. Refs #1493. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve MCP remote-only authorization and scoped legacy management alongside M365 source validation, durable Graph migration receipts, and model-budget integration. Resolve eight conflicts, add cross-feature regressions, and advance the application to 0.261.036. Refs #1493, #1497 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use explicit discard bindings for unused preparation results and an explicit absent-record state for Cosmos 404 handling. Preserve effective budgets and legacy action rejection, with focused normal/optimized regressions. Advance application version to 0.261.037. Refs #1493, #1497; CodeQL alerts 2781 and 2748. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add authoritative live/history cards for manual and delayed mail/calendar actions, shared-viewer projections, owner review and reconnect recovery. Unify conditional send/cancel claims and safe lifecycle cleanup; document retained draft behavior and recovery semantics. Bump application version to 0.261.038. Refs #1493 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Address review comment 4055671401 by preserving the document cleanup call without assigning its ignored return value. Add focused cleanup-order and audit regressions, document the disposition, and bump the app to 0.261.039. Refs #1493 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Interactive reconnect (
f5f25690): adds Profile > Settings > Microsoft 365 chat connection > Reconnect Microsoft 365 for chat, even when credentials already exist or no request is paused. Fresh state/nonce/PKCE sign-in replaces the cache only after same-account verification; failures preserve the old cache. Profile reconnect does not replay past requests or change workflow connections or sharing approvals. Graph bearer-token HTTP 401 responses now preserve scopes/source for the existing chat sign-in continuation. Policy denial, throttling, service/configuration failures, and expired temporary download links remain distinct.Important unresolved retrieval configuration: read-only investigation of the latest screenshot identified
model_context_unavailable, not expired Microsoft credentials. The selectedgpt-5.6-terracatalog record has no declared context/output token limits. Reconnecting does not fix that separate model-budget issue; this change neither invents limits nor bypasses the safety bound. Details are inM365_CHAT_RECONNECT_RECOVERY_FIX.md.Consent callback (
98c4b0ab): accepts additional previously consented permissions in successful token responses while requiring every requested grant. The outbound scope allowlist, configured cloud matching, and narrow workflow authorization remain unchanged.Connection onboarding (
26e44a23): binds selected actions before kernel loading, offers Connect in chat before model execution when delegated access is missing, and resumes the original conversation. Reuses/getAToken, fixes HTTPS callbacks and exact stale-CSRF recovery, and uses source-level consent bundles with Commercial/Government/custom-cloud support.Streaming and CodeQL (
bdb668af,1883af6e,c23e32c1): fixes unsupported Cosmos replacement arguments and async streaming context lifetime; removes public workflow diagnostics, protects historical projections, clarifies control flow, and removes the execution/connection import cycle. Four intentional Protocol/facade notes are documented and their review threads were answered/resolved without global suppression.Target:
Developmentinmicrosoft/simplechat.Setup: interactive chat and Profile chat reconnect use
/getATokenand the server-side login session, without Key Vault or a saved workflow connection. Unattended workflows separately require/api/m365/connections/callback, explicit Run as consent, and a dedicated Key Vault encryption key referenced byM365_WORKFLOW_TOKEN_KEY_SECRET_NAME. Bootstrap provisionsm365_connectionsandm365_execution_runswith/user_idpartitions. Seedocs/explanation/features/MICROSOFT_365_ACTIONS.md.Deployment: 0.261.034 is committed and pushed for user-managed deployment. This session has not rebuilt/restarted the test app or changed tenant permissions/Key Vault credentials. The inspected deployment's workflow-only callback and encryption-key reference still require administrator setup for unattended workflows.
Linked issue
Refs #1493. Related sync/external-tab work in #954 and #956 remains separate.
Release Notes & Latest Features
Compatibility: no new combined Graph actions; workflows require an explicitly selected, consenting Run as account. Selecting Calendar or Email requests its supported operation permission bundle, shown by Microsoft before consent; disabled action capabilities and outgoing-delivery reviews still apply. Existing narrower connections are not silently upgraded.
Is this visible to end users?
Is this admin-facing (Admin Settings, governance, deployment, config)?
Should this become a Latest Feature card?
Screenshot needed for the card?
Version bump
application/single_app/config.pyVERSIONthird segment bumped, or not needed because this is docs-onlydeployers/version.txtbumped, or not needed becausedeployers/was not changedApplication advanced from
0.261.028through the feature/remediation fixes to0.261.034. Latest patch adds interactive reconnect and Graph authentication recovery. No deployer files changed.Testing / validation
c23e32c1reduced 31 PR findings to four intentional notes. Workflows onbdb668afand26e44a23also passed. These are historical results, not a claim about CI on the latest head.Live evidence: Azure telemetry and the existing shared browser reproduced the earlier missing-action/callback issues. The consent incident showed successful Microsoft token exchange followed by local scope rejection. For the latest screenshot, extracted diagnostic codes were
model_context_unavailableand earlierinvalid_query; a correlated Graph search returned 200. No live token bodies or document contents were retrieved for diagnosis, and temporary log downloads were removed.Known pre-existing tests: three unchanged grounding tests have stale call-count/incomplete AST fixtures against original head
b8a75418; an unchanged chat-reattach test asserts historical version0.239.191exactly. They were not edited to conceal failures.Not performed: live end-to-end qualification of the newly deployed 0.261.034 reconnect flow or live Government/custom-cloud, Copilot, and Key Vault qualification. The user handles deployment before live retesting. Reconnect does not resolve the separate missing model-budget configuration.
Documentation
Feature, source-action, Profile, workflow, admin, and chat-control documentation is updated. Versioned fixes cover CodeQL, Cosmos/streaming, onboarding, consent-scope responses, and
M365_CHAT_RECONNECT_RECOVERY_FIX.md. Release notes remain unchanged per the prior request; a Latest Feature card is not included.Security checklist
@swagger_route(security=get_auth_security())and Blueprint/user guardssanitize_settings_for_user()