pvillard31 opened a new pull request, #11722:
URL: https://github.com/apache/nifi/pull/11722

   # Summary
   
   NIFI-16387 - Support Microsoft Entra access token authentication for SQL 
Server in DBCP services
   
   This change adds support for Microsoft Entra access-token authentication to 
Microsoft SQL Server and Azure SQL through NiFi DBCP controller services.
   
   The Azure Entra Database Password Provider previously supported Azure 
Database for PostgreSQL and Azure Database for MySQL by supplying an OSS RDBMS 
token through the JDBC password property. The Microsoft JDBC Driver for SQL 
Server instead requires the token through its `accessToken` property.
   
   - Added `DatabaseCredentialPlacement` to the DBCP service API with:
     - `PASSWORD`
     - `ACCESS_TOKEN`
   - Added a backward-compatible default placement method to 
`DatabasePasswordProvider`.
   - Updated the provider-aware DBCP data source to use attempt-local JDBC 
properties for every physical connection.
   - Added access-token placement that:
     - Removes `user`, `userName`, and `password` aliases case-insensitively.
     - Sets canonical blank `user` and `password` values.
     - Sets the generated credential as `accessToken`.
     - Preserves other JDBC properties for driver validation.
   - Ensured provider-returned credential arrays are cleared.
   - Ensured attempt-local credentials are removed after successful and failed 
connection attempts.
   - Added database target selection to the Azure Entra Database Password 
Provider:
     - **Azure OSS Database**, using the existing OSS RDBMS scope and password 
placement.
     - **Microsoft SQL Server**, using the SQL Server scope and access-token 
placement.
   - Kept Azure OSS Database as the default to preserve existing configurations.
   - Updated provider documentation for both target types, token scopes, JDBC 
behavior, and validation boundaries.
   - Expanded existing tests without increasing the test-method count.
   
   The changes were tested against a SQL Server instance deployed in Azure with 
authentication using Workload Identity Federation via an Entra application.
   
   <img width="1056" height="327" alt="Screenshot 2026-09-25 at 14 28 14" 
src="https://github.com/user-attachments/assets/d69f5193-829a-400f-8acc-205f4ad53e2d";
 />
   
   <img width="1052" height="587" alt="Screenshot 2026-09-25 at 14 28 29" 
src="https://github.com/user-attachments/assets/49caf573-80bb-4240-a3c9-0633fe5cebd2";
 />
   
   
   # Tracking
   
   Please complete the following tracking steps prior to pull request creation.
   
   ### Issue Tracking
   
   - [Apache NiFi Jira](https://issues.apache.org/jira/browse/NIFI) issue 
created
   
   ### Pull Request Tracking
   
   - Pull Request title starts with Apache NiFi Jira issue number, such as 
`NIFI-00000`
   - Pull Request commit message starts with Apache NiFi Jira issue number, as 
such `NIFI-00000`
   - Pull request contains [commits 
signed](https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits)
 with a registered key indicating `Verified` status
   
   ### Pull Request Formatting
   
   - Pull Request based on current revision of the `main` branch
   - Pull Request refers to a feature branch with one commit containing changes
   
   # Verification
   
   Please indicate the verification steps performed prior to pull request 
creation.
   
   ### Build
   
   - [ ] Build completed using `./mvnw clean install -P contrib-check`
     - [ ] JDK 21
     - [ ] JDK 25
   
   ### Licensing
   
   - [ ] New dependencies are compatible with the [Apache License 
2.0](https://apache.org/licenses/LICENSE-2.0) according to the [License 
Policy](https://www.apache.org/legal/resolved.html)
   - [ ] New dependencies are documented in applicable `LICENSE` and `NOTICE` 
files
   
   ### Documentation
   
   - [ ] Documentation formatting appears as expected in rendered files
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to