python-1.12.0
505 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
c033adb1f4 |
.NET: [BREAKING] Graduate HarnessAgent (#7119)
* Graduate HarnessAgent * Switch harness project to released and remove unreleased shell dependency * Address PR comments. |
||
|
|
f4e49958f3 |
samples: add AgentMemory (Neo4j-agent memory reimplemented in NET ) shopping assistant sample (#7096)
* samples: add Neo4j Shopping Assistant (standalone, published AgentMemory 1.0.1) The .NET port of the official Neo4j Agent Memory "retail assistant" example (neo4j-labs/agent-memory examples/microsoft_agent_retail_assistant, referenced from the Learn integration page), which is currently Python-only. Wires Neo4jMemoryContextProvider (AIContextProvider), MemoryToolFactory memory tools, and a ProductCatalog of retail tools over a Neo4j :Product graph, via the published AgentMemory + AgentMemory.AgentFramework 1.0.1 NuGet packages. Lives at the repo root rather than under dotnet/samples/: that tree is .NET 10 + Central Package Management + Microsoft.Agents.AI ~1.13 with source ProjectReferences, while AgentMemory currently targets net9.0 + Microsoft.Agents.AI 1.9.0. A repo-native version needs AgentMemory bumped to track the newer Agents.AI/Extensions.AI line first. Cross-linked from dotnet/samples/02-agents/AgentWithMemory/README.md as a "See also" entry, same pattern already used for the cross-folder Custom Memory Implementation link. Verified: dotnet build succeeds (0 warnings, 0 errors) against the published packages, proving the AgentMemory public surface is package-consumable. Matches sibling AgentWithMemory samples' conventions (BOM + copyright file header on .cs files, README sections: Features Demonstrated / Prerequisites / Environment Variables / Run the Sample / Expected Output). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * samples: move Neo4j shopping assistant into AgentWithMemory as Step06 Relocates the standalone shopping-assistant sample from the repo root into dotnet/samples/02-agents/AgentWithMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory, following that folder's naming/README/solution conventions. Renames its identity from "Neo4j" to "AgentMemory" (the library it actually demonstrates) since this is a community .NET port, not an officially recognized Neo4j integration - Neo4j is still referenced where it's a genuine technical detail (the graph backing store, env vars, Cypher). Adds empty Directory.Build.props/targets markers so it stays isolated from the repo's net10.0/CPM build, and registers it (skipped, like the Mem0 sample) in the CI sample-verification list since it needs a live Neo4j instance. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Update dotnet/samples/02-agents/AgentWithMemory/README.md Co-authored-by: westey <164392973+westey-m@users.noreply.github.com> * Update dotnet/samples/02-agents/AgentWithMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory/AgentWithMemory_Step06_MemoryUsingAgentMemory.csproj Co-authored-by: westey <164392973+westey-m@users.noreply.github.com> * cleanup :) * DefaultAzureCredential warning * fixes - simplification userId * minor doc fix * NU1015 fix * PR review fixes-improvements * Bump AgentMemory to 1.2.0, let the context provider surface memory tools WithMemoryOwnerScoping(sp) (1.1.0) already removed the need to manually wrap agent.RunAsync in ownerContext.BeginOwnerScope(userId). This picks up 1.2.0's ExposeMemoryToolsFromContextProvider option, so Neo4jMemoryContextProvider now appends the memory tools to AIContext.Tools itself on every model call — no more separate MemoryToolFactory wiring, AIContextProviders = [memoryProvider] is enough. Addresses westey-m's PR review suggestion. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * improvements according to pr review comments * Fix CI: use plural TargetFrameworks to actually restrict this sample to net10.0 Directory.Build.props sets a repo-wide TargetFrameworks (plural) list before this project's own properties are evaluated, and the SDK decides multi-targeting from that plural property at Sdk.props time. The prior singular TargetFramework=net10.0 override didn't take effect early enough, so restore still ran against net9.0/net8.0/netstandard2.0/net472 too - frameworks the published AgentMemory 1.2.0 packages don't support (NU1202), plus surfaced an OpenTelemetry.Api advisory as an error (NU1902) since TreatWarningsAsErrors is on repo-wide. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * Fix CI: pin OpenTelemetry.Api to unblock NU1902 audit failure The sample opts out of central package management, so it was pulling in OpenTelemetry.Api 1.12.0 transitively (via Microsoft.Agents.AI), which has a known moderate-severity vulnerability (GHSA-g94r-2vxg-569j). The repo treats NuGet audit warnings as errors, so restore failed outright and took down every dotnet-build matrix leg plus check-format. Pinned OpenTelemetry.Api to 1.15.3, matching Directory.Packages.props. With restore succeeding, previously-masked analyzer/format issues surfaced and are fixed too: RCS1118 (const local for immutable Cypher queries), CA1859 (List<IRecord> param instead of IReadOnlyList<IRecord>), and IDE1006 naming violations (s_seed field prefix, PascalCase Cypher/Shopper consts). Verified locally with the same mcr.microsoft.com/dotnet/sdk:10.0 image CI uses: dotnet build --warnaserror and dotnet format --verify-no-changes both pass clean, and a full solution build completed ~24 min with zero errors. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: westey <164392973+westey-m@users.noreply.github.com> |
||
|
|
b3f2e53923 |
.NET: [BREAKING] Graduate ToolApprovalAgent and add ToolAutoApprovalRuleContext (#7107)
* Graduate ToolApprovalAgent and introduce tool auto approval context * Address PR comments |
||
|
|
d93fc2dd74 |
.NET: [BREAKING] Harness: Switch FileAccess to opt-in (#7093)
* Switch FileAcessProvider on Harness to opt-in * Address PR comment --------- Co-authored-by: Evan Mattson <35585003+moonbox3@users.noreply.github.com> |
||
|
|
54617557e6 |
Update Foundry branding (#6999)
Replace user-facing Azure AI Foundry branding with Microsoft Foundry across docs, samples, comments, and display text while preserving technical identifiers. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Evan Mattson <35585003+moonbox3@users.noreply.github.com> |
||
|
|
23977a6045 |
.NET: Add name collision warnings for auto-approvals (#7089)
* Add name collision warnings for auto-approvals * Address PR comments |
||
|
|
e57f046d8a | Graduate mode and todo providers (#7052) | ||
|
|
beb65b21a8 |
.NET: [BREAKING] Graduate message injection out of experimental (#7044)
* Remove experiemental flags for MessageInjection component * Improve locking on message injection. |
||
|
|
875031ff56 | Fix broken sample | ||
|
|
fbaa346eec |
.NET: Python/.Net: Agent Harness blog post accompanying samples part 3 (#6741)
* Python/.Net: Agent Harness blog post accompanying samples part 3 * Delete inadvertently added files * Address PR feedback. * Rename files that are causing dotnet format failures * Address PR comment * Fix blog links |
||
|
|
3d17615b6e |
.NET: Replace MAF AG-UI abstractions with the AG-UI C# SDK abstractions (#6653)
* .NET: Replace internal AG-UI implementation with external ag-ui packages Remove the in-tree Microsoft.Agents.AI.AGUI sources and consume the external AG-UI .NET SDK packages (AGUI.Abstractions, AGUI.Formatting, AGUI.Protobuf, AGUI.Client, AGUI.Server) at 0.1.0-preview instead. - Microsoft.Agents.AI.Hosting.AGUI.AspNetCore keeps its own ASP.NET glue (MapAGUI / AddAGUI / SSE result) layered over the framework-agnostic AGUI.Server primitives (ToChatRequestContext / AsAGUIEventStreamAsync). - Migrate call sites to the options-based AGUIChatClient constructor and recover the originating AG-UI input via ChatOptions.TryGetRunAgentInput. - Multi-turn continuation flows through parentRunId + threadId on RawRepresentationFactory; shared state flows through RunAgentInput.State and is surfaced as StateSnapshotEvent raw representations. - Update samples, hosting/unit/integration tests, and central package versions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add migration README for removed Microsoft.Agents.AI.AGUI package Keep the package folder in place with a README explaining that the in-tree AG-UI protocol abstractions moved to the external AGUI.* NuGet packages, with a mapping of old namespaces to the new packages and a migration guide. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Roger Barreto <19890735+rogerbarreto@users.noreply.github.com> |
||
|
|
03a96faf43 |
.NET: Add security information to harness features xml docs (#6933)
* Add security information to harness features xml docs * Address PR comments |
||
|
|
331d17c5a1 |
.NET: fix: Require explicit TokenCredential in AddFoundryToolboxes (#6877)
* fix: require explicit TokenCredential in AddFoundryToolboxes The AddFoundryToolboxes extension methods now require callers to pass a TokenCredential explicitly rather than relying on an internally-created default credential. This makes the credential choice intentional and avoids non-deterministic credential probing in production environments. Breaking change (experimental API): - AddFoundryToolboxes(IServiceCollection, params string[]) becomes AddFoundryToolboxes(IServiceCollection, TokenCredential, params string[]) - AddFoundryToolboxes(IServiceCollection, Action?, params string[]) becomes AddFoundryToolboxes(IServiceCollection, TokenCredential, Action?, params string[]) - Azure.Identity package dependency removed from Foundry.Hosting library. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: simplify redundant generic type argument (IDE0001) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: avoid duplicate FoundryToolboxService registration Inject the AddFoundryToolboxes credential directly into the FoundryToolboxService factory and fail early if the service was already registered. This avoids registering TokenCredential in the host DI container while preserving a single toolbox service instance for both request handling and hosted startup. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
db80926f31 |
.NET: Improving DotNet samples (#6869)
* fix: resolve CA1873 in GitHubCopilotAgent by using LoggerMessage source generator Replace the direct logger.LogWarning() call (which eagerly evaluates string.Join()) with a [LoggerMessage]-generated extension method in GitHubCopilotAgentLogMessages.cs. Fixes build error: GitHubCopilotAgent.cs(580,13): error CA1873: Evaluation of this argument may be expensive and unnecessary if logging is disabled Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fixing more dotnet samples --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Ben Thomas <25218250+alliscode@users.noreply.github.com> |
||
|
|
551b44f04f |
.NET: Bump Azure.AI.Projects to 2.1.0-beta.4 (#6795)
* .NET: Bump Azure.AI.Projects to 2.1.0-alpha.20260629.1 Bumps Azure.AI.Projects beta.3 to alpha.20260629.1 and aligns transitive deps (System.ClientModel 1.14.0, Azure.Core 1.59.0, Msal 4.84.2). Adapts to renamed AgentSessionFiles APIs (Upload/GetAll/Delete, scoped GetAgentSessionFiles, SizeInBytes), AgentToolboxes (CreateVersion/Delete), and strongly typed toolbox tools (WebSearchToolboxTool, MCPToolboxTool). Adds azure-sdk public dev feed for prerelease restore. * Use positional arg for AgentSessionFiles.DeleteAsync cleanup * Move to Azure.AI.Projects 2.1.0-beta.4 (released beta) Swaps the alpha daily build for the published 2.1.0-beta.4. Drops the azure-sdk public dev feed since beta.4 and its deps are on nuget.org. Beta.4 requires Azure.Core 1.60.0, which cascades the 10.0.8 servicing packages (Microsoft.Bcl.AsyncInterfaces, System.Diagnostics.DiagnosticSource, System.Text.Json, System.Threading.Channels, Microsoft.Extensions.DependencyInjection.Abstractions, Microsoft.Extensions.Logging.Abstractions) to 10.0.9. * Reconcile Azure.Core 1.60.0 bump with merged main Reverts the over-eager System.Threading.Channels 10.0.9 bump back to 10.0.8 (it was not part of the Azure.Core 1.60.0 cascade and caused a net472 MSB3277 conflict against the 10.0.8 that Microsoft.Extensions.AI pulls). Drops the now-obsolete Azure.Core VersionOverride=1.59.0 in HostedWorkflowHandoff (added on main to satisfy AgentServer while the central pin was lower); the central pin is now 1.60.0 which already satisfies the >=1.59.0 floor, and the override was downgrading this project below sibling projects (CS1705). |
||
|
|
62f0024707 |
.NET: Foundry Hosting gracefully tolerates lacking user identity when run locally (#6870)
* .NET: Make Foundry Hosting resilient to missing user identity in local runs AgentFrameworkResponseHandler threw InvalidOperationException (surfaced as a 500 on every request) when the isolation-key provider returned null, which always happens locally because the platform x-agent-user-id header is absent. Running a hosted image outside Foundry therefore failed out of the box. The handler now branches on FoundryEnvironment.IsHosted: hosted stays strict (null identity is still a hard error), but non-hosted (local docker run / dotnet run) tolerates a null identity - per-user isolation is simply not triggered, the request proceeds with userId null (no partition), and no hosted context is stamped or validated. Because local runs no longer need a fallback, the sample-side DevTemporaryLocalUserIdProvider and AddDevTemporaryLocalContributorSetup are removed from Hosted_Shared_Contributor_Setup and all sample Program.cs files. To simulate distinct users locally, send an x-agent-user-id request header; the default provider reads it exactly as it reads the platform-injected value. The Memory sample smoke script now drives alice/bob against one container via that header. AGENT_NAME defaults added to Hosted-ChatClientAgent and Hosted-MemoryAgent so a hosted deploy (where AGENT_* is a reserved env var) does not crash at startup. Updates the two affected unit tests to assert the local-success path and amends ADR 0031. * Address review: correct isolation-guarantee and Memory-sample local docs - AgentFrameworkResponseHandler: note the null/local case is unscoped/shared, not fully partitioned per user. - HostedSessionIsolationKeyProvider XML docs: phrase the non-null UserId rule as a constraint on the returned-context case, since null is now allowed locally. - Hosted-MemoryAgent: the PerUser() memory scope requires a resolved user, so a local run needs an x-agent-user-id header; corrected the Program.cs comment and README (removed the inaccurate "shared bucket locally" claim). - Test: assert absence of any u-* per-user directory via a wildcard search rather than checking for a literal "u-" directory. |
||
|
|
c1e20632f7 |
.NET: Remove Experimental attribute from Skills API in Microsoft.Agents.AI (#6861)
* .NET: Remove Experimental attribute from Skills API in Microsoft.Agents.AI Closes microsoft/agent-framework#6835 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Restore MAAI001 suppression for Step07 sample (still uses ToolApproval experimental APIs) Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Keep bare NoWarn placeholder in Step01 and Step02 samples Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: SergeyMenshykh <SergeMenshikh@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> |
||
|
|
e56f34c521 |
.NET: [BREAKING] Add file editing tools and align FileAccess/FileMemory store API (#6807)
* Add support for editing to file access and memory plus renames * Address PR comments * Address PR comments |
||
|
|
f9b2fbb676 |
.NET: Foundry Hosting per-user session isolation and Responses v2 protocol fast-fail (#6832)
* Add per-agent and per-user session storage isolation for Foundry Hosting
Partitions hosted session and checkpoint files as {root}/a-{agentName}/u-{userId}/c-{contextId}.json so a container that serves multiple agents and multiple users cannot leak state across tenants. The user layer collapses to a-{agent}/c-{conv}.json when no x-agent-user-id is present (raw local). Adds a reject-style path-traversal guard (CWE-22) for the untrusted user id plus a resolve-and-assert-under-root containment check, and keeps the strict-resume 403 identity check as a second defense layer.
AgentSessionStore.GetSessionAsync/SaveSessionAsync take a required (nullable) userId so a caller can never silently persist a session unscoped; the handler resolves the user id before loading the session and threads it to both. Tool approvals ride in the session checkpoint (ToolApprovalIdMap to AgentSessionStateBag), so the partitioned path covers them and no separate approval store is needed. Renames the sample HOSTED_USER_ISOLATION_KEY env var to HOSTED_USER_ID and DevTemporaryLocalSessionIsolationKeyProvider to DevTemporaryLocalUserIdProvider. Documents the design in ADR 0031. Adds handler-driven multi-agent/multi-user file-system tests and store-level traversal/isolation tests.
* Fail fast with a clear 501 when hosted container is served responses protocol 1.0.0
A 2.0.0-only hosted image served container protocol 1.0.0 (no x-agent-foundry-call-id
header) previously threw and surfaced an opaque 500 on every request. It now returns a
clear 501 "unsupported_container_protocol_version" naming the required protocol.
* HostedProtocolCompatibility gate keyed on FoundryEnvironment.IsHosted plus
PlatformContext.CallId (the 2.0.0 exclusive marker); invoked before isolation resolution
* HostedProtocolCompatibilityTests unit coverage; AgentFrameworkResponseHandlerTests note
clarifies the non-hosted path
* UnsupportedProtocolHostedAgentTests integration test deploys a dedicated
it-unsupported-protocol agent as 1.0.0 and asserts the 501 (validated live on cace)
* TestContainer recognizes the unsupported-protocol scenario
* it-bootstrap-agents.ps1 placeholder default raised to responses 2.0.0 and adds the
it-unsupported-protocol agent; HostedAgentFixture protocol version is overridable
* Address PR review: whitespace protocol gate and InMemory store agent keying
* HostedProtocolCompatibility treats a whitespace-only x-agent-foundry-call-id as
absent (IsNullOrWhiteSpace) so a proxy injecting whitespace cannot bypass the gate;
unit test covers empty, spaces and tab
* InMemoryAgentSessionStore keys sessions by agent.Name (omitting the agent segment
when Name is unset), mirroring FileSystemAgentSessionStore, so session continuity
survives a recreated or transient agent rather than keying on the per-instance agent.Id
|
||
|
|
0d53d11bc6 |
.NET: [BREAKING] Bump Azure.AI.AgentServer to 2.0.0 protocol and migrate Foundry.Hosting (#6800)
* .NET: Bump Azure.AI.AgentServer to 2.0.0 protocol and migrate Foundry.Hosting Bumps Core .25->.26, Invocations .4->.5, Responses .5->.6 and adopts the 2.0.0 container protocol. Breaking change: IsolationContext (UserIsolationKey + ChatIsolationKey) is replaced by PlatformContext (UserIdKey from x-agent-user-id, CallId from x-agent-foundry-call-id). The per-chat key is gone; HostedSessionContext is now user-only and the per-request CallId is forwarded outbound to Foundry first-party services (toolbox/MCP). Also fixes a real call-id egress bug: AsyncLocal writes inside the streaming response iterator are reverted across yield boundaries, so the call id was dropped before the toolbox/MCP egress ran. The handler now re-applies HostedCallContext.CallId before each egress point. Adds HostedConversationKey to map a request to a stable MAF AgentSession via conversation_id, else the partition key embedded in previous_response_id, else the minted response id. This keeps store=false previous_response_id chains and conversation_id forks on a single hosted MAF session without using the container session id. Sample manifests bump the responses protocol to 2.0.0 (invocations stays 1.0.0). Integration tests split store/session semantics into HostedResponsesStoreConfigTests with its own scenario, read stored responses through the per-agent endpoint client, and inject the model deployment into the container. * Pin Azure.Core 1.59.0 for Hosted-Workflow-Handoff sample AgentServer 1.0.0-beta.26 (pulled transitively via Foundry.Hosting) requires Azure.Core 1.59.0. This sample disables transitive pinning and references Azure.Core directly, so override just this project to the SDK-required version without moving the solution-wide central pin. * Add guard test for request-scoped call-id cleanup Asserts HostedCallContext.CallId does not leak into the caller's execution context after CreateAsync's stream completes, while confirming the agent run still observed the call id. Documents the request-scoped contract and guards against stale-header leakage across requests handled on the same thread. * Refresh hosting READMEs for AgentServer 2.0 migration Updates stale docs to match the shipped code: the MemoryAgent README now describes the x-agent-user-id user-identity header (chat isolation key removed) feeding HostedSessionContext.UserId; the IntegrationTests README corrects the scenario count (six to eleven), adds the missing memory scenario row, and stops claiming all scenarios are skipped now that several are validated and active. * Add ADR 0030 superseding 0026 for AgentServer 2.0 platform context Documents the migration from ResponseContext.Isolation (UserIsolationKey/ChatIsolationKey) to ResponseContext.PlatformContext (UserIdKey/CallId): user-only HostedSessionContext, the request-scoped HostedCallContext call-id forwarded on egress, HostedConversationKey session keying, and removal of the PerChat/PerUserAndChat memory scopes. Marks ADR 0026 as superseded. * Add breaking-change v2.0-only disclaimer to package metadata Augments the package Description and adds PackageReleaseNotes stating this release targets the Foundry Responses container protocol v2.0 only, is not compatible with v1, and directs consumers to a previous release for the v1 protocol definition. * Address review comments: dead chat-key surface and weak test assertions Fixes the automated review findings: the MemoryAgent/AgentSkills .env.example now say one variable (only HOSTED_USER_ISOLATION_KEY remains); the MemoryAgent smoke script drops the unused ChatKey parameter and its call-site arguments; HostedConversationKey null test now exercises a real null (and whitespace); and the reuse-one-session test asserts an exact SessionCount of 1 instead of <= 1. |
||
|
|
4272d90051 |
Python/.Net: Agent Harness blog post accompanying samples part 2 (#6692)
* Add samples for the harness blog part 2 * Address PR comments * Fix blog links. * Address PR comments * Fix bug where mode was incorrectly defaulted when reading the mode before the first run. * Add reference to new sample readme |
||
|
|
a1c37b69e0 |
[Generated by SRE Agent] Clarify identifier security guidance (#6510)
Co-authored-by: Azure SRE Agent <noreply@microsoft.com> Co-authored-by: Evan Mattson <35585003+moonbox3@users.noreply.github.com> |
||
|
|
d5c5fb9d3d |
.NET: Enforce ApprovalRequiredAIFunction in GitHub Copilot provider via OnPreToolUse hook (#6674)
* .NET: Enforce ApprovalRequiredAIFunction in GitHub Copilot provider The GitHub Copilot SDK owns the tool-calling loop and invokes registered custom functions directly, so the standard FunctionInvokingChatClient approval round-trip never runs for this provider. As a result a tool wrapped in ApprovalRequiredAIFunction (only a marker) could execute without any Agent Framework approval. Add an agent-level onFunctionApproval callback and wrap approval-required tools in an ApprovalGatedAIFunction that enforces approval before invoking the underlying function. Secure-by-default: with no callback, or when the callback denies or throws, execution is denied. The gate forwards tool metadata (including the Copilot skip_permission flag) so it stays transparent to the SDK. This mirrors the Python provider's behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Propagate cancellation from GitHub Copilot approval callback Let OperationCanceledException propagate from the approval callback instead of swallowing it into a denial, so cooperative cancellation is honored. Other callback failures still deny by default. Added a unit test. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Enforce ApprovalRequiredAIFunction via Copilot SDK OnPreToolUse hook Replace the custom approval enforcement (ApprovalGatedAIFunction wrapper + onFunctionApproval callback) with the GitHub Copilot SDK's native OnPreToolUse hook, which the SDK already provides for pre-execution gating. When a tool wrapped in ApprovalRequiredAIFunction is registered and the caller hasn't supplied their own OnPreToolUse hook, the agent installs a default hook that returns "ask" for those tools (routing the decision to OnPermissionRequest) and defers (null) for all other tools, preserving today's behavior for non-approval tools. If the caller supplies their own OnPreToolUse hook, it takes precedence and they own approval handling; the agent logs a warning naming any approval-required tool that will not be auto-gated, and the behavior is documented. Adds an optional ILoggerFactory parameter for the warning. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Address PR review feedback on GitHub Copilot approval hook - Build the approval-required tool-name HashSet directly instead of via an intermediate List. - Remove the redundant MEAI001 NoWarn suppression (tests already suppress it via .editorconfig and the source project builds clean without it). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
7749823393 |
.NET: Sample fix (#6773)
* Fixing some samples and sample verification. * Workaround for continuation token moved to sample. * Address PR review comments: reset _stdinEof on reuse, null-guard modelId, format - WorkflowRunner: reset _stdinEof=false at start of ExecuteAsync so reused instances don't exit immediately on the next external request - 04_memory: throw clear InvalidOperationException when DefaultModelId is null rather than silently sending null to the Foundry Responses API - dotnet format: no code changes, formatting only Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Improving memory sample by not creating an agent just to get a chat client. --------- Co-authored-by: Ben Thomas <25218250+alliscode@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
daac8c15f3 |
.NET: Prefer HTTPS backends in Aspire DevUI (#6772)
Prefer allocated HTTPS endpoints when resolving Aspire DevUI backends and fall back to HTTP for existing services. Update the DevUI Aspire sample so WriterAgent exercises HTTPS redirection. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
231b35da55 |
.NET: Foundry hosted-agent toolbox OAuth consent support (#6718)
* .NET: Foundry hosted-agent toolbox OAuth consent support Add per-user OAuth (MCP CONSENT_REQUIRED) support for Foundry hosted agents. * Defer hard toolbox startup failures so a per-user OAuth-gated toolbox no longer bricks the container at startup (new Degraded status, retried per request). The container stays routable and surfaces consent on the first user request. * Emit the platform-canonical oauth_consent_request output item (instead of mcp_approval_request) for toolbox OAuth consent, matching the Python implementation and how the Foundry platform heads render consent. * Parse the toolbox CONSENT_REQUIRED (-32006) error and surface the consent link; resume by re-sending the prompt with no reply item needed. * Add the Hosted-Toolbox-AuthPaths OAuth consent REPL client sample that detects oauth_consent_request, prints the consent link, and re-sends. * Add tests for the consent parser, startup deferral, and oauth_consent_request emission. Fixes #6562 * .NET: Address review feedback on toolbox OAuth consent * Make RecomputeStatus the single source that refreshes ConsentRequiredToolboxNames from the pending-consent set, so a per-request marker that records consent via GetToolboxToolsAsync no longer leaves ConsentRequiredToolboxNames stale (which made ResolvePendingConsentsAsync skip surfacing it). * Surface lazy / per-request marker consent in the same request: after resolving markers the handler now emits oauth_consent_request + incomplete when a marker hit CONSENT_REQUIRED, instead of silently running without that toolbox. * Add FoundryToolboxService.GetPendingConsents() snapshot accessor. * Fix stale ToolboxConsentParser doc comment (mcp_approval_request -> oauth_consent_request). * .NET: Harden toolbox consent paths from code review * Thread-safety: GetPendingConsents() now returns an immutable snapshot rebuilt in RecomputeStatus under the lock, instead of enumerating the live _pendingConsents dictionary off-lock (which could throw under concurrent requests). * Resource leak: OpenToolboxAsync builds the endpoint Uri before allocating the HttpClient and now disposes the HttpClient when McpClient.CreateAsync throws (the unreachable/deferred case retried per request), not only when ListToolsAsync fails. * StrictMode now gates on the pre-registered ToolboxNames set rather than the opened-toolbox cache, so a registered-but-deferred toolbox is no longer rejected as unknown. * Sample REPL: the legacy approval-args consent fallback only reads the explicit consent_url key, so a normal function-tool approval carrying a URL argument is not misread as an OAuth consent request. * .NET: Scope per-request toolbox marker consent to the request Addresses review feedback that a marker-originated toolbox could leak into global scope after consent. GetToolboxToolsAsync now returns a request-scoped ToolboxResolution (tools or consent requirements) instead of recording marker consent in the container-global _pendingConsents and appending resolved tools to the service-wide Tools list. * Marker consent is surfaced as oauth_consent_request for the requesting turn only and collected in the handler's marker loop; it no longer injects tools into, or raises a consent prompt on, a later request that did not reference the marker. * Marker resolution no longer flips the container StartupStatus to ConsentRequired (per-request markers must not affect readiness, per the StartupStatus contract). * Remove the now-unused GetPendingConsents()/snapshot path; _pendingConsents is once again exclusively the pre-registered/startup consent set. * .NET: Add consent request-scoping UTs and an OAuth consent integration test Unit tests (Microsoft.Agents.AI.Foundry.Hosting.UnitTests): * New FoundryToolboxMarkerScopingTests proves per-request marker resolution is request-scoped: a marker consent is returned to the caller without mutating ConsentRequiredToolboxNames, StartupStatus, or the service-wide Tools cache, and marker-resolved tools are returned to the caller rather than injected globally (so a request with no marker sees neither the tools nor the consent). * Adds a test-only ToolboxOpener seam on FoundryToolboxService so the consent/tools resolution can be exercised without a live MCP proxy. Makes ToolboxOpenResult and CachedToolbox internal (CachedToolbox.Client nullable, guarded at dispose). Integration test (Foundry.Hosting.IntegrationTests): * New toolbox-oauth-consent scenario wired into the TestContainer (pre-registers a Foundry toolbox via AddFoundryToolboxes from IT_TOOLBOX_NAME), a ToolboxOAuthConsentHostedAgentFixture, and a ToolboxOAuthConsentHostedAgentTests that invokes the deployed agent and asserts the consumer captures an oauth_consent_request consent link (container stays routable, no 424). Skipped by default per the IT convention; documents the consent-gated toolbox prerequisite. * Adds the scenario to it-bootstrap-agents.ps1 and the README scenario table. |
||
|
|
e3b64fdc47 |
.NET: [BREAKING] Make all AgentSkillsProvider tools require approval by default (#6729)
* Make all AgentSkillsProvider tools require approval by default - Wrap all tools (load_skill, read_skill_resource, run_skill_script) with ApprovalRequiredAIFunction unconditionally - Add ReadOnlyToolsAutoApprovalRule and AllToolsAutoApprovalRule static properties following the FileAccessProvider pattern - Remove ScriptApproval from AgentSkillsProviderOptions and UseScriptApproval from AgentSkillsProviderBuilder - Add Agent_Step07_SkillsAutoApproval sample Closes #6727 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add UseToolApproval to hosted AgentSkills scenarios Wire AllToolsAutoApprovalRule into the integration test container and the Hosted-AgentSkills sample so skill tools execute without blocking on approval when no interactive approval handler is configured. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add API compatibility suppressions for removed ScriptApproval members Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: SergeyMenshykh <SergeMenshikh@outlook.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
3a5bbb5f8e |
.NET: Add DeclarativeWorkflowJsonOptions for AOT-safe declarative workflow checkpointing (#6745)
* Add experimental DeclarativeWorkflowJsonOptions for AOT-safe declarative workflow checkpointing * Address PR comments |
||
|
|
336a19fd32 |
.NET: .NET samples: migrate coding samples to Foundry-first AIProjectClient (#6557)
* Migrate 02-agents/Agents samples to AIProjectClient (Foundry) Replace AzureOpenAIClient with AIProjectClient as the AI provider in all 02-agents/Agents samples, aligning with the Foundry-first approach. Changes: - 19 Program.cs files migrated to use AIProjectClient.AsAIAgent() - 19 .csproj files updated (Azure.AI.OpenAI -> Microsoft.Agents.AI.Foundry) - Environment variables: AZURE_OPENAI_* -> FOUNDRY_PROJECT_ENDPOINT/FOUNDRY_MODEL - Updated description comments to reflect Foundry backend - Provider-specific samples in AgentsWithFoundry/ intentionally unchanged Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Migrate 02-agents/AgentSkills, AgentWithMemory, AgentWithRAG, AgentOpenTelemetry to AIProjectClient Replace AzureOpenAIClient with AIProjectClient as the AI provider. Environment variables: AZURE_OPENAI_* -> FOUNDRY_PROJECT_ENDPOINT/FOUNDRY_MODEL. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Migrate 03-workflows samples to AIProjectClient (Foundry) Replace AzureOpenAIClient with AIProjectClient as the AI provider in all 03-workflows samples that use an AI model. Environment variables: AZURE_OPENAI_* -> FOUNDRY_PROJECT_ENDPOINT/FOUNDRY_MODEL. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix PR 6557 build breaks and align Foundry client usage - Add explicit Azure.Identity package references to migrated sample projects that use DefaultAzureCredential - Fix AgentWithRAG_Step05_Neo4jGraphRAG to use AIProjectClient.AsAIAgent() with ChatOptions.ModelId instead of AIProjectClient.AsIChatClient() - Keep migrated samples on AIProjectClient pattern (no FoundryAgent/AzureOpenAIClient) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR 6557 Foundry review follow-ups Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix post-rebase sample build and format regressions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Updates to fix issues from switching to Responses. * Fixing more tests and deleting checkpoint directories created for samples. * Fixing formatting * Restore DefaultAzureCredential warnings in agents samples Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
a9e5f6d798 |
.NET: .NET Foundry: add CreateMcpTool projectConnectionId overload (#6703)
* .NET Foundry: add CreateMcpTool projectConnectionId overload Adds FoundryAITool.CreateMcpTool(serverLabel, serverUri, projectConnectionId, ...) so hosted MCP tools can authenticate through a Foundry project connection, matching the Python FoundryChatClient.get_mcp_tool(..., project_connection_id=...) factory. The connection id is applied via the McpTool.ProjectConnectionId extension that ships in Azure.AI.Projects.Agents (patches project_connection_id), already referenced by the Foundry package. Includes unit tests and sample/README guidance plus the existing FromResponseTool workaround. * Fold projectConnectionId into existing CreateMcpTool overload Replaces the separate project-connection overload with an optional projectConnectionId parameter on the existing serverUri CreateMcpTool, so all settings (authorizationToken, headers, allowedTools, ...) stay available and there is no positional overload ambiguity. Adds tests for the default (no connection) path and for preserving other settings. Sample/README now show only the supported overload. |
||
|
|
15df1152fc |
.NET: Add sample for per-run refreshable MCP authentication headers (#6624)
* Add sample for per-run refreshable MCP authentication headers Adds a Foundry RAPI sample that attaches per-run, refreshable authentication headers to MCP requests using existing primitives: a DelegatingHandler on the MCP transport's HttpClient plus an AsyncLocal run scope. The same agent runs under two contexts, each minting a fresh token, proving the header is per run rather than bound at agent or connection creation time. The handler attaches the bearer only over HTTPS to the MCP server's own origin, logs the non-secret label only, disables cookies, and checks certificate revocation. The README covers security considerations and production notes. Fixes #1631 * Address PR review: harden redirect handling, nest-safe scope, README env vars Disable AllowAutoRedirect on the shared handler so a redirect cannot carry the bearer past the origin check. Save and restore the prior run scope instead of clearing to null so the helper is safe under nesting. Note the Foundry env vars in the samples folder README row and update the sample README security notes. |
||
|
|
88f0b23fb0 |
.NET: Change A2A default session store to NoopAgentSessionStore (#6635)
* Change A2A default session store to NoopAgentSessionStore Align the A2A hosting layer default session store with the AG-UI sibling by using NoopAgentSessionStore, making persistence an explicit opt-in choice. Update samples to document how to register a persistent session store for multi-turn conversations. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify test name to specify session store default Rename test to FallsBackToNoopSessionStoreDefaultAsync to avoid implying all stores default to noop (task store still uses InMemory). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
7b6f582b13 |
Python: Agent Harness blog post accompanying samples part 1 (#6605)
* Add samples for harness blog post part 1 * Add readme for python samples * Update python instructions to match dotnet instructions * Address PR comments * Add link to blog posts * Fix blog post naming. * Add more blog post links |
||
|
|
098e521586 |
.NET: Bring Hosted-Toolbox sample to parity with sibling hosting samples (#6633)
* Bring Hosted-Toolbox sample to parity with sibling hosting samples Adds the standard scaffolding files (.env.example, agent.yaml, agent.manifest.yaml, Dockerfile, Dockerfile.contributor) that every other 04-hosting Foundry sample ships but Hosted-Toolbox lacked. Fixes the toolbox name environment variable: reads TOOLBOX_NAME instead of the platform reserved FOUNDRY_TOOLBOX_NAME so it survives agent create, and aligns the default to my-toolset. Rewrites the README to the standard section layout with PowerShell fenced commands, and adds Using-Samples READMEs documenting why the client REPLs exist. Renames Azure AI Foundry to Foundry across the 04-hosting sample READMEs and comments for consistent product naming. * Address PR review: accurate docs and TOOLBOX_NAME in ToolboxMcpSkills - SimpleAgent README: correct the demo banner to the real per-agent URL the client prints (https scheme and the /api/projects/<project> segment). - Hosted-Toolbox Program.cs: move FOUNDRY_MODEL out of the Required block into Optional since it has a gpt-4o default and an AZURE_AI_MODEL_DEPLOYMENT_NAME fallback. - Hosted-ToolboxMcpSkills: switch the toolbox name from the reserved FOUNDRY_TOOLBOX_NAME to TOOLBOX_NAME across Program.cs, .env.example, agent.yaml, agent.manifest.yaml and README so it is deployable via the manifest, matching the other toolbox samples. |
||
|
|
89d19a2370 |
.NET: Migrate 01-get-started samples to Foundry as canonical default (#6555)
* Migrate 01-get-started samples to Foundry as canonical default Change canonical provider from Azure OpenAI to Microsoft Foundry Responses API: Code changes: - Updated all 01-get-started samples (01_hello_agent, 02_add_tools, 03_multi_turn, 04_memory, 06_host_your_agent) to use FoundryAgent or AIProjectClient.AsAIAgent() - Updated environment variables: AZURE_OPENAI_* → FOUNDRY_PROJECT_ENDPOINT/FOUNDRY_MODEL - Updated .csproj files to reference Microsoft.Agents.AI.Foundry instead of Azure.AI.OpenAI - Added warning comments about DefaultAzureCredential production usage - 05_first_workflow unchanged (workflow pattern only, no AI model) Documentation changes: - Updated AGENTS.md Default provider section to reflect Foundry as canonical - Updated code example to use FoundryAgent constructor pattern - Updated env var documentation Note: 04_memory (AIContextProvider sample) extracts IChatClient from FoundryAgent to maintain the memory pattern while using Foundry backend. All samples verified to build successfully. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR 6555 review feedback and format failures - Add Microsoft.Agents.AI.Foundry using to AGENTS.md Foundry snippet - Update verify-samples GetStarted env vars to FOUNDRY_PROJECT_ENDPOINT/FOUNDRY_MODEL - Remove unnecessary usings flagged by dotnet format in 01_get_started samples Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Switch 01-get-started samples from FoundryAgent to AIProjectClient.AsAIAgent() Use AIProjectClient.AsAIAgent() as the canonical pattern for all 01-get-started samples. Reserve FoundryAgent only for samples that specifically demonstrate the Foundry-managed (prompt) agent — i.e. 02-agents/AgentsWithFoundry/. Changes: - 01_hello_agent, 02_add_tools, 03_multi_turn, 06_host_your_agent: swap FoundryAgent constructor for AIProjectClient.AsAIAgent(model, instructions) - 04_memory: get IChatClient via AIProjectClient.AsAIAgent(options).GetService() instead of extracting from a throwaway FoundryAgent - AGENTS.md: update default-provider snippet and note on when to use FoundryAgent Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
54a30571aa |
Dotnet - Add support for Foundry Adaptive evals (#6267)
* .NET: feat(evals): RubricScore type + EvalScoreResult.Dimensions Adds the core rubric-evaluator surface that mirrors the Python work in PR #6101 (commit e45b934cc). Provider-agnostic types only — no Foundry coupling. Subsequent commits will wire these into FoundryEvals. - RubricScore: per-dimension score record (Id, Score?, Applicable, Weight, Reason). - EvalScoreResult.Dimensions: optional init-only list of RubricScore. Null for non-rubric (built-in) evaluators. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: feat(evals): GeneratedEvaluatorRef + assertion helpers Adds the provider-agnostic surface for referencing a pre-existing rubric evaluator and gating CI on per-item / per-dimension thresholds. Mirrors Python PR #6101 commits e5830dd7f (ref type) and 4bc60462d (asserts). - GeneratedEvaluatorRef: name + optional version/display-name, plus a Latest(name) factory for versionless refs (discouraged for CI; consumers should warn at run time). - AgentEvaluationResults.AssertScoreAtLeast: walks DetailedItems[].Scores, optionally filtered by evaluator name, recurses into SubResults. - AgentEvaluationResults.AssertDimensionScoreAtLeast: walks each score's Dimensions list, skips non-applicable dimensions by default, supports requireApplicable to flip that, recurses into SubResults. - AgentEvaluationResults.AssertNoFailedItems: walks DetailedItems for fail/error statuses, recurses into SubResults. All helpers throw InvalidOperationException (matches existing AssertAllPassed). Truncates offender lists to the first 5 with a '+N more' suffix to keep CI output readable, mirroring the Python helpers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: feat(foundry-evals): accept GeneratedEvaluatorRef in evaluators= Adds FoundryEvaluatorSpec, a readonly-struct union with implicit conversions from both string and GeneratedEvaluatorRef so call sites can mix built-in evaluator names with rubric evaluator references: var evals = new FoundryEvals( projectClient, model, new GeneratedEvaluatorRef("policy-rubric", "3"), FoundryEvals.Relevance, FoundryEvals.Coherence); FoundryEvals constructors (3 overloads), EvaluateTracesAsync, and EvaluateFoundryTargetAsync now take FoundryEvaluatorSpec[]/params instead of string[]/params. Existing call sites using string literals or string[] keep working unchanged via implicit conversion. FoundryEvalConverter.BuildTestingCriteria emits the documented Foundry wire format for rubric refs: { "type": "azure_ai_evaluator", "name": <DisplayName ?? Name>, "evaluator_name": <Name>, "evaluator_version": <Version>, // omitted when null "initialization_parameters": { "deployment_name": <model> }, "data_mapping": { conversation arrays, optional tool_definitions } } WireTestingCriterion gains an optional EvaluatorVersion field. Rubric refs are preserved through FilterToolEvaluators (tool-aware but not tool-required) and ignored by FindMissingGroundTruthEvaluators. A versionless ref emits a Trace.TraceWarning at criterion-build time so CI authors notice the floating version (mirrors the Python warning). Adds 6 new Foundry unit tests (3 BuildTestingCriteria rubric paths, 1 FindMissingGroundTruthEvaluators, 1 FilterToolEvaluators preservation, 1 mixed-order). 369/369 Foundry tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: feat(foundry-evals): parse rubric dimension_scores into RubricScore Adds FoundryEvals.ParseRubricScores, called per result inside ParseDetailedItem. Each EvalScoreResult now populates Dimensions when the evaluator's sample carries a rubric breakdown. Accepts three shapes for forward compatibility with provider SDK iterations: 1. sample.properties.dimension_scores (canonical Foundry runtime shape) 2. sample.properties.rubric_scores (preview/legacy key) 3. top-level sample.dimension_scores / sample.rubric_scores (defensive fallback) Entries missing 'id', 'weight', or 'applicable' are skipped without invalidating well-formed siblings. Non-applicable dimensions may omit 'score' (parsed as null). Adds 6 unit tests covering canonical and legacy keys, top-level fallback, no-match returns null, malformed-entry skipping, and the non-applicable null-score path. 375/375 Foundry tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: feat(samples): Evaluation_FoundryRubric end-to-end sample Adds dotnet/samples/05-end-to-end/Evaluation/Evaluation_FoundryRubric mirroring the Python evaluate_with_rubric_sample.py: - Fetches a pre-existing Foundry agent via AgentAdministrationClient (GetAgentAsync for latest, GetAgentVersionAsync when FOUNDRY_AGENT_VERSION is pinned). - References a rubric evaluator by GeneratedEvaluatorRef(name, version); falls back to GeneratedEvaluatorRef.Latest(name) with the documented floating-version warning. - Mixes the rubric with FoundryEvals.Relevance and FoundryEvals.Coherence in a single FoundryEvals run (implicit string-and-ref conversion). - Prints per-dimension breakdowns from EvalScoreResult.Dimensions for each item. - Demonstrates a CI quality gate with AssertDimensionScoreAtLeast("general_quality", 3.0). Documents the FOUNDRY_PROJECT_ENDPOINT footgun (must be project-scoped URL .../api/projects/<project>, not the bare Azure OpenAI endpoint) and the Eval-Definition-vs-Rubric-Evaluator distinction in the README. Ships a .env.example with the FOUNDRY_* variables. Registers the project in agent-framework-dotnet.slnx and cross-links from the sibling Evaluation_Multimodal / Evaluation_ExpectedOutputs READMEs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(foundry-evals): harden FoundryEvals public surface for review Address PR #6267 review comments on the .NET FoundryEvals integration: - Add source-compat overloads accepting `string[] evaluators` for `FoundryEvals` ctor, `EvaluateTracesAsync`, and `EvaluateFoundryTargetAsync` so existing callers passing string arrays keep compiling unchanged. New overloads forward via a private `ToSpecs` helper that wraps each name through the implicit `string -> FoundryEvaluatorSpec` conversion. - Guard against `default(FoundryEvaluatorSpec)` entries (both `BuiltinName` and `GeneratedRef` null) that would NRE the downstream converter. Adds `FoundryEvaluatorSpec.IsValid` / `EnsureValid` plus an internal `EnsureAllSpecsValid` helper, wired into the main ctor and both static evaluation entry points. - Add 6 unit tests covering the new validation surface. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(sample): set ExitCode=1 when rubric dimension gate trips PR #6267 review comment: the FoundryRubric sample swallowed the AssertDimensionScoreAtLeast failure, so a CI run that included it as a quality gate would still exit 0 even when the rubric regressed. Set `System.Environment.ExitCode = 1` in the catch so CI fails while still letting the rest of the sample's logging complete cleanly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(foundry-evals): search typed Sample directly for rubric scores PR #6267 review comment: `_extract_rubric_scores` only searched the `properties` dict when the sample exposed one. When the Azure AI Projects typed SDK returns a Sample object that puts `dimension_scores` / `rubric_scores` directly on the instance (no `properties` wrapper), we missed them and surfaced no per-dimension scores. Add an `else: containers.append(sample)` branch so non-dict typed samples are also inspected for the score keys. Covered by two new tests: one with `dimension_scores` directly on a typed Sample without a `properties` wrapper, and one with the legacy `rubric_scores` key in the same shape. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * test(evals): cover assert_score_at_least and assert_no_failed_items PR #6267 review comments: both assertion helpers shipped without unit tests. Add `TestAssertScoreAtLeast` (above threshold, below w/ offenders, evaluator filter, sub_results recursion) and `TestAssertNoFailedItems` (all passing, failed/errored statuses, sub_results recursion) with a shared `_score_results` fixture builder. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(samples): remove dead rubric-evaluator doc link from FoundryRubric sample The Azure AI Foundry rubric evaluator concept doc page has not yet been published, so the link in the sample README and Program.cs comment 404s. Drop the references until the upstream doc is live. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Address PR 6267 review nits Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Ben Thomas <25218250+alliscode@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> |
||
|
|
92823e9e61 |
.NET: [BREAKING] Require approval for FileAccessProvider tools with auto-approval rules (#6521)
* Require approval for file-access * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Rename DisableToolApproval to DisableToolAutoApproval for clarity * Fix broken suggestion. * Address PR comments and fix build issue. * Update dotnet/src/Microsoft.Agents.AI.Harness/HarnessAgentOptions.cs Co-authored-by: Roger Barreto <19890735+rogerbarreto@users.noreply.github.com> --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Roger Barreto <19890735+rogerbarreto@users.noreply.github.com> |
||
|
|
015e3bcd3b |
.NET: Enabling sequential orchestration to pass entire conversation or only previous output. (#6554)
* Fix sequential workflow input forwarding Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Make sequential workflow context configurable Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify sequential chain-only behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify sequential output messaging Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Ben Thomas <25218250+alliscode@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
1fc57c45ee |
.NET: Bump Azure.AI.Projects to 2.1.0-beta.3 (#6542)
* Bump Azure.AI.Projects to 2.1.0-beta.3 Updates Azure.AI.Projects from 2.1.0-beta.2 to 2.1.0-beta.3, together with the transitive Azure.Core (1.56.0 to 1.57.0) and System.ClientModel (1.12.0 to 1.13.0) pins that beta.3 requires (beta.3 forces System.ClientModel 1.13.0.0 via Azure.Core 1.57.0). Migrates the affected samples and integration test to the beta.3 surface: * MemorySearch sample: MemorySearchToolCallResponseItem renamed to MemorySearchToolCall, Results renamed to Memories, MemoryItem indirection removed. * AgentSkills sample: skill provisioning/download API redesigned to a version based model (CreateSkillVersionFromFiles, GetSkillContent which now downloads and unzips), removing manual ZIP handling. * Session files integration test: GetSessionFilesAsync now returns an async collection of SessionDirectoryEntry and renames the sessionId parameter to agentSessionId. * Stream session file listing and short-circuit in integration test Avoids materializing the entire session directory listing into a List. The test now streams GetSessionFilesAsync and breaks as soon as the expected entry is found, then asserts it was located. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
1519e50f2f |
Harden archive extraction guard so path containment is statically recognized (#6564) (#6565)
The Hosted-AgentSkills sample and its mirrored unit-test helper gated ZIP extraction on `StartsWith(destinationRoot)` OR `Equals(destinationRoot)`. The second branch left an acceptance path not covered by the containment check, so static analysis could not prove the extraction sink stays within the destination. Make the single resolved-path StartsWith check the only gate to extraction in both files and add a nested-entry regression test. Closes #6564 |
||
|
|
fcc5576b04 |
.NET: feat(dotnet): Add LocalCodeAct package for local Python execution (#6105)
* feat(dotnet): Add LocalCodeAct package scaffold Create Microsoft.Agents.AI.LocalCodeAct package with: - Project file with embedded Python resources - ExecutionMode enum (Subprocess only) - ProcessExecutionLimits record - FileMount record and FileMountMode enum - README.md documentation - Embedded Python runner and validator scripts This is the .NET equivalent of the Python agent-framework-local-codeact package. Next: Implement process bridge and tool integration. * feat(dotnet): Add embedded Python runner and validator Copy Python runner and validator scripts from the Python implementation as embedded resources for the .NET package. * feat(dotnet): Add CodeValidator wrapper Implement CodeValidator.cs that: - Extracts embedded Python validator script to temp file - Invokes Python validator with JSON request - Passes custom allow/block lists - Throws CodeValidationException on failures - Cleans up temp files Uses the embedded Resources/validator.py for AST validation. * feat(dotnet): Add LocalExecuteCodeFunction Implement LocalExecuteCodeFunction as AIFunction: - Accepts Python executable path (required) - Registers host tools for code to call - Validates code via CodeValidator if custom lists provided - Executes via ProcessBridge - Converts result dict to ChatMessage list - Builds dynamic description including available tools Matches Python LocalExecuteCodeTool functionality. * feat(dotnet): Add LocalCodeActProvider Implement AIContextProvider that: - Injects execute_code tool into context - Adds CodeAct instructions - Enforces single-provider-per-agent via StateKeys - Wraps LocalExecuteCodeFunction lifecycle Minimal provider implementation matching Python LocalCodeActProvider. * feat(dotnet): Add tests and sample for LocalCodeAct Add unit tests: - LocalExecuteCodeFunctionTests (4 tests) - ProcessExecutionLimitsTests (2 tests) - FileMountTests (2 tests) Add sample: - LocalCodeAct/Program.cs - Demonstrates provider and function usage - LocalCodeAct/README.md - Documentation and safety warnings Tests verify basic construction, metadata, and disposal. Sample shows provider creation, function setup, and configuration. Note: Build requires .NET 10 SDK per global.json. * feat(dotnet): Add LocalCodeAct sample project Add sample demonstrating: - LocalCodeActProvider creation and configuration - LocalExecuteCodeFunction direct usage - Execution modes and file mount configuration - Safety warnings and prerequisites Includes project file and README with security guidance. * feat(dotnet): Add file mount support and integration tests - Added FileMountHelper.cs for file mount normalization, snapshot, and capture - Updated LocalExecuteCodeFunction to support file mounts parameter - Added file snapshot before/after execution with capture logic - Updated LocalCodeActProvider to pass file mounts through - Created comprehensive IntegrationTests.cs with 10 test cases: - Simple code execution - Timeout handling - Syntax error handling - Blocked import validation - Blocked builtin validation - Custom allowed imports - File mount read/write with capture - Stdout capture - Provider tool injection All features from Python implementation now ported to .NET. * Rewrite .NET LocalCodeAct to address all PR review comments Complete rewrite that follows the Hyperlight package conventions (see Microsoft.Agents.AI.Hyperlight) and addresses all 24 review comments on PR #6105: Architectural fixes: * LocalCodeActProvider now uses options-class constructor pattern matching HyperlightCodeActProvider. * Override of ProvideAIContextAsync uses the correct (InvokingContext, CancellationToken) signature returning ValueTask<AIContext>. * ExecuteCodeFunction follows the AIFunction Name/Description/JsonSchema property pattern with InvokeCoreAsync override. * Provider exposes AddTools/GetTools/RemoveTools/ClearTools and AddFileMounts/GetFileMounts/RemoveFileMounts/ClearFileMounts CRUD methods, with snapshot-at-invocation semantics under a lock. Runtime/security fixes: * Subprocess IPC uses JsonObject/JsonNode end-to-end (no Dictionary<string, object?> casts that broke under JsonElement deserialization). * Validator runs in its own subprocess with a dedicated timeout (ProcessExecutionLimits.ValidationTimeoutSeconds), never reuses the runner script. * Validation enabled by default; can be opt-ed out via ValidationEnabled = false. * validator.py has a __main__ entrypoint that reads JSON from stdin and exits with structured errors. * validator.py is now compatible with Python 3.9+ (Match nodes added conditionally). * call_id parsed as long to match Python id(kwargs) range. Other: * README rewritten with valid C# syntax (options-class, FileMount constructor) and accurate descriptions of validator and file capture behavior. * Added integration tests that exercise the real subprocess and validator (skipped gracefully when python3 is not on PATH). * All 18 tests pass (15 unit + 3 integration) across net8/net9/net10. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Sync embedded validator.py with Python package allow-list enforcement The embedded Python validator script used by the .NET LocalCodeAct package now enforces the builtin allow-list, matching the latest behavior of agent_framework_local_codeact._validator. Names that are real Python builtins must appear in the allow-list, while unknown names (user-defined functions, registered tools) remain allowed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Hosted-LocalCodeAct foundry hosted-agent sample Mirrors the Python foundry_hosted_agent.py sample for the local-codeact package: registers compute and fetch_data as sandbox-only host tools on LocalCodeActProvider so the model only sees execute_code and reaches them via await call_tool(...). Includes the standard hosted-agent supporting files (agent.yaml, agent.manifest.yaml, Dockerfile, Dockerfile.contributor, .env.example, README.md) and installs python3 in the container images so the embedded runner and validator can execute. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(local-codeact-dotnet): sync validator os.* allow-list with Python Mirror the Python package change: the embedded validator.py invoked by the .NET ProcessBridge replaces the os.* deny-list with an allow-list of {environ, path}. Add allowed_os_attrs parameter to validate_code and _CodeValidator, and surface it via the stdin JSON request schema so the .NET host can opt in to a broader allow-list when needed. Default behavior tightens to match the documented contract: any os.* attribute outside {environ, path} (for example os.listdir, os.open, os.getcwd) is rejected. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(local-codeact-dotnet): address review + tighten validator - validator.py: enforce os.* allow-list on `from os import X` so names like `system`, `getcwd` cannot bypass the visit_Attribute restriction. - ProcessBridge.ConfigureEnvironment: document that null Environment inherits the parent env (matching real behavior) and update the public LocalCodeActProviderOptions.Environment doc to describe the explicit empty-dictionary opt-in for a scrubbed environment. - Tests: * FileMountHelperTests covers per-file, per-mount, and total capture-limit branches that return TextContent omissions. * Integration tests cover unknown-tool dispatch error, tool throwing exception, and CodeValidator timeout that kills the process and raises CodeValidationException. - Sample: drop unused `Microsoft.Agents.AI.Foundry` using in Hosted-LocalCodeAct/Program.cs to satisfy IDE0005 check-format. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * chore(local-codeact-dotnet): remove stale orphan sample The dotnet/samples/LocalCodeAct/ scaffolding sample referenced APIs that don't exist in the current package (`ExecutionMode`, FileMount object-initializer syntax, the old LocalExecuteCodeFunction constructor signature, function.Metadata.*), produced a long list of check-format violations (CHARSET, IMPORTS, IDE0073 header, IDE0005 unused using, IDE1006 Async suffix, RCS1037 trailing whitespace), and did not match any of the documented sample layouts. The hosted-agent example at dotnet/samples/04-hosting/FoundryHostedAgents/responses/Hosted-LocalCodeAct is the supported entry-point sample for this package. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * style(local-codeact-dotnet): satisfy check-format rules - Add UTF-8 BOM to source files (CHARSET) - Remove unused using directives (IDE0005) - Simplify type names (IDE0001/IDE0002/IDE0090) - Rename static field JsonOptions -> s_jsonOptions (IDE1006) - Rename static field SyncRoot -> s_syncRoot (IDE1006) - Add missing this. qualifications in ProcessBridge (IDE0009) - Remove unused _options field from LocalCodeActProvider (IDE0052) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(local-codeact-dotnet): wire hosted sample into solution Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(local-codeact-dotnet): sync embedded Python scripts Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(local-codeact-dotnet): exercise Python integration on Windows Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Address LocalCodeAct API review feedback Move the required Python executable path to LocalCodeAct constructors, invert the validation flag default, and apply small project/file mount cleanup suggestions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Address LocalCodeAct concurrency review Surface unauthorized mount traversal errors and use concurrent provider registries for LocalCodeAct tool and file mount CRUD operations. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Simplify LocalCodeAct function wrappers Use AIFunctionFactory-created inner functions for LocalCodeAct execute_code wrappers and remove redundant script cache and JsonNode cloning logic. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Update LocalCodeAct factory result tests Handle JsonElement result values produced by AIFunctionFactory delegation in LocalCodeAct execute_code integration tests. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
6cc7ddb73e |
.NET: Integrate LoopAgent into HarnessAgent with TodoCompletionLoopEvaluator (#6544)
* Add LoopAgent to Harness with TodoEvaluator sample * Address PR comments * Fix build error |
||
|
|
39f4b5ec72 | Align function tool names for BackgroundAgent and FileMemory between python and .net (#6550) | ||
|
|
4d492614a9 |
.NET samples: structural alignment changes (#6485)
* Rescope dotnet provider samples cleanup Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix provider samples README link Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
5e830f4dc9 |
.NET: Only use the output from the last message for structured output (#6499)
* Only use the output from the last message for structured output * Address PR comments * Address PR comment * Address PR comments |
||
|
|
3f77c555cf |
.NET: [BREAKING] Align FileAccess tools with Python; add directory discovery and recursive search (#6474)
* Align FileAccess with python and improve functionality * Addressing PR comments |
||
|
|
c79f886dc3 |
.NET: Align Foundry sample environment variables and credentials. (#6422)
* dotnet: refresh Foundry sample guidance Carry forward the still-relevant sample guidance and Foundry-specific documentation fixes from the old stacked sample migration work, adapted to the current repo layout and policy. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * dotnet: rename Foundry sample env vars Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * dotnet: remove persistent provider sample Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * dotnet: drop SAMPLE_GUIDELINES.md from this PR Defer the guidelines doc and its cross-link to a follow-on PR to avoid broken-link failures in CI. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * dotnet: add DefaultAzureCredential warning to remaining samples Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * dotnet: address PR review feedback Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |
||
|
|
12ce099165 |
.NET: Add LoopAgent capability for Harnesses (#6384)
* Add LoopAgent capability for Harnesses * Address PR comments. * Add support for returning user messages and response aggregation * Support fresh context per iteration with input sessions via cloning * Add ability to receive newly created sessions via callback * Address PR comments * Add judge criteria * Address PR comments |
||
|
|
8e1998ddcb |
.NET: Adds Valkey to chat message history - issue 5445 (#5542)
* Adds Valkey to chat message history * Address review: switch to Valkey.Glide, add options class, remove context provider - Switch from StackExchange.Redis to Valkey.Glide 1.1.0 (official Valkey .NET client) - Extract optional params into ValkeyChatHistoryProviderOptions - Add JsonSerializerOptions support, remove [RequiresUnreferencedCode] - Make MaxMessages/MaxMessagesToRetrieve readonly via options - Remove ValkeyContextProvider (overlaps with ChatHistoryMemoryProvider + MEVD) - Remove ValkeyProviderScope (only used by context provider) - Remove connection string constructors (caller manages IConnectionMultiplexer) - Update samples to use new API and gpt-5.4-mini * Use type-safe JsonSerializer overloads, remove suppress attributes Use JsonSerializerOptions.GetTypeInfo() for Serialize/Deserialize calls to enable NativeAOT/trimming compatibility without suppress attributes. Default to AgentAbstractionsJsonUtilities.DefaultOptions when no options provided. Signed-off-by: Matthias Howell <matthias.howell@improving.com> * Update READMEs: remove context provider references Remove ValkeyContextProvider and long-term memory references from sample READMEs since the context provider was removed from this PR. Simplify Valkey server requirements (no search module needed for chat history). Signed-off-by: Matthias Howell <matthias.howell@improving.com> * Apply suggestion from @westey-m * Fix formatting (dotnet format) Signed-off-by: Matthias Howell <matthias.howell@improving.com> * Update dotnet/src/Microsoft.Agents.AI.Valkey/Microsoft.Agents.AI.Valkey.csproj Co-authored-by: Roger Barreto <19890735+rogerbarreto@users.noreply.github.com> --------- Signed-off-by: Matthias Howell <matthias.howell@improving.com> Co-authored-by: Matthias Howell <matthias.howell@yoppworks.com> Co-authored-by: westey <164392973+westey-m@users.noreply.github.com> Co-authored-by: Roger Barreto <19890735+rogerbarreto@users.noreply.github.com> |
||
|
|
dd29f9aa65 |
.NET: Hosted Agent Sample - Toolbox with various Auth (#5777) (#6018)
* .NET: Add Hosted-Toolbox-AuthPaths sample and auto-map /readiness with toolbox health gating (#5777) Add a new hosted agent sample demonstrating five MCP tool authentication paths (API key, agent MI, project MI, custom OAuth, literal token) via a Foundry Toolbox. Package changes (Microsoft.Agents.AI.Foundry.Hosting): - MapFoundryResponses now auto-maps GET /readiness via MapHealthChecks, idempotent across Tier 1/2 (AgentHost, already mapped) and Tier 3 (WebApplication, gap filled). - AddFoundryResponses registers AddHealthChecks() so the pipeline is available. - AddFoundryToolboxes registers FoundryToolboxHealthCheck on the /readiness aggregate, gating readiness on pre-registered toolbox startup outcome (per spec section 3.1). - FoundryToolboxService now exposes StartupStatus and FailedToolboxNames properties. New types: - FoundryToolboxStartupStatus (public enum): Pending, Healthy, Failed, NoEndpoint. - FoundryToolboxHealthCheck (internal IHealthCheck): adapts startup status to the AspNetCore HealthChecks pipeline with failed toolbox names in result data. Tests: - 3 new tests for /readiness auto-mapping (Tier 3 default, pre-mapped skip, idempotent). - 4 new tests for FoundryToolboxHealthCheck (Pending, NoEndpoint, Failed, Healthy). - 3 enhanced FoundryToolboxServiceTests with StartupStatus assertions. * .NET: Align FoundryToolboxService with tools-integration-spec (#5777 Part A) Bring Microsoft.Agents.AI.Foundry.Hosting's toolbox path into compliance with tools-integration-spec.md sections 2-4, 6.3, and 9. Empirically validated against tao-foundry-prj: the previous code (reading FOUNDRY_AGENT_TOOLSET_ENDPOINT, which the platform never injects) silently registered zero tools in production. Package changes (Microsoft.Agents.AI.Foundry.Hosting): - FoundryToolboxService.StartAsync now derives the toolbox proxy base URL from the platform-injected FOUNDRY_PROJECT_ENDPOINT and constructs the per-toolbox URL as {FOUNDRY_PROJECT_ENDPOINT}/toolboxes/{name}/mcp?api-version={ApiVersion} per spec sections 2-3. The legacy FOUNDRY_AGENT_TOOLSET_ENDPOINT env var is removed outright (preview package, no production consumers). - FoundryToolboxOptions.ApiVersion default flipped to 'v1' to match spec example. - FoundryToolboxBearerTokenHandler always sends the mandatory Foundry-Features: Toolboxes=V1Preview header per spec section 2, merging any additional flags supplied via the FOUNDRY_AGENT_TOOLSET_FEATURES env var. - FoundryToolboxBearerTokenHandler token scope changed from https://cognitiveservices.azure.com/.default to https://ai.azure.com/.default per spec section 4. - FoundryToolboxBearerTokenHandler propagates W3C trace context (traceparent, tracestate, baggage) from Activity.Current per spec section 6.3. Sample changes: - Hosted-Toolbox-AuthPaths and Hosted-Toolbox Program.cs, README.md, and .env.example corrected to describe the actual env-var contract (FOUNDRY_PROJECT_ENDPOINT auto-injected; AZURE_AI_PROJECT_ENDPOINT as the local-dev fallback). Removes the misleading 'auto-injected by Foundry runtime' claims for FOUNDRY_AGENT_TOOLSET_ENDPOINT. - Hosted-Toolbox-AuthPaths/agent.manifest.yaml declares the toolbox and model dependencies under resources[] per the AgentManifest schema so azd ai agent init users get them provisioned automatically. Tests: - 4 new FoundryToolboxServiceTests covering env-var derivation, EndpointOverride precedence, trailing-slash normalization, and the existing NoEndpoint behavior under the new env var name. - 4 new FoundryToolboxBearerTokenHandlerTests covering token scope, mandatory feature header always present, header merging with override, no duplicate mandatory flag, trace context propagation from Activity.Current, and no override of caller-set traceparent. - New FoundryProjectEndpointEnvFixture xUnit collection definition serializes env-var-mutating tests across FoundryToolboxServiceTests and FoundryToolboxHealthCheckTests, preventing parallel-execution races. - FoundryToolboxHealthCheckTests adjusted for the new env var name. * .NET: Drop ACA prereq from Hosted-Toolbox-AuthPaths README (#5777 Part B) Empirically verified that any Azure Cognitive Services MCP endpoint already in the Foundry project (e.g., a Language service MCP) accepts Entra tokens and can serve Paths 2 and 3 without deploying a separate Azure MCP Server to ACA. README updates: - Step 0 rewritten: 'Identify an Entra-authenticated MCP target in your project' instead of 'Deploy Azure MCP Server to Azure Container Apps' (the original azmcp-foundry-aca-mi setup is now optional, not required). - Auth-paths matrix updated to describe AAD-based connections targeting a Cognitive Services MCP URL (e.g., Language service) instead of an ACA URL. - Step 2 connections table updated: the Entra ID category is now a single 'AAD' authType. The original 'Agent Identity' vs 'Project Managed Identity' as selectable connection sub-types is NOT exposed via the ARM control plane today; the platform selects the calling principal contextually. Both connections in the walkthrough share the same shape and target. - Added an explicit RBAC note: the agent identity AND project MI must hold the required role (typically Cognitive Services User) on the target resource; without it the MCP server returns HTTP 401 even though the connection wiring is correct. - Toolbox tool entries renamed lang_entra_agent / lang_entra_project to match the new connection names. Empirical validation supporting these changes is captured in the session plan.md (Part B addendum). * .NET: Document correct connection shape for Hosted-Toolbox-AuthPaths Paths 2/3 (#5777) Updates the sample README with the verified connection shape and RBAC procedure for Microsoft Entra agent-identity and project-managed-identity MCP authentication: - Connection authType values: AgenticIdentityToken (agent identity) and ProjectManagedIdentity (project MI), both with category=RemoteTool. - Top-level audience property required; for Cognitive Services targets the value is https://cognitiveservices.azure.com. - Connections created via ARM REST (the Foundry portal wizard does not yet expose these authTypes). - RBAC grants target the project's shared agent identity blueprint principal (project.properties.agentIdentity.agentIdentityId) for Path 2 and the project's system-assigned MI (project.identity.principalId) for Path 3. - Troubleshooting table updated with the audience-mismatch symptom and the startup-cache behavior of FoundryToolboxService. * .NET: Drop Path 3 (project MI) and align with new agent model in Hosted-Toolbox-AuthPaths (#5777) Updates the sample to use only the new Foundry agent object model and removes the project managed identity path: - Auth-path matrix reduced to four paths: key, Entra agent identity, custom OAuth, inline authorization. Project managed identity is moved into a note describing when it applies (multiple agents sharing access) rather than as a documented sample path. - RBAC instructions reference the agent's own instance_identity.principal_id from the agent ARM resource (new agent object model) instead of the project's shared agent identity blueprint (legacy model). - Step 2 (connections) creates only the AgenticIdentityToken connection. - Step 3 (toolbox tools) lists four tool entries instead of five. - Sample prompts and troubleshooting table updated to match. * .NET: Restore Path 3 (project MI) to Hosted-Toolbox-AuthPaths matrix (#5777) The sample's purpose is to enumerate every authentication path a Foundry toolbox can drive, not to pick one. Path 3 belongs alongside the other four with explicit guidance for when each path is the right choice. - Path 3 (project managed identity, authType=ProjectManagedIdentity) restored to the matrix with a 'When to pick this' column. - Step 2 (connections) provisions both lang-mcp-agent-id and lang-mcp-project-mi via ARM REST. - Step 3 (toolbox) lists five tool entries (one per path). - RBAC instructions cover both the agent's instance identity (Path 2) and the project's system-assigned MI (Path 3). - Sample prompts include all five paths. - Troubleshooting table updated accordingly. * .NET: Fix duplicate line in Hosted-Toolbox-AuthPaths README (#5777) * .NET: Fix broken markdown link to ToolCallingApprovalHostedAgentFixture (#5777) * .NET: Fix relative path depth in markdown link (#5777) * .NET: Address Copilot review feedback for #5777 - FoundryToolboxHealthCheck description: rename FOUNDRY_AGENT_TOOLSET_ENDPOINT → FOUNDRY_PROJECT_ENDPOINT (stale reference; operator-facing in /readiness body). - FoundryToolboxStartupStatus.NoEndpoint XML doc: same rename. - ServiceCollectionExtensions XML docs: same rename + URL shape update. - Foundry.Hosting.IntegrationTests.TestContainer: remove explicit app.MapGet('/readiness') — now redundant + would conflict with the auto-mapped readiness route from MapFoundryResponses. - Hosted-Toolbox-AuthPaths agent.manifest.yaml: parameterize TOOLBOX_NAME via {{TOOLBOX_NAME}} template substitution and declare it under parameters with a default of 'auth-paths-toolbox' so the README's 'use any name' guidance actually works for hosted deployments. * .NET: Address Copilot review round 2 — fallback env + dedup + naming (#5777) - FoundryToolboxService.StartAsync: fall back to AZURE_AI_PROJECT_ENDPOINT when FOUNDRY_PROJECT_ENDPOINT is absent. Matches the local-dev convention used by the samples and resolves the doc/code mismatch flagged in review. - FoundryToolboxHealthCheck description updated for the fallback. - AddFoundryToolboxes: guard against duplicate health-check registration via an explicit name-uniqueness check on HealthCheckServiceOptions.Registrations. AddCheck<T>(name, ...) does not dedupe by name, so repeated AddFoundryToolboxes calls would have registered multiple instances. - FoundryToolboxOptions.EndpointOverride doc: clarify URL becomes {EndpointOverride}/toolboxes/{name}/mcp (was missing /toolboxes/ segment). - Hosted-Toolbox sample (Program.cs + README): switch FOUNDRY_TOOLBOX_NAME to TOOLBOX_NAME (the FOUNDRY_* prefix is reserved by the platform), default changed from 'my-toolset' to 'my-toolbox', terminology updated from 'Toolset' to 'Toolbox'. - FoundryToolboxServiceTests: 2 test renames to reflect what they actually assert (StartupStatus + FailedToolboxNames, not URL shape directly). - Tests adjusted to clear both env vars in NoEndpoint scenarios. * .NET: Fix stale NoEndpoint XML doc and misleading test comment (#5777) Update FoundryToolboxStartupStatus.NoEndpoint XML doc to mention both FOUNDRY_PROJECT_ENDPOINT and AZURE_AI_PROJECT_ENDPOINT (the service checks both since the fallback was added). Fix test comment that claimed URL derivation validation when the test only asserts on StartupStatus and FailedToolboxNames. * Remove OAuth consent path from AuthPaths sample, keep four working auth paths The interactive OAuth identity passthrough path needs a protocol gap closed in the hosting package (the proprietary oauth_consent_request item is not representable through the OpenAI/MEAI abstractions), so it is deferred to a separate spike branch. This strips the OAuth path from the AuthPaths sample, the companion REPL client, the agent manifest, and the docs, then renumbers the inline Authorization path so the sample teaches four contiguous paths: API key via connection, Entra agent identity, Entra project managed identity, and inline Authorization (anti-pattern). Package code is unchanged; the consent infrastructure already present in main stays as baseline. Both samples build with --warnaserror and all 246 hosting unit tests pass. * .NET: Drop project MI auth path and dedicated client from Hosted-Toolbox-AuthPaths (#5777) Live validation against tao-foundry-prj showed the ProjectManagedIdentity path failing with an unresolved token audience 401, so the sample now ships three working auth paths instead of four: connection key, agent managed identity, and inline Authorization. Changes: - Remove the project managed identity path from the AuthPaths sample matrix, prerequisites, connections, toolbox table, prompts, Program.cs instructions and agent.manifest.yaml. - Delete the near duplicate Hosted-Toolbox-AuthPaths-Client project and remove it from the solution. The README now drives the agent with the shared SimpleAgent REPL via AsAIAgent(agentEndpoint). - Correct the troubleshooting note: the Foundry toolbox tools/list is all or nothing, so one bad source returns -32007, fails startup, and returns 424 for every path. Add the allowed_tools caveat that names must match the upstream server. - Mark the toolbox startup status and health check experimental under AgentsAIExperiments (MAAI001) instead of AIOpenAIResponses, and update the package NoWarn set accordingly. * .NET: Address PR review nits for Hosted-Toolbox-AuthPaths (#5777) - Remove duplicated NU1903 comment in Foundry.Hosting csproj. - Fix stale 'four-tool' cross-links in Hosted-Toolbox and Hosted-McpTools READMEs to describe the three-path toolbox driven by the shared SimpleAgent REPL. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Address toolbox startup-status review feedback (#5777) - Rename FoundryToolboxStartupStatus.Failed to Unhealthy so it is the proper opposite of Healthy, and clarify the doc comment covers the partial-failure case. - Raise the missing-endpoint toolbox log from Information to Warning, since enabling toolboxes is an explicit opt-in and a silently disabled toolbox warrants a higher-severity signal. - Update unit tests and the AuthPaths README troubleshooting row accordingly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Reword toolbox-wiring comment to avoid hosting-layer internals (#5777) Address PR review feedback: explain how a Foundry Toolbox is attached using the public API (AddFoundryToolboxes vs the CreateHostedMcpToolbox marker) and observable behavior, instead of naming the internal AgentFrameworkResponseHandler type and FoundryToolboxService.Tools property. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> |