Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739 - #451
Merged
Conversation
We no longer monitor the AuthN SDK - ADAL Android service tree (937cdc57-1253-4b55-878e-5854368926a2). Removed it from DEFAULT_SERVICE_IDS and tenant patterns in merge-items.js, the Target Services table and query examples in SKILL.md, and the report header service chips in generate-report.js and report-template.md. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
|
✅ Work item link check complete. Description contains link AB#3697739 to an Azure Boards work item. |
1 similar comment
|
✅ Work item link check complete. Description contains link AB#3697739 to an Azure Boards work item. |
somalaya
approved these changes
Jul 22, 2026
fadidurah
approved these changes
Jul 22, 2026
shahzaibj
added a commit
that referenced
this pull request
Jul 31, 2026
…DAL header cleanup, Fixes AB#3706577 (#453) Fixes [AB#3706577](https://identitydivision.visualstudio.com/fac9d424-53d2-45c0-91b5-ef6ba7a6bf26/_workitems/edit/3706577) ## What Hardens the `s360-reporter` skill so the decommissioned **ADAL Android** service tree can never re-enter scope, and finishes removing ADAL from the report header (a gap left after PR #451). ## Why PR #451 removed ADAL from the fetch scope, but a teammate re-ran the skill and ADAL items still reappeared. Root cause was not the fetch: a stale pasted "last week" report (4 active ADAL bugs owned by a manager) tripped the Step 1e "don't mark active items resolved" continuity guard, and the agent "recovered" ADAL by re-adding the ADAL service GUID to `team.json` `serviceIds` and the manager alias to `aliases`. Removal-by-omission alone was not robust against agent reasoning, so this adds a hard, code-level denylist. ## Changes - **`merge-items.js`** — new `DECOMMISSIONED_SERVICE_IDS` denylist (ADAL GUID `937cdc57-1253-4b55-878e-5854368926a2`): - Sanitizes any `team.json` `serviceIds` override that tries to re-add the GUID (emits a WARN). - `isTeamRelevant()` early-returns false for decommissioned `TargetId`s (blocks the Person-targeted path). - New `svcScoped` filter drops service-query items targeting a decommissioned service tree. - **`SKILL.md`** — new "Decommissioned Scope" section, Step 0b exclusion note, and a critical Step 1e decommissioned-scope guard so stale-report items are classified `decommissioned/out-of-scope` (never `resolved`, never auto-closed, never linked). - **`generate-report.js` / `report-template.md`** — remove the leftover "AuthN SDK - ADAL Android" entry from the report header (completes PR #451). ## Verification - Unit test against a fixture: all three leak paths (service-query, tenant-pattern, Person-targeted) drop ADAL. - Adversarial re-add test reproducing the teammate's exact mechanism (ADAL GUID back in `serviceIds`, manager in `aliases`, ADAL TargetIds in both queries): output contained only the 2 legit items; all three defenses fired and `serviceIds` collapsed 2 -> 1. --------- Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
We no longer monitor the AuthN SDK - ADAL Android service tree (
937cdc57-1253-4b55-878e-5854368926a2), so this removes it from thes360-reporterskill.Changes
DEFAULT_SERVICE_IDS, removed'adal'fromDEFAULT_TENANT_PATTERNS, and updated the "3 → 2 Android Auth service tree GUIDs" comment.targetIdsquery example, and updated the "three services / three service tree GUIDs" wording and tenant-name pattern list.The skill now monitors only MSAL Android and Microsoft Authenticator - Android.
Fixes AB#3697739