Skip to content

Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739 - #451

Merged
shahzaibj merged 1 commit into
masterfrom
shjameel-microsoft-glowing-eureka
Jul 23, 2026
Merged

Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739#451
shahzaibj merged 1 commit into
masterfrom
shjameel-microsoft-glowing-eureka

Conversation

@shahzaibj

@shahzaibj shahzaibj commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

We no longer monitor the AuthN SDK - ADAL Android service tree (937cdc57-1253-4b55-878e-5854368926a2), so this removes it from the s360-reporter skill.

Changes

  • merge-items.js — dropped the ADAL GUID from DEFAULT_SERVICE_IDS, removed 'adal' from DEFAULT_TENANT_PATTERNS, and updated the "3 → 2 Android Auth service tree GUIDs" comment.
  • SKILL.md — removed the ADAL row from the Target Services table, dropped the ADAL GUID from the targetIds query example, and updated the "three services / three service tree GUIDs" wording and tenant-name pattern list.
  • generate-report.js & report-template.md — removed the ADAL Android chip from the report header services line.

The skill now monitors only MSAL Android and Microsoft Authenticator - Android.

Fixes AB#3697739

We no longer monitor the AuthN SDK - ADAL Android service tree (937cdc57-1253-4b55-878e-5854368926a2). Removed it from DEFAULT_SERVICE_IDS and tenant patterns in merge-items.js, the Target Services table and query examples in SKILL.md, and the report header service chips in generate-report.js and report-template.md.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
@shahzaibj
shahzaibj requested a review from a team as a code owner July 21, 2026 21:19
@github-actions github-actions Bot changed the title Remove ADAL service tree from S360 Reporter skill Remove ADAL service tree from S360 Reporter skill, Fixes AB#3697739 Jul 21, 2026
@github-actions

Copy link
Copy Markdown

✅ Work item link check complete. Description contains link AB#3697739 to an Azure Boards work item.

1 similar comment
@github-actions

Copy link
Copy Markdown

✅ Work item link check complete. Description contains link AB#3697739 to an Azure Boards work item.

@shahzaibj
shahzaibj merged commit c4e0711 into master Jul 23, 2026
5 checks passed
shahzaibj added a commit that referenced this pull request Jul 31, 2026
…DAL header cleanup, Fixes AB#3706577 (#453)

Fixes
[AB#3706577](https://identitydivision.visualstudio.com/fac9d424-53d2-45c0-91b5-ef6ba7a6bf26/_workitems/edit/3706577)

## What
Hardens the `s360-reporter` skill so the decommissioned **ADAL Android**
service tree can never re-enter scope, and finishes removing ADAL from
the report header (a gap left after PR #451).

## Why
PR #451 removed ADAL from the fetch scope, but a teammate re-ran the
skill and ADAL items still reappeared. Root cause was not the fetch: a
stale pasted "last week" report (4 active ADAL bugs owned by a manager)
tripped the Step 1e "don't mark active items resolved" continuity guard,
and the agent "recovered" ADAL by re-adding the ADAL service GUID to
`team.json` `serviceIds` and the manager alias to `aliases`.
Removal-by-omission alone was not robust against agent reasoning, so
this adds a hard, code-level denylist.

## Changes
- **`merge-items.js`** — new `DECOMMISSIONED_SERVICE_IDS` denylist (ADAL
GUID `937cdc57-1253-4b55-878e-5854368926a2`):
- Sanitizes any `team.json` `serviceIds` override that tries to re-add
the GUID (emits a WARN).
- `isTeamRelevant()` early-returns false for decommissioned `TargetId`s
(blocks the Person-targeted path).
- New `svcScoped` filter drops service-query items targeting a
decommissioned service tree.
- **`SKILL.md`** — new "Decommissioned Scope" section, Step 0b exclusion
note, and a critical Step 1e decommissioned-scope guard so stale-report
items are classified `decommissioned/out-of-scope` (never `resolved`,
never auto-closed, never linked).
- **`generate-report.js` / `report-template.md`** — remove the leftover
"AuthN SDK - ADAL Android" entry from the report header (completes PR
#451).

## Verification
- Unit test against a fixture: all three leak paths (service-query,
tenant-pattern, Person-targeted) drop ADAL.
- Adversarial re-add test reproducing the teammate's exact mechanism
(ADAL GUID back in `serviceIds`, manager in `aliases`, ADAL TargetIds in
both queries): output contained only the 2 legit items; all three
defenses fired and `serviceIds` collapsed 2 -> 1.

---------

Copilot-Session: 84aa6694-5d85-4319-a0ca-41ba459894e7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants