Skip to content

Weekly Permissions sync 2026-07-30 - #1587

Merged
jasonjoh merged 1 commit into
masterfrom
permissions-update/2026-07-30
Jul 30, 2026
Merged

Weekly Permissions sync 2026-07-30#1587
jasonjoh merged 1 commit into
masterfrom
permissions-update/2026-07-30

Conversation

@marabooy

Copy link
Copy Markdown
Contributor

Weekly Permissions sync 2026-07-30

@marabooy
marabooy requested a review from a team as a code owner July 30, 2026 00:53
Copilot AI review requested due to automatic review settings July 30, 2026 00:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Weekly permissions data sync updating the Graph permissions metadata used by the devx-content pipeline.

Changes:

  • Added new permission deployment entries in provisioningInfo.json (including ChannelMessage.Send.All, ChatMessage.Send.All, and CredentialProvenance.ReadWrite.All).
  • Updated permissions.json networkAccess function path names and adjusted least-privilege annotations under Teamwork.Migrate.All.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
permissions/new/provisioningInfo.json Adds new permission deployment records for additional scopes/schemes.
permissions/new/permissions.json Renames networkAccess function paths and modifies least-privilege markers for migration-related message endpoints.
Comments suppressed due to low confidence (2)

permissions/new/provisioningInfo.json:3447

  • For other permissions targeting resourceAppId ab3be6b7-f5df-413d-ac2d-abf1e3fd9c0b, the environment is consistently set to "public". This new ChatMessage.Send.All entry uses an empty environment string, which is inconsistent with the surrounding entries and with other disabled/hidden entries for the same resourceAppId.
        "environment": "",

permissions/new/permissions.json:55491

  • Similar to /chats/{id}/messages, clearing these two values removes the only "least=Application" markers for POSTing channel messages/replies. There are no other POST mappings in permissions.json that mark these endpoints as least=Application, so this likely drops the application least-privilege signal for migration message creation.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread permissions/new/provisioningInfo.json
Comment thread permissions/new/permissions.json
@jasonjoh
jasonjoh merged commit 05d2b77 into master Jul 30, 2026
5 checks passed
@jasonjoh
jasonjoh deleted the permissions-update/2026-07-30 branch July 30, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants