Repository navigation
Add approvalReference to private endpoint connection in 2026-01-01 - #45604
Conversation
… 2026-01-01 Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
Next Steps to MergeImportant checks have failed. As of today they are not blocking this PR, but in near future they may.Addressing the following failures is highly recommended:
Comment generated by summarize-checks workflow run. |
API Change CheckAPIView identified API level changes in this PR and created the following API reviews
Comment generated by After APIView workflow run. |
The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
ARM API Review Critic — Verdict: FAIL (environment/input failure)I could not perform the independent verification required by protocol due to missing required inputs in this execution environment:
Per my binding instructions, when required instruction files, inputs, or evidence are unavailable, I must return an explicit failure verdict rather than claim Critic-verified status. This is a genuine environment/tooling gap, not a judgment on the underlying finding's correctness — I was unable to independently confirm or refute whether the Recommendation: Re-run this Critic step in an environment where (a) the No claim of Critic-verified PASS or FAIL on the substantive finding is made here — this is strictly an infrastructure/input-availability failure report.
|
ARM API Review SummaryReviewed PR #45604 at head SHA Approval labels observed: none.
This PR adds an optional, create-only posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 9e09295
|
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (Critic unavailable; reviewer self-check only, 3 iteration(s), 1 finding posted) against commit 9e09295a3903b489ebce4d69dbdd6db403504463. See inline comments for findings on specification/network/resource-manager/Microsoft.Network/Network/stable/2018-10-01/vmssNetwork.json line 3478.
Approval labels observed: none.
🔍 ARM API review by ARM API Review: Automated Workflow
|
@microsoft-github-policy-service agree company="Microsoft" |
Per internal discussion, drop the create-only mutability restriction on approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create) decorator in Common/main.tsp and regenerates the Network and Vmss project swaggers so x-ms-mutability is no longer emitted. The approvalReference property and ApprovalReference model are retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a
ARM API Review SummaryReviewed PR #45604 at head SHA Approval labels observed: none.
This PR adds an optional posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: new | critic: unknown | head-sha: 721e83b
|
Summary for ARM reviewerThis PR adds one optional property, Intended API surface (the actual change):
The property is a normal read/write property by design (no The two failing checks are known/expected, not new code issues:
The automated ARM API review returned 0 Blocking; both inline findings have author replies. CLA is signed and |
Sandip Shahane (sandipsh)
left a comment
There was a problem hiding this comment.
ARM API Review
Posting findings from the ARM API Reviewer agent (critic-verified, 1 iteration(s), converged) against commit 721e83b. See inline comments for finding 1.
Approval labels observed: none.
Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources.
ARM API Review SummaryReviewed PR #45604 at head SHA Approval labels observed: none.
This PR adds an optional posted-by: arm-api-reviewer-agent | rule: summary | severity: suggestion | classification: existing | critic: unknown | head-sha: 3aa0658
|
3aa0658 to
401c5b1
Compare
ARM API Review SummaryReviewed PR #45604 at head SHA Approval labels observed: none.
This run re-verified the canonical PR head via the Pull Requests API and found it is posted-by: arm-api-reviewer-agent | rule: summary | severity: warning | classification: existing | critic: unknown | head-sha: 401c5b1
|
this is not addressed yet. |
|
ZiWei Chen (@kazrael2119) Chenjie Shi (@tadelesh) — requesting breaking-change sign-off for the Go ( Why the labels fire: This PR adds one optional property, Precedent: This is the same established shared-model emission pattern already approved in prior Network releases — see #41904 (API version 2025-07-01), where Could you please review and apply the |
b33a4ee
into
release-microsoft-network-2026-01-01
* Add API version 2026-01-01 for Microsoft.Network (#45569) Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> * Add Enum values for VPN migrationType (#45647) Co-authored-by: Akshat Kale <akale@microsoft.com> * Fix Bug 38477992: type computedDisabledRules.rules as integers (2026-01-01) (#45621) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 * [Network] Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 (#45625) * Add WAF rule paranoiaLevel and rule set displayName to 2026-01-01 Ports the change from azure-rest-api-specs-pr PR 29807 onto the public 2026-01-01 release branch. Adds three read-only properties that NRP surfaces from api-version 2026-01-01 for Application Gateway WAF: - paranoiaLevel on ApplicationGatewayFirewallRule - displayName on ApplicationGatewayFirewallRuleSetPropertiesFormat - displayName on ApplicationGatewayFirewallManifestRuleSet - displayName on DefaultRuleSetPropertyFormat paranoiaLevel uses a new extensible enum ApplicationGatewayWafRuleParanoiaLevel with values PL1 to PL4. All new members are annotated with @added(Versions.v2026_01_01). The change is additive and all new properties are optional. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Retrigger CI The SDK Validation - Rust build failed on a transient GitHub timeout while installing the Azure SDK Tools CLI. Nothing in the spec changed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Centurion WAF: add WAF policy tier + Basic_v2/Basic_WAF_v2 SKUs (2026-01-01) (#45766) * Add Centurion WAF updates for 2026-01-01 Update WAF policy tier and reserved capacity support. Add Basic_v2 and Basic_WAF_v2 SKUs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic v2 application gateway tiers WebApplicationFirewallPolicyTier ordering aligns Standard=0 and Basic=1. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Basic WAF and application gateway examples Add Basic WAF policy create/get examples and Basic-tier coverage. Add Basic_v2 and Basic_WAF_v2 application gateway create/get examples, including reservedCapacity and WAF policy association. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add AuthenticationPolicy resource and Application Gateway authConfigs binding for 2026-01-01 (#45764) * Add AuthenticationPolicy support for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align AuthenticationPolicy contract with service behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Enforce AuthenticationPolicy name and binding constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 --------- Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 (#45650) * Add minAllocationSize and maxAllocationSize to IpamPool for 2026-01-01 Adds optional min/max allocation-size bounds to the Microsoft.Network IpamPool resource in api-version 2026-01-01: - IpamPoolProperties (PUT/GET): minAllocationSize, maxAllocationSize - IpamPoolUpdateProperties (PATCH): minAllocationSize, maxAllocationSize marked x-nullable so an explicit null clears the bound while an absent bound is preserved, per ARM merge-patch semantics. Both properties are gated with @added(Versions.v2026_01_01) so earlier api-versions are unchanged. Regenerated virtualNetwork.json and updated the 2026-01-01 IpamPools Create/Get/List/Update examples. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Move min/max allocation size into dedicated IpamPool examples The allocation-size bounds are optional, so the baseline IpamPools examples should not imply they are always supplied. Restores IpamPools_Create/Get/List/Update to their original content and adds dedicated examples that exercise the feature: - IpamPools_CreateWithAllocationBounds.json: PUT setting both bounds. - IpamPools_UpdateAllocationBounds.json: PATCH setting both bounds. - IpamPools_UpdateClearAllocationBounds.json: PATCH clearing both bounds with an explicit null, per ARM merge-patch semantics. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address ARM review: drop nullable union on new min/max update properties New properties must not use a nullable union, since backward compatibility does not apply to additions. The RP already treats an empty string as a clear on PATCH, so the explicit null is unnecessary. - IpamPoolUpdateProperties min/maxAllocationSize: string | null -> string, removing the no-nullable suppressions and x-nullable from the swagger. - Document clearing via an empty string. - IpamPools_UpdateClearAllocationBounds example now clears with "". Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add Swagger Avocado suppression for frozen 2018-10-01 VMSS surface Per ARM reviewer guidance on PR #45650: the package-2026-01-01 default tag intentionally retains stable/2018-10-01/vmssNetwork.json for backward compatibility, which trips Avocado's MULTIPLE_API_VERSION rule. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix Avocado suppression tool name to SwaggerAvocado Per ARM reviewer bot feedback on PR #45650: the suppression tool name has no space. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Add approvalReference to private endpoint connection in 2026-01-01 (#45604) * Add approvalReference (create-only) to private endpoint connection in 2026-01-01 Adds optional approvalReference.privateEndpointId to PrivateLinkServiceConnectionProperties, gated @added(v2026_01_01) with @visibility(Lifecycle.Read, Lifecycle.Create) so it is create-only (emits x-ms-mutability: [read, create]) and is not resupplied on update. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Regenerate vmssNetwork.json for approvalReference (Vmss project) The Vmss TypeSpec project shares PrivateLinkServiceConnectionProperties and emits stable/2018-10-01/vmssNetwork.json, which must be regenerated so approvalReference/ApprovalReference are included. Fixes TypeSpec Validation (Vmss). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Remove x-ms-mutability (create-only) from approvalReference Per internal discussion, drop the create-only mutability restriction on approvalReference. Removes the @visibility(Lifecycle.Read, Lifecycle.Create) decorator in Common/main.tsp and regenerates the Network and Vmss project swaggers so x-ms-mutability is no longer emitted. The approvalReference property and ApprovalReference model are retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Type approvalReference.privateEndpointId as armResourceIdentifier Address ARM review finding [TSP-ARM-RESOURCE-ID]: privateEndpointId references an existing private endpoint, so type it as Azure.Core.armResourceIdentifier<Microsoft.Network/privateEndpoints> instead of plain string. Regenerated swagger emits format: arm-id and x-ms-arm-id-details.allowedResources. --------- Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a * Add ExpressRoutCircuit on ExpressRouteLag (#45689) * Add ExpressRoutCircuit on ExpressRouteLag * Fix ExpressRouteLag examples: sync circuits to output copies and remove invalid circuit properties Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * Align ExpressRouteCircuitCreateOnExpressRouteLag responses with request (EX-PARAM-CONSISTENCY) Fix response bodies to match request: LAG reference lagName (was test), enableDirectPortRateLimit true, and SKU Premium_MeteredData in the 200 response. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * Add AppGw Advanced Routing Rule in NRR API 2026-01-01 (#45844) * Add advanced routing features to Application Gateway for API version 2026-01-01 * buid artifacts after changes to models.tsp * added examples * fix merge conflict --------- Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> * Modify sdk-suppressions.yaml for breaking changes (#45914) Updated breaking changes for Azure SDK suppressions in network resource manager. * [Microsoft.Network] Add provider-led ExpressRoute circuit migration APIs (#45905) * Add ExpressRoute circuit migration APIs Add TypeSpec operations and models for provider-led ExpressRoute circuit migration, generated 2026-01-01 Swagger, examples, and the scoped brownfield resource-name suppression. * Fix Network specification validation Use valid UUID subscription IDs, add required TypeSpec example metadata, regenerate migration LRO metadata, and suppress the intentional mixed-version VMSS surface in the combined Network package. * Fix Network Avocado suppression Move the mixed API-version exception from an unsupported AutoRest directive to the Network SwaggerAvocado path-suppression file, scoped to the default-tag readme. * Fix Network validation suppressions * Correct Avocado suppression identifier * Geo-Ip filter changes (#45631) * Geo Ip Filter Changes * Document GeoIP filter format (ISO 3166-1 alpha-2) and fix WAF scrubbing-rule model * Fixing Swagger ModelValidation Filure related errors * Dummy Push to reinitate build * Type Spec validation failure fix * Remove duplicate GeoIP filter properties --------- Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> * Add NeuroShield API for 2026-01-01 (#45722) * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add NeuroShield API for 2026-01-01 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Align NeuroShield contract with service behavior Require customer-facing configuration, align mitigation responses with the safe service projection, make cancellation synchronous, and correct protected-resource delete polling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Refine NeuroShield 2026-01-01 contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield validation regressions * Address ARM review feedback for NeuroShield Use supported ARM resource templates, scope Swagger suppressions to exact operations, and isolate inherited Network validation debt. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Fix NeuroShield LintDiff suppressions * Use standard ARM entity tag property --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac * Add post calls for auth key of authorization objects for expressrouteciruits and expressrouteports (#45679) * Added post calls for expressroute auth key * Added the objects in 2026-01-01 version * addressed ai comments * Addressed comments * fixed * removed suppression * fixed suppressions --------- Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> * Fix Hub virtual network IPv6 peering contract (#45637) * Fix IPv6 peering contract for Network 2026-01-01 * Correct IPv6 peering contract in Network 2025-09-01 * Update client.tsp * Update sdk-suppressions.yaml --------- Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: kazrael2119 <98569699+kazrael2119@users.noreply.github.com> * Correct AuthenticationPolicy contract for 2026-01-01 (#45892) * Correct authentication policy contract Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Keep provider type extensible Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Document authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Align authentication examples with service Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Restore authentication policy tags update Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Suppress PatchIdentityProperty for AuthenticationPolicies_UpdateTags The tags-only PATCH takes the shared Network RP TagsObject body, matching ApplicationGateways_UpdateTags. The service only updates tags on this operation, so identity does not belong in the request body. * Complete authentication policy constraints Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Correct Basic v2 authentication example Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Address ARM review feedback on AuthenticationPolicy 2026-01-01 - Make the arm-resource-invalid-envelope-property suppression reason self-contained by stating why the user-assigned identity belongs in the resource envelope. - Scope the PatchIdentityProperty suppression with a where: clause targeting the AuthenticationPolicies_UpdateTags PATCH operation. - Type issuer as url and require an https scheme, consistent with jwksUri and clientSecret. - Document the sessionTimeout string syntax and units, and constrain it with a base-10 integer pattern and max length. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Also scope PatchIdentityProperty suppression to the PATCH body parameter path Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove AuthenticationPolicy PATCH operation The service supports only GET, PUT, and DELETE for authenticationPolicies, matching ApplicationGatewayWebApplicationFirewallPolicies, which also ships without a PATCH. Removing the tags-only PATCH also resolves the PatchIdentityProperty finding at its source: that rule fires only on an existing PATCH, so with no PATCH the identity envelope property no longer needs a suppression. - Remove AuthenticationPolicies_UpdateTags and its source and generated examples. - Drop the PatchIdentityProperty suppression. - Restore the TrackedResourcePatchOperation no-PATCH suppression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Drop stale PATCH path from ProvisioningStateMustBeReadOnly suppression The AuthenticationPolicy PATCH operation was removed, so the patch response entry in the where: list no longer matches anything. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Restore AuthenticationPolicy PATCH with a resource-specific update model AuthenticationPolicy is a tracked resource: it extends the Network RP Resource base type, which supplies location, tags and x-ms-azure-resource. ARM requires resource providers to support PATCH for updating tags on a tracked resource, so removing the operation was incorrect. Restore PATCH using a resource-specific AuthenticationPolicyUpdateParameters model carrying both tags and identity, rather than the shared TagsObject. This satisfies the tracked-resource tags requirement and the MSI onboarding requirement that the control plane accept identity updates on PATCH, which means PatchIdentityProperty is now satisfied at the source and needs no suppression. - Add AuthenticationPolicyUpdateParameters (tags, identity). - Add AuthenticationPolicies_Update, replacing the former tags-only AuthenticationPolicies_UpdateTags. - Add an example exercising both tags and identity updates. - Drop the TrackedResourcePatchOperation suppression, no longer applicable. - Scope ProvisioningStateMustBeReadOnly to the new PATCH 200 response schema. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 * Add bastion session recording configuration and identity properties (#45630) * Add bastion session recording configuration property * Fix the patch body for identity support * Update examples * Fix prettier violation * Revert documentation changes * Add BastionHostUpdate model instead of anonymous type * Add tpye constraint for userAssignedIdentityId * Fix invalid arm id for public ip in example * Fix wrong name in 200 responses in new examples * Fix documentation for BastionHostUpdate * Preserve existing updateTags operation * Update suppression justification * Revert previous changes which maintained the old operation * Update suppression justification for update operation --------- Co-authored-by: Matthew Lee <matthelee@microsoft.com> * Add azureFirewall enableAiAddOn (#45976) * Add azureFirewall enableAiAddOn * Enable aiSecurityAddOn in Azure Firewall configuration Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * copilot messed up, fix typescript * fix fields in exampels * fix fields in examples --------- Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Revert "Add NeuroShield API for 2026-01-01 (#45722)" (#46208) This reverts commit efb6f29. * Address swagger review findings on AuthenticationPolicy for 2026-01-01 (#46260) * Address swagger review findings on AuthenticationPolicy Resolves five of the review findings at the source rather than by suppression, removing four AuthenticationPolicy suppressions. RequiredReadOnlySystemData: declare systemData explicitly on AuthenticationPolicy, following the existing Network RP pattern used by AdminRuleCollection, BaseAdminRule and Commit. It is emitted read-only. RPC-Delete-V1-01: drop the ArmDeletedNoContentResponse override so the sync DELETE emits 200, 204 and default. AuthenticationPolicy was the only resource in this project overriding the delete response; every sibling uses the default. Removes the DeleteResponseCodes and DeleteOperationResponses suppressions. SEC-SECRET-DETECT: remove the secret-prop suppression. The rule only fires on properties typed as the builtin string, and clientSecret is typed url, so the suppression had no effect. The property holds only a Key Vault reference, which the documentation now states explicitly. The XMSSecretInResponse suppression is also removed, as nothing in the generated file is marked x-ms-secret. RPC-SUPPRESS-SCOPE: scope RequiredPropertiesMissingInResourceModel to $.definitions.AuthenticationPolicy, and explain why LatestVersionOfCommonTypesMustBeUsed stays file-level: the common-types version is pinned package-wide by arm-types-dir, so the finding applies to every common-types reference in the file rather than to any single definition. Section 4.1: document the authenticationPolicy Features member instead of suppressing documentation-required, and replace the placeholder FIXME justification on WebApplicationFirewallPolicyTier with a real one. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix LintDiff and ModelValidation failures on AuthenticationPolicy 2026-01-01 Three CI failures introduced by the previous review-feedback commit: 1. LintDiff RequiredPropertiesMissingInResourceModel: the where: scope added for this rule only covered $.definitions.AuthenticationPolicy, but the rule also fires on AuthenticationPolicyListResult. Added that definition to the scope and extended the reason to explain that the list result is a paged envelope rather than a resource. 2. LintDiff XMSSecretInResponse on clientSecret: removing the TypeSpec secret-prop suppression did not clear this because the swagger rule matches purely on the property name ending in a sensitive keyword. The property only ever carries an absolute HTTPS Key Vault reference URL, never secret material, so annotating it with x-ms-secret would be incorrect - it would stop the service returning the reference in GET. Renamed the property to clientSecretUrl, which both clears the rule without any suppression and describes the value accurately. 2026-01-01 is not yet published, so the rename carries no breaking-change cost. 3. ModelValidation RESPONSE_STATUS_CODE_NOT_IN_EXAMPLE: the delete operation now declares a 200 response, so AuthenticationPolicyDelete.json needs a matching (bodyless) 200 entry alongside the existing 204. Swagger Avocado remains failing with MULTIPLE_API_VERSION on the package-2026-01-01 tag. That failure reproduces on the base release branch PR (#46086) and is unrelated to this change. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Rename clientSecretUrl to clientSecretUri TypeSpec Validation compiles client.tsp with --warn-as-error, which surfaces @azure-tools/typespec-client-generator-core/csharp-no-url-suffix: properties ending in 'Url' must use the 'Uri' suffix so the generated C# surface is idiomatic. The local emit-only compile of the Network project does not run client.tsp, so this was missed. clientSecretUri still avoids the LintDiff XMSSecretInResponse keyword match, which only fires on names ending in a sensitive keyword. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Revert clientSecret rename and suppress XMSSecretInResponse instead The rename to clientSecretUrl/clientSecretUri was wrong. The property name is part of the contract already implemented by the Network resource provider, so the spec has to match NRP rather than pick a name that happens to dodge the linter's keyword match. Reverted to clientSecret. To keep LintDiff green, XMSSecretInResponse is suppressed instead, scoped to $.definitions.AuthenticationProviderProperties.properties.clientSecret. The justification is substantive rather than a waiver: the property carries only an absolute HTTPS Key Vault secret URL, never secret material - the secret value is read from Key Vault at runtime using the resource's user-assigned identity and is never accepted or returned by this API. Annotating it with x-ms-secret would be actively incorrect, because that would stop the service returning the Key Vault reference on GET, which callers need in order to see how a policy is configured. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Santosh Lokarapu <v-slokar@microsoft.com> Co-authored-by: Akshat Kale <kaleakshat@gmail.com> Co-authored-by: Akshat Kale <akale@microsoft.com> Co-authored-by: yaarark <yaararonenkr@gmail.com> Co-authored-by: yaarark <178404435+yaarark@users.noreply.github.com> Co-authored-by: Shaigoldbourt22 <118125561+Shaigoldbourt22@users.noreply.github.com> Co-authored-by: Shai Goldbourt <shgoldbourt@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: baoqihuang0326 <119557638+baoqihuang0326@users.noreply.github.com> Co-authored-by: Arjun Patel <94936045+arjun-d-patel@users.noreply.github.com> Co-authored-by: ajoyduwary <ajoyduwary@gmail.com> Co-authored-by: Ajoy Duwary (from Dev Box) <ajoyduwary@microsoft.com> Co-authored-by: mshrimankar10 <66165250+mshrimankar10@users.noreply.github.com> Co-authored-by: Meera Shrimankar <mshrimankar@microsoft.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: paawankohli <44478509+paawankohli@users.noreply.github.com> Co-authored-by: Paawan Kohli <paawankohli@microsoft.com> Co-authored-by: ZiWei Chen <98569699+kazrael2119@users.noreply.github.com> Co-authored-by: gurram-amulya <111553857+gurram-amulya@users.noreply.github.com> Co-authored-by: kshitizmathur-max <kshitiz.mathur@gmail.com> Co-authored-by: Kshitiz Mathur <kshmathur@microsoft.com> Co-authored-by: Satya-Kotha1008 <sathi.kotha1008@gmail.com> Co-authored-by: carenlim20 <carenlim+github@microsoft.com> Co-authored-by: Caren Lim <carenlim@microsoft.com> Co-authored-by: Matthew Lee <mwlee29@gmail.com> Co-authored-by: Matthew Lee <matthelee@microsoft.com> Co-authored-by: Ben Eshed <105308016+bewatersmsft@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Copilot-Session: 29f2cbb3-29c5-444f-837b-9f5efa9782a3 Copilot-Session: 8c9963e3-6d51-4873-bdf8-95fb546098c3 Copilot-Session: 8a51a230-76ca-454e-a1d9-4bd6b37f202a Copilot-Session: 0f50978e-4a9f-439e-bdb8-4a0e00eb02ac
Summary
Adds an optional
approvalReference.privateEndpointIdproperty toPrivateLinkServiceConnectionProperties, gated@added(Versions.v2026_01_01). The property is emitted into the newstable/2026-01-01swagger outputs (common.json,virtualNetwork.json).approvalReferencelets a manual private endpoint connection inherit the connection-approval state of an existing, already-approved private endpoint at creation time.Notes
x-ms-mutability/@visibility, and there is no create-only enforcement in the swagger. (An earlier revision of this PR added@visibility(Lifecycle.Read, Lifecycle.Create); that was removed by design.)stable/2018-10-01/vmssNetwork.jsonchange is a generated artifact. TheVmssTypeSpec project sharesPrivateLinkServiceConnectionPropertiesand pins@useDependency(Common.Versions.v2026_01_01), sotsp compileemits this new Common property into its single2018-10-01output. This is the same behavior as prior Network releases (e.g.ddosCustomPolicy/disablePeeringRouteadded to the same file in the 2025-07-01 release). The regenerated file is required for TypeSpec Validation to pass; it cannot be hand-trimmed without breaking the compile-parity check.