Skip to content

[pull] main from Azure-Samples:main - #34

Open
pull[bot] wants to merge 412 commits into
digital-power:merge/17102024-merge-changes-from-azurefrom
Azure-Samples:main
Open

[pull] main from Azure-Samples:main#34
pull[bot] wants to merge 412 commits into
digital-power:merge/17102024-merge-changes-from-azurefrom
Azure-Samples:main

Conversation

@pull

@pull pull Bot commented Oct 20, 2024

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.1)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot added ⤵️ pull merge-conflict Resolve conflicts manually labels Oct 21, 2024
@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog270
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408274
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers75
samples/data-ingestion/README.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers88
samples/chat/README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog272
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408276

@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

3 similar comments
@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken Paths

We have automatically detected the following broken relative paths in your files.
Review and fix the paths to resolve this issue.

Check the file paths and associated broken paths inside them. For more details, check our Contributing Guide.

File Full Path Issues
docs/data_ingestion.md
#LinkLine Number
1/app/frontend/src/components/settings/Settings.tsx60

@github-actions

github-actions Bot commented Nov 5, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

@github-actions

github-actions Bot commented Nov 7, 2024

Copy link
Copy Markdown

Check Broken Paths

We have automatically detected the following broken relative paths in your files.
Review and fix the paths to resolve this issue.

Check the file paths and associated broken paths inside them. For more details, check our Contributing Guide.

File Full Path Issues
docs/data_ingestion.md
#LinkLine Number
1/app/frontend/src/components/settings/Settings.tsx60

@github-actions

github-actions Bot commented Nov 7, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://aka.ms/entgptsearchblog291
2https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure/ba-p/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid/ba-p/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/azure-architecture-blog/azure-openai-landing-zone-reference-architecture/ba-p/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/t5/ai-azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in/ba-p/3960809#:~:text=Integrated%20vectorization%20is%20a%20new%20feature%20of%20Azure,pull-indexers%2C%20and%20vectorization%20of%20text%20queries%20through%20vectorizers78

@github-actions

github-actions Bot commented Nov 7, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/revolutionize-your-enterprise-data-with-chatgpt-next-gen-apps-w-azure-openai-and/3762087291
2https://techcommunity.microsoft.com/blog/azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure-ai-search/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid-retrieval-and-ranking-ca/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid-retrieval-and-ranking-ca/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azurearchitectureblog/azure-openai-landing-zone-reference-architecture/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in-azure-ai-search/3960809209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in-azure-ai-search/396080978

1 similar comment
@github-actions

github-actions Bot commented Nov 7, 2024

Copy link
Copy Markdown

Check Broken URLs

We have automatically detected the following broken URLs in your files. Review and fix the paths to resolve this issue.

Check the file paths and associated broken URLs inside them. For more details, check our Contributing Guide.

File Full Path Issues
README.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/revolutionize-your-enterprise-data-with-chatgpt-next-gen-apps-w-azure-openai-and/3762087291
2https://techcommunity.microsoft.com/blog/azure-ai-services-blog/access-control-in-generative-ai-applications-with-azure-ai-search/3956408295
docs/deploy_lowcost.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid-retrieval-and-ranking-ca/392916743
docs/customization.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/azure-ai-search-outperforming-vector-search-with-hybrid-retrieval-and-ranking-ca/3929167120
docs/productionizing.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azurearchitectureblog/azure-openai-landing-zone-reference-architecture/388210286
docs/deploy_features.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in-azure-ai-search/3960809209
docs/data_ingestion.md
#LinkLine Number
1https://techcommunity.microsoft.com/blog/azure-ai-services-blog/announcing-the-public-preview-of-integrated-vectorization-in-azure-ai-search/396080978

@MyrtheLammerse
MyrtheLammerse changed the base branch from main to merge/17102024-merge-changes-from-azure November 19, 2024 15:24
Copilot AI and others added 16 commits July 29, 2025 22:07
…entation (#2653)

* Initial plan

* Add comprehensive Mermaid architecture diagrams and documentation

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

* Move Architecture Overview link to list above HTTP Protocol

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

* Address PR feedback: fix Mermaid syntax, update architecture docs

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

* Fix formatting and Mermaid syntax issues per PR feedback

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

* Update README.md

* Update docs/README.md

* Fix Mermaid parse error by removing parentheses from optional service labels

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

* Fix Mermaid parse error by removing dashes from node labels

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>
Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
* Configure Azure Developer Pipeline

* Private endpoints draft

* Conditional for SPL

* private endpoint for ACA

* Add P2S VPN gateway and other improvements

* Private endpoint almost working

* Usving avm for the subnets

* Connected app to vnet

* Feedback from Matt

* Move resources into modules

* Bring back unneeded changes

* Update prepdocs with ping and update docs

* Fix VPN client link

* Add App Service private endpoint for deployment

* Revert unneeded bicep changes

* Revert unneeded changes

* Remove unneeded NSG rules

* Address feedback from Copilot

* Address feedback from Copilot

* Address Copilot feedback

* Update NSG, container registry

* Update NSG, container registry

* Address feedback

* Bring back workload profile name
* Initial plan

* Add Bicep description for infra/private-endpoints.bicep

Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: pamelafox <297042+pamelafox@users.noreply.github.com>
* GPT-5 evals

* Add evals for GPT-5

* Upgrade openAI SDK

* Change snapshots to reasoning_effort of minimal
…nt (#2672)

* Add chat modes and prompts

* Fix tasks to work with chat mode

* Remove unrelated changes

* Update docs about local dev

* Add Windows command
* Use lowest reasoning effort appropriate for a model

* Address comments from Copilot
* Improved custom mode and repo instructions

* Update .github/copilot-instructions.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

* Update .github/copilot-instructions.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
…2669)

Bumps the github-actions group with 1 update: [Azure/setup-azd](https://github.com/azure/setup-azd).


Updates `Azure/setup-azd` from 2.1.0 to 2.2.0
- [Release notes](https://github.com/azure/setup-azd/releases)
- [Changelog](https://github.com/Azure/setup-azd/blob/main/CHANGELOG.md)
- [Commits](Azure/setup-azd@v2.1.0...v2.2.0)

---
updated-dependencies:
- dependency-name: Azure/setup-azd
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the github-actions group with 1 update: [actions/checkout](https://github.com/actions/checkout).


Updates `actions/checkout` from 4 to 5
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump pypdf from 4.3.1 to 6.0.0 in /app/backend

Bumps [pypdf](https://github.com/py-pdf/pypdf) from 4.3.1 to 6.0.0.
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](py-pdf/pypdf@4.3.1...6.0.0)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update snapshot for splitting

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pamela Fox <pamela.fox@gmail.com>
john0isaac and others added 30 commits July 6, 2026 14:42
* Group CSV rows into pages to avoid OOM in cloud ingestion

CsvParser emitted one Page per row, so large CSV files created thousands of Page objects and could exhaust memory in the cloud ingestion text-processor function (#2878). Add an optional CSV_MAX_PAGE_CHARS azd env variable that, when greater than 0, groups consecutive rows into pages up to that many characters. Default behavior (one page per row) is unchanged. Plumbed through build_file_processors, prepdocs, both ingestion functions, and infra. Adds tests for grouping, splitting, oversized rows, and large-file regression.

* Fix ruff UP012 in csv parser tests (drop redundant utf-8 encode arg)

* Fix prepdocs parallel issue and add manage_indexer script

* Address feedback about os.getenv

* Remove trailing blank line in test_csvparser.py for black

---------

Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
…Promise, Chromium 150.0.0 changed scrollIntoView() to return a Promise. (#3134)
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.0 to 2.13.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.12.0...2.13.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.13.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): upgrade msal to 1.37.0 and cryptography to 49.0.0

* docs(AGENTS): add manual test plan for msal / auth changes

* docs(AGENTS): use generic REGION placeholder in msal test plan
….11.7 (#3140)

* chore(deps): upgrade msgraph-sdk to 1.58.0 and microsoft-kiota-* to 1.11.7

* docs(AGENTS): add manual test plan for msgraph-sdk / kiota upgrades

* docs(AGENTS): drop hardcoded env name from msgraph test plan
* Upgrade azure-search-documents to 12.1.0b1

Bump the SDK from 11.7.0b2 to 12.1.0b1 ahead of the MAF port.

Real API changes handled:
- QueryCaptionResult.additional_properties was removed; drop it from
  caption serialization and the test mock.
- VectorizedQuery.k was renamed to k_nearest_neighbors.
- SearchIndexKnowledgeSourceParameters (index-definition model) dropped
  include_reference_source_data; remove it from the test fixture. The
  query-time *Params models still accept it and are unchanged.
- Update _generated imports to their public module paths.

Behavior improvements reflected in updated snapshots:
- Reference ids are now coerced to str, so first-citation [ref_id:0]
  correctly resolves to its source page instead of being left raw.
- Agentic "thoughts" activity records now serialize as camelCase, matching
  the SDK model representation.

Suppress ty call-non-callable false positives on SearchFieldDataType.Collection().

All 493 tests pass; ty, ruff, and black are clean.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Normalize agentic query_plan keys to snake_case after SDK upgrade

azure-search-documents 12.1.0b1 regenerated its models from TypeSpec, so
model .as_dict() now emits REST wire names (camelCase) instead of the
snake_case Python attribute names emitted by 11.7.0b2. The query_plan in
the agentic-retrieval ThoughtStep is built from
response.activity[*].as_dict(), so its keys silently switched to camelCase
(elapsedMs, knowledgeSourceName, searchIndexArguments, webArguments,
inputTokens, outputTokens, ...).

The frontend Execution Steps renderer (AgentPlan.tsx / agentPlanUtils.ts)
reads snake_case, so without this the query plan would show "—" for
elapsed time, fall back for source names, blank searches, and zeroed token
graphs. Normalize the keys back to snake_case in the backend so the app's
JSON contract stays snake_case and the frontend is untouched. Activity
"type" discriminator values (searchIndex, web, ...) are values, not keys,
so they are preserved.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Render query plan in camelCase on the frontend instead of normalizing in backend

The azure-search-documents 12.1.0b1 upgrade regenerated the SDK models so
KnowledgeAgentActivityRecord.as_dict() now emits REST wire names (camelCase).
The earlier fix normalized those keys back to snake_case in the backend
(camel_to_snake_keys helper) so the frontend query-plan renderer kept working.

Switch to updating the frontend instead: the backend passes activity.as_dict()
through verbatim, and the QueryPlanStep type + AgentPlan renderer read the SDK's
native camelCase keys. This removes the backend translation layer and keeps the
UI mirroring the SDK. Agent snapshots regenerated to camelCase accordingly.

Note: retrieval_reasoning_effort in the request overrides (models.ts / Chat.tsx)
is our own contract and stays snake_case; only the query_plan response fields
change. TokenUsage object-literal keys are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add e2e regression test for agentic query plan rendering

Guards against the camelCase drift introduced by the azure-search-documents
12.x upgrade: activity.as_dict() switched from snake_case to camelCase, which
the existing agentic e2e test did not catch because it only asserted section
headers, not the actual Execution steps table content.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix query_source_authorization kwarg rename in azure-search-documents 12.1.0b1

The SDK renamed the retrieve()/search() keyword from
x_ms_query_source_authorization to query_source_authorization. The
knowledgebase retrieve() forwards unknown kwargs straight to the aiohttp
transport, so the stale name raised TypeError: ClientSession._request()
got an unexpected keyword argument 'x_ms_query_source_authorization' on
the agentic retrieval path. Rename all four call sites and update the
test mocks to mirror the SDK parameter name.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix agentic retrieval regression from azure-search-documents 12.1.0b1

The upgraded SDK defaults the knowledgebase retrieval client to api-version
2026-05-01-preview, whose retrieval execution currently 502s server-side on
services that haven't rolled out that preview, and it also renamed the auth
kwarg to query_source_authorization while gating it to 2026-05-01-preview+
via client-side validation.

- Pin the knowledgebase client to 2025-11-01-preview (env-overridable via
  AZURE_SEARCH_KNOWLEDGEBASE_API_VERSION), the earliest version that supports
  the fields the app sends and retrieves successfully.
- Only forward query_source_authorization when the client's api-version
  supports it and a token is present; the search index source retrieves fine
  without it.

Both issues only surfaced via live agentic testing since the **kwargs mocks
could not catch them.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add e2e test for agentic retrieval query plan rendering

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Default knowledgebase api-version to latest 2026-05-01-preview

The earlier service-side 502 on 2026-05-01-preview was a transient outage
per the search team, not a version problem. Default to the latest version
(which supports every field the app sends, including query_source_authorization)
and keep the env override for services still rolling out the preview.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Clarify knowledgebase api-version comment: 502 was East US 2 regional outage

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* test: drop never-executed auth kwarg read from early-return mocks

The query_source_authorization rename put these lines in the diff, but
both mocks return early (empty path / access control disabled) so the
search closure never runs, leaving the renamed line uncovered. access_token
stays None via its initializer, so the assertions are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove knowledgebase api-version override, always use SDK default

Reverts to main's behavior: pass no api_version to KnowledgeBaseRetrievalClient
(SDK default is the latest 2026-05-01-preview) and forward query_source_authorization
unconditionally. The override and version-gate were only added while debugging a 502
that turned out to be a regional outage, not a version problem.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Consolidate duplicate agentic query plan e2e tests

Delete the weaker test_chat_agentic_query_plan and keep the stricter
test, renamed to test_agentic_retrieval_query_plan for consistency with
the other test_agentic_retrieval_* tests. Trim verbose backend-detail
comments from the docstring and body.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…ut (#3144)

* Handle Easy Auth redirect on /auth_setup fetch to fix CORS after logout

Use redirect: "manual" so a 302 from Container Apps / App Service Easy Auth
to login.microsoftonline.com does not surface as a CORS error on the initial
fetch. When we see an opaqueredirect response, reload the page so the browser
follows the redirect at the top level and the login flow can complete.

Fixes #1780

* Address review: document why the never-resolving Promise is intentional
…#3093)

* chore(deps): bump esbuild, @vitejs/plugin-react and vite

Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependencies [esbuild](https://github.com/evanw/esbuild), [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) and [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together.


Removes `esbuild`

Updates `@vitejs/plugin-react` from 4.7.0 to 6.0.2
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.2/packages/plugin-react)

Updates `vite` from 6.4.3 to 8.0.16
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version:
  dependency-type: indirect
- dependency-name: "@vitejs/plugin-react"
  dependency-version: 6.0.2
  dependency-type: direct:development
- dependency-name: vite
  dependency-version: 8.0.16
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* Drop Node 20 support: bump CI matrix and engines.node for vite 8

vite 8 requires Node >=22.12.0. Update the test matrix to [22, 24] (matches
the current Cloud Shell Node 24), bump the azure-dev workflow to Node 22,
and pin engines.node to >=22.12.0. Node 20 hit EOL in April 2026.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pamela Fox <pamelafox@microsoft.com>
Bumps the github-actions group with 1 update: [DavidAnson/markdownlint-cli2-action](https://github.com/davidanson/markdownlint-cli2-action).


Updates `DavidAnson/markdownlint-cli2-action` from 23 to 24
- [Release notes](https://github.com/davidanson/markdownlint-cli2-action/releases)
- [Commits](DavidAnson/markdownlint-cli2-action@v23...v24)

---
updated-dependencies:
- dependency-name: DavidAnson/markdownlint-cli2-action
  dependency-version: '24'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the pallets group with 1 update: [click](https://github.com/pallets/click).


Updates `click` from 8.4.1 to 8.4.2
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](pallets/click@8.4.1...8.4.2)

---
updated-dependencies:
- dependency-name: click
  dependency-version: 8.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pallets
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pymupdf](https://github.com/pymupdf/pymupdf) from 1.27.2.3 to 1.28.0.
- [Release notes](https://github.com/pymupdf/pymupdf/releases)
- [Changelog](https://github.com/pymupdf/PyMuPDF/blob/main/changes.txt)
- [Commits](pymupdf/PyMuPDF@1.27.2.3...1.28.0)

---
updated-dependencies:
- dependency-name: pymupdf
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…3154)

Bumps [prettier](https://github.com/prettier/prettier) from 3.8.1 to 3.9.4.
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](prettier/prettier@3.8.1...3.9.4)

---
updated-dependencies:
- dependency-name: prettier
  dependency-version: 3.9.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…end (#3156)

Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) from 26.0.1 to 26.1.1.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 26.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [rollup-plugin-visualizer](https://github.com/btd/rollup-plugin-visualizer) from 5.12.0 to 7.0.1.
- [Changelog](https://github.com/btd/rollup-plugin-visualizer/blob/master/CHANGELOG.md)
- [Commits](btd/rollup-plugin-visualizer@v5.12.0...v7.0.1)

---
updated-dependencies:
- dependency-name: rollup-plugin-visualizer
  dependency-version: 7.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Replace the 9 `existing` resourceGroups resources with computed name
variables used via `scope: az.resourceGroup(<name>)`. Under Bicep
languageVersion 2.0 (symbolic-name codegen), a conditional `existing`
resourceGroups resource whose name equals the main resource group name
collides with the main resource group ("defined multiple times"), and the
sequencer self-dependency error also surfaces. Removing those resources
eliminates the collision so the template is valid whether Bicep compiles
it as 1.0 or 2.0, without changing deploy behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…d popup redirect-bridge scaffolding (#3148)

* Proxy /redirect to backend in vite dev config

MSAL best-practice is that the popup redirect URI (/redirect) should
be an empty page that does NOT load MSAL, so the parent window's popup
client can scrape the auth code from the popup's URL and close it.
The backend /redirect route returns an empty response for exactly this
reason, but the vite dev server did not proxy /redirect, so in local
dev the popup landed on vite's index.html fallback which re-initialized
MSAL and prevented the parent from completing the login flow.

Manifested with msal-browser 5.x, which is stricter about this pattern.

* AGENTS.md: add local-dev popup login step to auth manual test plan

The deployed site uses Easy Auth redirect flow; local dev uses MSAL
popup. These are separate code paths and previous msal-browser
upgrades silently broke the popup flow because vite wasn't proxying
/redirect to the backend. Add an explicit step so future upgrades
catch this before merging.

* Fix MSAL popup login on msal-browser 5.x by running the redirect bridge

msal-browser 5.x replaced the old "parent polls popup.location.href" popup
handshake with a BroadcastChannel bridge: the popup redirect URI must run
broadcastResponseToMainFrame() (from @azure/msal-browser/redirect-bridge)
to post-message the auth response back to the opener and close itself.
Our backend was serving /redirect as an empty page (correct for msal-browser 4.x
but a no-op in 5.x), so the popup landed on /redirect#code=... and just sat
there with no way to hand the code back to the parent.

Supersedes the earlier vite.config.ts + AGENTS.md commits on this branch;
the vite proxy addition was reverted here since the SPA fallback is what we
actually want at /redirect.

Changes:
* app/backend/app.py: /redirect now serves index.html so the SPA loads there
  in both prod and local dev, giving the bridge script a chance to run.
* app/frontend/src/index.tsx: before mounting the app, detect that this
  window was opened by MSAL as a popup and carries an auth response, then
  call broadcastResponseToMainFrame(). It broadcasts + closes the popup;
  the throw prevents the SPA from partially mounting in the popup and
  fighting with the parent frame's handshake.
* app/frontend/vite.config.ts: revert the /redirect proxy entry — no longer
  needed now that /redirect serves index.html via the vite SPA fallback.
* tests/test_app.py: /redirect now returns HTML (index.html) not an empty
  body — update assertion accordingly.
* AGENTS.md: update the popup-fails hint under the auth manual test plan
  to point at index.tsx + the redirect-bridge.

* Follow MSAL best practice: use a dedicated redirect.html popup page

Per MSAL docs (msal-browser/docs/login-user.md#redirecturi-considerations),
the popup redirect URI must be a minimal dedicated page containing ONLY the
redirect-bridge script — no routing, no other application code — so it does
not interfere with the BroadcastChannel handshake used since msal-browser 5.x.

The previous approach in this branch loaded the full SPA at /redirect and
did an early throw before mounting; that worked but violated MSAL guidance
and forced the popup to download the entire ~1.9MB SPA bundle.

Refactor to a proper dedicated entry point:

* app/frontend/redirect.html: minimal HTML with <title>Signing in</title>
  and a single module script.
* app/frontend/src/redirect.ts: only imports broadcastResponseToMainFrame
  from @azure/msal-browser/redirect-bridge and invokes it.
* app/frontend/vite.config.ts:
  - Add redirect.html as a second rollup input entry.
  - Isolate @azure/msal-browser / @azure/msal-common into a dedicated 'msal'
    chunk so the redirect entry does not pull in React/Fluent UI/vendor.
  - Add a small dev middleware that aliases /redirect to /redirect.html so
    the popup redirect URI matches production without a trailing .html.
* app/frontend/src/index.tsx: revert the popup-detection hack — no longer
  needed now that the popup loads redirect.html instead of index.html.
* app/backend/app.py: /redirect now serves redirect.html (not index.html).
* AGENTS.md: update the debugging hint to point at redirect.html + redirect.ts.

Popup entry-point size dropped from the full ~1.9MB SPA bundle to just
redirect.js (195 bytes) + msal.js (235KB gzip 59KB).

* Keep LoginContext in sync with MSAL events (msal-react best practice)

Per msal-react docs (hooks.md#usemsal-hook):

  > If your component relies on instance.getActiveAccount(), be aware that
  > getActiveAccount() may return null immediately after authentication
  > completes. This happens because the render triggered by
  > ACQUIRE_TOKEN_SUCCESS can run before setActiveAccount() has been called.
  > To handle this, subscribe to the ACTIVE_ACCOUNT_CHANGED event and retry
  > your logic when the active account becomes available.

LayoutWrapper was only calling checkLoggedIn(instance) once on mount, and
LoginButton relied on chaining setLoggedIn off loginPopup().then() — which
races the LOGIN_SUCCESS event handler that actually calls setActiveAccount.

Fix: subscribe to LOGIN_SUCCESS, LOGOUT_SUCCESS, ACTIVE_ACCOUNT_CHANGED and
ACQUIRE_TOKEN_SUCCESS events in LayoutWrapper and re-run checkLoggedIn on
each. This way the loggedIn state (and downstream UI: LoginButton username,
QuestionInput enabled state, etc.) stays authoritatively driven by MSAL
instead of by promise-chain timing.

* checkLoggedIn/getUsername: fall back to getAllAccounts() when no active account

Root cause of the popup UI not updating after login (per browser log the events
fire correctly and refresh runs, but checkLoggedIn returned false):

  * msal-browser fires ACQUIRE_TOKEN_SUCCESS before LOGIN_SUCCESS.
  * Our index.tsx handler only calls setActiveAccount() on LOGIN_SUCCESS.
  * checkLoggedIn / getUsername / getTokenClaims all use getActiveAccount(),
    which returns null between ACQUIRE_TOKEN_SUCCESS and setActiveAccount()
    running \u2014 so both refresh() calls in LayoutWrapper saw no account and
    setLoggedIn(false).

msal-react's own useIsAuthenticated hook works around this by checking
accounts.length > 0 (i.e. getAllAccounts()) instead of getActiveAccount().
Adopt the same pattern here: prefer active account, fall back to first cached
account. The account is populated in getAllAccounts() as soon as MSAL processes
the token response, so this no longer races setActiveAccount().

Also fix LoginButton's username useEffect: it was pinned to [] and never re-ran,
so even if setLoggedIn eventually flipped to true, the button still rendered an
empty username. Depend on [instance, loggedIn] so it refreshes on state change.

* postLogoutRedirectUri should also be /redirect for popup logout

logoutPopup lands the popup on postLogoutRedirectUri when Entra finishes
signing the user out. That URL was previously "/" (the main app root),
so after logout the popup rendered the full SPA instead of running the
redirect-bridge and closing itself.

Point postLogoutRedirectUri at /redirect too, so the bridge script broadcasts
the logout response back to the opener and calls window.close(). The
mainWindowRedirectUri: "/" already passed per-call in LoginButton.tsx
takes care of navigating the parent window to "/" after logout completes.

/redirect is already registered as an SPA redirect URI in scripts/auth_update.py,
so no Entra app registration change is required.

* Cache negative /.auth/me result so checkLoggedIn doesn't spam 404s

Local dev (and any deploy without Easy Auth) has no /.auth/me endpoint,
so getAppServicesToken() got a 404 on every call. checkLoggedIn /
getUsername / getTokenClaims all fall back to getAppServicesToken(), and
LayoutWrapper now calls checkLoggedIn on every MSAL event (LOGIN_SUCCESS,
ACQUIRE_TOKEN_SUCCESS, ACTIVE_ACCOUNT_CHANGED, ...) — resulting in a
storm of red 404s in the console after every login.

Latch a globalThis.appServicesAuthUnavailable flag on the first 404
(Easy Auth availability is a deployment-time property, not something
that flips at runtime) and short-circuit further getAppServicesToken()
calls to Promise.resolve(null).

* chore(deps): upgrade @azure/msal-browser to 5.17 and @azure/msal-react to 5.5 (#3139)

* Fall back to first cached account in logout handler

getActiveAccount() can be null between an MSAL token event and our
setActiveAccount() handler (same msal-browser 5.x race that
checkLoggedIn/getUsername already handle). Fall back to
getAllAccounts()[0] so logoutPopup always fires, instead of accidentally
routing to appServicesLogout() and navigating the top window to
/.auth/logout.

* Handle Easy Auth 302 to Entra on API fetches

When the Container Apps / App Service Easy Auth session cookie is
missing or expired, Easy Auth returns a 302 to login.microsoftonline.com
for every request. The browser blocks the cross-origin redirect on a
same-origin fetch (CORS: 'No Access-Control-Allow-Origin header'), so
API calls like /chat/stream fail hard.

Wrap fetch in fetchWithAuthRedirect() that uses redirect: 'manual' and
reloads the page on opaqueredirect — the browser can follow the
cross-origin 302 on a top-level navigation and Easy Auth will complete
the sign-in flow. Same pattern that fetchAuthSetup() already uses for
/auth_setup (issue #1780).

* prettier: format redirect.html

* Consolidate active-or-first-account fallback into a helper

- Add getActiveOrFirstAccount(client) helper in authConfig.ts.
- Use it in checkLoggedIn, getUsername, getTokenClaims, and
  LoginButton.handleLogoutPopup instead of repeating the
  getActiveAccount() ?? getAllAccounts()[0] pattern with duplicated
  explanatory comments.
- Remove dead activeAccount local in TokenClaimsDisplay (declared but
  never read).

* Expand redirectAlias comment to explain why we don't proxy to Quart

* AGENTS.md: use <AUTH_ENV_NAME> placeholder instead of hardcoded env

* Address Copilot review comments

- test_redirect docstring: /redirect serves redirect.html (not
  index.html); update comment to match.
- AGENTS.md step 7: rewrite the msal-browser 5.x explanation to
  describe the actual design (dedicated bridge page + vite
  middleware rewrite in dev, Quart route in prod) instead of the
  stale "empty page proxied to backend" wording.
- authConfig.ts appServicesAuthUnavailable: only latch on HTTP 404
  from /.auth/me. Other statuses (401 session-expired, 403,
  transient 5xx) can recover on the next call.
- AnalysisPanel.tsx fetchCitation: activeCitation.indexOf('#')
  returns -1 (truthy) when '#' is absent, so the ternary was
  running the split branch and yielding undefined. Use
  String.prototype.includes for correctness.
* Upgrade default eval model from gpt-4.1 to gpt-5.4

The gpt-4.1 model is deprecated. Bump the default evaluation model
deployment to gpt-5.4 (version 2026-03-05) and update the docs.
Validated by provisioning the eval deployment in an azd env and
confirming it responds via the chat completions API.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Vendor evaltools with reasoning-model (gpt-5) support

The gpt-5.4 eval model upgrade broke evaluate.py because the upstream
ai-rag-chat-evaluator pinned azure-ai-evaluation==1.8.0, which sends
max_tokens (rejected by reasoning models) and lacks is_reasoning_model.

Vendor a lean subset of evaltools into evals/evaltools/ (eval runner,
metrics, service setup, markdown summary/diff CLI) so we can:
- construct the LLM-judged evaluators with is_reasoning_model=True, sending
  max_completion_tokens instead of max_tokens
- require azure-ai-evaluation>=1.18.0
- read the unprefixed rating columns (groundedness/relevance) that newer
  azure-ai-evaluation emits, while keeping gpt_* registry/summary keys for
  baseline continuity

Drops the promptflow-based prompt metrics and Textual TUI reviewers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Sort evaluate.py imports with evaltools as first-party

Vendoring evaltools into evals/ makes it a first-party import, so ruff's
isort groups it separately from third-party packages.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Trim unused service_setup functions from vendored evaltools

Remove get_openai_config_dict (only used by the dropped azure-ai-generative
generate flow) and get_search_client (unused), plus their now-unused
AzureKeyCredential and SearchClient imports.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove vendored evaltools LICENSE.md

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Consolidate citation metrics into vendored evaltools

Replace the inferior vendored has_citation/citation_match metrics with the
better file-extension-aware any_citation/citations_matched metrics (moved from
evals/evaluate.py into evaltools code_metrics.py). Removes the duplicate class
definitions and register_metric calls from evaluate.py so there is a single set.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add unit tests for vendored evaltools + rename evaluate.py

- Rename evals/evaluate.py -> evals/run_evaluate.py to disambiguate from
  the vendored evaltools library evaluate.py
- Add evals/tests/ with unit tests for send_question_to_target and the
  vendored code + builtin metrics, adapted from ai-rag-chat-evaluator
- Scope main pytest run to tests/ via testpaths so it does not collect
  evals/tests (which needs the evals requirements)
- Add .github/workflows/evals-test.yaml to run evals tests in CI

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add gpt-5.4-judged baseline eval runs and refresh baseline summary

Run the full 50-question eval suite 4 times against pf-ragchat-public
using the new gpt-5.4 judge (replacing the deprecated gpt-4.1 judge) and
regenerate results_summaries/baseline.{md,json} from these runs.

New baseline vs old gpt-4.1-judged baseline: groundedness pass 0.985->0.99,
relevance pass 0.895->0.95, means and other metrics stable within CIs.
Old gpt54-low-top5-run* folders kept for historical reference.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address PR review comments and add review utils tests

- Guard isclose stat comparison and fix ragged-row column count in review/utils
- Replace mutable default args and fix health-check deployment/model resolution in evaluate
- Make cli directory2 argument optional with proper type
- Use monkeypatch.setattr for requests.post in test_evaluate
- HTML-escape question/answer/truth/directory name in diff_markdown
- Add type annotations so ty check passes on evaltools
- Add unit tests for diff_directories, summarize_results, and diff_markdown escaping

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Add ty type-checking of vendored evaltools to evals CI

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Inline single-use config helpers in run_evaluate.py

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address PR review comments on copied evaltools

- diff_markdown: use tuple form of isinstance for style consistency
- diff_markdown: skip questions not present in every run to avoid KeyError
- utils.diff_directories: raise ValueError when --changed has <2 dirs
- utils.summarize_results: sort stat columns for deterministic output
- summary_markdown: use len(headers) for separator row (clarity)
- code_metrics.citations_matched: guard num_citations==0 (avoid ZeroDivisionError)
- evaluate: drop dead OPENAI_GPT_MODEL fallback since run_evaluate.py always passes model

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Drop OpenAI.com pathway from evals service setup

run_evaluate.py is the sole caller and always supplies an Azure
openai_config, so the OpenAI.com (OPENAICOM_KEY / organization) branch
was dead code. Simplify get_openai_config / get_openai_client to
Azure-only and drop the now-unused OpenAIModelConfiguration type and
cast import.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Default eval jmespath to output_text; write relative testdata_path

- Change target_response_answer_jmespath default to output_text across
  send_question_to_target, run_evaluation, and run_evaluate_from_config
  to match the app's Responses-API shape
- Update send_question_to_target tests to the output_text response shape
- Write testdata_path in evaluate_parameters.json relative to results_dir
  instead of an absolute path, and fix the 4 committed sample artifacts

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address PR review: use AZURE_OPENAI_ENDPOINT, consolidate credential path, add request timeout

- run_evaluate.py: use AZURE_OPENAI_ENDPOINT env var directly
- service_setup.py: single credential path in get_openai_client; remove dead get_azd_credential helper and unused AzureDeveloperCliCredential import
- evaluate.py: add timeout to target requests.post; str() cast in truncate_for_log
- test_evaluate.py: accept **kwargs in requests.post mocks

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Harden eval schema checks, guard empty stats, and go keyless-only

- Treat missing answer/output_text as a schema violation in send_question_to_target
- Guard get_aggregate_stats_for_numeric_rating against empty input (no ZeroDivisionError)
- Standardize eval auth on keyless (drop unused AZURE_OPENAI_KEY path)

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Escape metric cells in diff markdown; use Responses API for eval smoke test

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix evals CI ty check silently passing on evaltools

ty check evals/evaltools was a no-op: pyproject.toml's [tool.ty.src] include
list intentionally excludes evals/evaltools, so passing the directory path was
filtered out and ty found no files to check ('No python files found', always
green). Override src.include in the evals-test job so ty actually type-checks
the vendored package where eval-only deps are installed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix eval review table misalignment and non-numeric diff arrows

- summarize_results(): drop metrics with no recognized stat (e.g. num_questions
  which only carries a 'total' key). Previously such a metric added a header
  column with no matching data cells, misaligning the table and truncating
  columns via zip(*rows). The per-run question count is already shown by the
  appended 'n' column.
- diff_markdown.main(): only compute the up/down arrow when both the compared
  value and the baseline value are numeric. A metric numeric in the baseline run
  could be a non-numeric placeholder (e.g. the string 'Failed') in a later run,
  which raised TypeError on value > first_value and broke 'evaltools diff'.
  Also compare against the already-rounded first_value instead of re-reading raw.
- Add tests for both cases.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Address PR review: preserve traceback, surface HTTP errors, validate highlight run, fix docs examples

- send_question_to_target(): use bare 'raise' instead of 'raise e' to preserve
  the original traceback when raise_error=True, and call r.raise_for_status()
  after the POST so 4xx/5xx responses surface as HTTP errors with status codes
  rather than being misreported as JSON/schema problems.
- summary_markdown.main(): validate the --highlight run name and raise a helpful
  ValueError listing available runs instead of a bare 'x is not in list'.
- docs/evaluation.md: replace the non-existent results/baseline/ example paths
  with clear RUNHERE/FIRSTRUNHERE/SECONDRUNHERE placeholders.
- Add tests for the HTTP-error paths and summary_markdown highlight behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix latency aggregation and attribution

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Use tenant credential for eval judges

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Migrate to Azure AI Foundry account + project

Deploy the Azure AI account as an Azure AI Foundry account (kind: 'AIServices'
with allowProjectManagement) and create a Foundry project inside it, replacing
the classic kind: 'OpenAI' account. Models are still deployed on the account, so
the backend endpoint (*.openai.azure.com) and all AZURE_OPENAI_* env vars are
unchanged.

- Add infra/core/ai/ai-foundry-project.bicep: project resource + project-scoped
  RBAC (Azure AI Project Manager for the deploying user, Azure AI User for the
  backend identity) + name/endpoint outputs.
- Bump the account AVM module to 0.15.0 for allowProjectManagement support.
- Gate Foundry behavior on self-created accounts only: bring-your-own accounts
  (AZURE_OPENAI_SERVICE set) keep their existing kind and get no project, so
  classic Azure OpenAI accounts keep working unchanged.
- Refactor private-endpoints.bicep to support multiple DNS zones per endpoint;
  the Foundry PE resolves services.ai.azure.com in addition to openai.azure.com
  and cognitiveservices.azure.com.
- Add FOUNDRY_PROJECT_NAME / FOUNDRY_PROJECT_ENDPOINT outputs and wire
  foundryProjectName through main.parameters.json and both CI pipelines.
- Document BYO behavior in docs/deploy_existing.md.

Resolves #3084

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Ignore compiled Bicep output (infra/main.json)

`az bicep build` emits infra/main.json / infra/main.test.json next to the
templates; these are build artifacts and should never be committed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fully skip Azure OpenAI provisioning for bring-your-own accounts

Previously the openAi AVM module still ran for bring-your-own (BYO)
existing accounts, upserting the account and pushing model deployments,
which made the conditional logic hard to follow. Now the module only
runs on a fresh Foundry deploy (deployFoundryAccount). For BYO we skip
the account, model deployments, Foundry project, and private endpoint
entirely, only keeping the RG-scoped role assignments the app's managed
identity needs.

- Gate openAi module and its private endpoint on deployFoundryAccount
- Simplify the module (always AIServices + allowProjectManagement) and
  the private-endpoint DNS zone list (always the three Foundry zones)
- Add openAiServiceNameResolved / openAiEndpointResolved helper vars so
  env vars + outputs work across fresh / BYO-existing / custom paths;
  BYO endpoint is string-built to match the backend's derivation
- Document that BYO users must pre-create model deployments and manage
  their own private networking

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: explain why ai-foundry-project.bicep isn't an AVM module

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix BYO gating: deploy Foundry account on openAiHost intent, not openAiServiceName

AZURE_OPENAI_SERVICE is also a bicep output azd persists after every deploy,
so gating deployFoundryAccount on empty(openAiServiceName) wrongly skipped the
account on redeploys. Gate on isAzureOpenAiHost && deployAzureOpenAi (matching
upstream); azure_custom remains the don't-touch BYO path. Reuse openAiServiceName
for the account name/subdomain idempotently. Fix docs note accordingly.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* fix(infra): keep Foundry template in classic ARM mode to avoid RG collision

Pin the openAi AVM account module to 0.14.0 (was 0.15.0) and drop the
user-defined type in ai-foundry-project.bicep. Both 0.15.0 and UDTs force
the compiled template into symbolic-name mode (languageVersion 2.0), where
the many same-named `existing` resourceGroups references collide during ARM
validation ("resourceGroup ... is defined multiple times"), breaking real
azd provision. 0.14.0 is the newest account version that supports
allowProjectManagement while compiling to classic mode.

Validated with a live `azd provision`: the AIServices account flips to a
Foundry account (allowProjectManagement=true) and the Foundry project is
created, with FOUNDRY_PROJECT_NAME / FOUNDRY_PROJECT_ENDPOINT populated.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix safety-eval callback for Responses API response shape

The non-streaming /chat response now returns the assistant answer in
'output_text' (Responses API migration), not 'message'. Update the
adversarial simulator callback to build the assistant turn from
output_text so ContentSafetyEvaluator receives the app's reply.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Fix VPN gateway SKU to AZ variant (VpnGw2AZ)

Azure no longer allows non-availability-zone VPN gateway SKUs and rejects
them with NonAzSkusNotAllowedForVPNGateway. Switch the P2S VPN gateway
(AZURE_USE_VPN_GATEWAY=true path) from VpnGw2 to VpnGw2AZ.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs: correct reuse-existing NOTE — in-place Foundry upgrade

The reuse-by-name flow (OPENAI_HOST=azure + AZURE_OPENAI_SERVICE) runs the
same AVM account module (kind: AIServices + allowProjectManagement) against
the existing account and creates a Foundry project. A classic kind: 'OpenAI'
account is therefore upgraded in place (Microsoft's documented non-destructive
upgrade) and can host a project. The prior NOTE was misleading. Clarify that
only the azure_custom bring-your-own path leaves an account untouched.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): tighten deployFoundryAccount comment

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): drop redundant Foundry account comments

Remove the languageVersion 2.0 / #3146 rationale (already documented where
the plain-string RG vars are defined) and the duplicate module-level header,
keeping the inline comment on the kind/allowProjectManagement params.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): move Foundry account comment above the module

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* refactor(infra): rename openAi module to foundry for clarity

Rename the Cognitive Services account module symbol and deployment name
from openAi to foundry to make it clear it provisions a Microsoft Foundry
(AIServices) account. Params/vars/outputs that map to azd env vars
(openAiHost, openAiServiceName, AZURE_OPENAI_*) are unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* refactor(infra): rename foundry module to foundryAccount

Pairs with the foundryProject module (account vs. project inside it).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): link private DNS zone reference for Foundry account

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): fix private DNS zone reference link

Point to private-endpoint-dns (the page that actually lists the Foundry
Tools account zones), not private-endpoint-dns-integration.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* docs(infra): tighten DNS zone comment

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Fix azd target environment loading

Replace the duplicated local environment loaders with dotenv-azd so azd resolves AZURE_ENV_NAME consistently in hooks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Use consistent azd environment override behavior

Honor LOADING_MODE_FOR_AZD_ENV_VARS at every dotenv-azd call site so backend, scripts, and evals share one policy.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Test azd loading modes in script entry points

Verify both override modes and ensure the ADLS and Cosmos migration entry points continue into their orchestration paths.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* Upgrade agentic knowledge base model

Default new agentic knowledge base deployments to gpt-5-mini version 2025-08-07 while preserving all existing model, version, deployment, SKU, and capacity overrides. Update the agentic retrieval deployment guide to match.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* Use GPT-5.4 for agentic knowledge base

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* Apply suggestion from @pamelafox

* Apply suggestion from @pamelafox

* Fix knowledge base environment variable names

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* Evaluate GPT-5.4 agentic retrieval

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* Compare agentic knowledge base models

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* Restore default evaluation mode

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2
* Default agentic retrieval to minimal

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* test: add capacity-matched retrieval evals

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* docs: add eval throttling guidance

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

* docs: clarify evaluation capacity setup

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: be4e7d97-2903-4a98-ab69-6f245f2f67b2

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
* fix creation of knowledgebase in cloud ingestion

* small fix after running py -m black

* leave cloudingestionstrategy unchanged.

* leave cloudingestionstrategy unchanged, remove empty line.
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.2.0 to 12.3.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](python-pillow/Pillow@12.2.0...12.3.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.3.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…3176)

Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.11 to 3.4.12.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@3.4.11...3.4.12)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.12
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.13.3 to 6.14.2.
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](py-pdf/pypdf@6.13.3...6.14.2)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.14.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull merge-conflict Resolve conflicts manually

Projects

None yet

Development

Successfully merging this pull request may close these issues.