Add required observability for OBO without logging PII.
-
Log:
- OBO success/failure
- token cache hit/miss
- user identifier (oid OR sub)
- tenant ID
-
Propagate OpenTelemetry correlation ID
-
Set correlation values in SQL SESSION_CONTEXT when enabled
-
Ensure SESSION_CONTEXT is not used for authorization
Add required observability for OBO without logging PII.
Log:
Propagate OpenTelemetry correlation ID
Set correlation values in SQL SESSION_CONTEXT when enabled
Ensure SESSION_CONTEXT is not used for authorization