Sad Tux - Windows bias detected
This page contains Windows bias

About This Page

This page is part of the Azure documentation. It contains code examples and configuration instructions for working with Azure services.

Bias Analysis

Detected Bias Types
windows_first
missing_linux_example
Summary
The documentation provides a C# example for generating the client secret JWT using the Microsoft.IdentityModel.Tokens NuGet package, which is Windows/.NET-centric. There are no examples or guidance for Linux-native tools or languages (such as Python, Node.js, or OpenSSL) that are commonly used on Linux platforms. The documentation does not mention or demonstrate how to perform these steps on Linux, nor does it reference Linux-specific tools or workflows.
Recommendations
  • Add examples for generating the client secret JWT using cross-platform or Linux-native tools, such as Python (PyJWT), Node.js (jsonwebtoken), or OpenSSL.
  • Include command-line instructions for Linux environments, such as using OpenSSL to handle the .p8 key and sign JWTs.
  • Reference Linux package managers (apt, yum) for installing necessary libraries, and provide sample scripts for Bash.
  • Clarify that the process is not limited to Windows/.NET and explicitly mention Linux compatibility.
  • Provide parity in code samples by showing both Windows/.NET and Linux/open-source approaches side-by-side.
GitHub Create Pull Request

Scan History

Date Scan Status Result
2026-01-12 00:00 #99 completed Biased Biased
2026-01-11 06:20 #98 completed Clean Clean
2026-01-11 00:00 #95 cancelled Clean Clean
2026-01-10 00:00 #92 completed Biased Biased
2026-01-09 00:00 #87 cancelled Clean Clean
2026-01-08 00:00 #84 in_progress Clean Clean
2026-01-06 22:28 #78 completed Clean Clean
2025-12-29 18:00 #48 cancelled Biased Biased
2025-12-22 00:00 #24 cancelled Clean Clean
2025-12-15 00:00 #7 completed Clean Clean
2025-12-14 05:05 #6 completed Clean Clean

Flagged Code Snippets

using Microsoft.IdentityModel.Tokens;

public static string GetAppleClientSecret(string teamId, string clientId, string keyId, string p8key)
{
    string audience = "https://appleid.apple.com";

    string issuer = teamId;
    string subject = clientId;
    string kid = keyId;

    IList<Claim> claims = new List<Claim> {
        new Claim ("sub", subject)
    };

    CngKey cngKey = CngKey.Import(Convert.FromBase64String(p8key), CngKeyBlobFormat.Pkcs8PrivateBlob);

    SigningCredentials signingCred = new SigningCredentials(
        new ECDsaSecurityKey(new ECDsaCng(cngKey)),
        SecurityAlgorithms.EcdsaSha256
    );

    JwtSecurityToken token = new JwtSecurityToken(
        issuer,
        audience,
        claims,
        DateTime.Now,
        DateTime.Now.AddDays(180),
        signingCred
    );
    token.Header.Add("kid", kid);
    token.Header.Remove("typ");

    JwtSecurityTokenHandler tokenHandler = new JwtSecurityTokenHandler();

    return tokenHandler.WriteToken(token);
}