Skip to content

SSL context caching to lower overhead of per-turn httpx.AsyncClient creation - #608

Merged
Rodrigo Brandão (rodrigobr-msft) merged 8 commits into
mainfrom
users/robrandao/teams
Oct 1, 2026
Merged

Rodrigo Brandão (rodrigobr-msft) merged 8 commits into
mainfrom
users/robrandao/teams

Conversation

@rodrigobr-msft

Copy link
Copy Markdown
Contributor

This pull request introduces significant performance improvements and dependency updates for the Teams API client, along with supporting changes to resource cleanup and development setup. The most important changes are summarized below.

Teams API Client Performance and Resource Management:

  • Added caching of the SSL context in _teams_api_client.py to avoid repeated CA certificate loading and reduce client initialization overhead, significantly improving performance for high-traffic agents.
  • Refactored Teams API client construction to use a shared _client function that leverages the cached SSL context. [1] [2]
  • Added an on_after_turn hook to ensure the Teams API client's HTTP resources are properly closed after each turn, preventing resource leaks.

Dependency Updates:

  • Updated the microsoft-teams-api dependency to version 2.1.0 in both setup.py and the changelog. [1] [2]

Development and Test Setup:

  • Ensured the microsoft-agents-hosting-msteams package is installed in editable mode in both development setup scripts (dev_setup.sh and dev_setup.ps1). [1] [2]
  • Adjusted test helper to no longer pre-cache the ApiClient in the test context, aligning with the new client lifecycle.

@github-actions

Copy link
Copy Markdown

Teams API drift analysis

Compared 2.0.16 to 2.1.0.
blocking: 1 · no-action: 119 · required: 0 · review: 8

  • TSAPI-0066 — review · symbol-added: microsoft_teams.api.clients.AGENTIC_IDENTITY_CLEAR
  • TSAPI-0067 — review · symbol-added: microsoft_teams.api.clients.AgenticIdentityClear
  • TSAPI-0068 — review · symbol-added: microsoft_teams.api.clients.AgenticIdentityScope
  • TSAPI-0069 — blocking · constructor-changed: microsoft_teams.api.clients.api_client.ApiClient.__init__
  • TSAPI-0070 — review · method-added: microsoft_teams.api.clients.api_client.ApiClient.clone

Download the complete deterministic report and evidence

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Client cleanup is not guaranteed on failure paths, and the custom HTTP client unintentionally changes timeout behavior.

Review effort: Balanced
Findings: 2 Medium severity · 4 Low severity

Open (6)
What changed in this PR

Improves per-turn Teams API client performance and lifecycle management while updating dependencies and development setup.

Changes:

  • Caches SSL context creation and centralizes HTTP client construction.
  • Adds per-turn client cleanup.
  • Updates Teams API dependency and editable-install scripts.
File Description
tests/​hosting_msteams/​helpers.py Removes test client pre-caching.
scripts/​dev_setup.sh Installs the M365 Teams package.
scripts/​dev_setup.ps1 Installs the M365 Teams package.
libraries/​microsoft-agents-hosting-msteams/​setup.py Updates Teams API to 2.1.0.
libraries/​microsoft-agents-hosting-msteams/​microsoft_agents/​hosting/​msteams/​teams_agent_extension.py Registers client cleanup after turns.
libraries/​microsoft-agents-hosting-msteams/​microsoft_agents/​hosting/​msteams/​_teams_api_client.py Adds cached SSL context and custom client construction.
changelog.md Documents performance and dependency updates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread libraries/microsoft-agents-hosting-msteams/setup.py
Comment thread tests/hosting_msteams/helpers.py

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Cleanup failures can still leak resources, and cached TLS configuration no longer honors custom CA environment settings.

Review effort: Balanced
Findings: 3 Medium severity · 1 Low severity

Open (4)
Resolved since last review (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Preserve HTTPX SSL certificate environment handling

libraries/​microsoft-agents-hosting-msteams/​microsoft_agents/​hosting/​msteams/​_teams_api_client.py:41

Constructing the cached context directly from certifi drops HTTPX's default SSL_CERT_FILE/SSL_CERT_DIR handling. Deployments that add a corporate or private CA through those standard environment variables will start failing TLS verification. Build the cached context with the same trust-environment semantics as HTTPX's default instead of hard-coding only the certifi bundle.

Comment thread tests/hosting_msteams/test_teams_agent_extension.py

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The test helper introduces an unused import that can fail linting, and the central SSL-context caching behavior lacks direct coverage.

Review effort: Balanced
Findings: None

Resolved since last review (4)
Previously missed (1)

In code that hasn't changed since last review

Low severity Add test verifying SSL context creation is cached

libraries/​microsoft-agents-hosting-msteams/​microsoft_agents/​hosting/​msteams/​_teams_api_client.py:42

The caching behavior that provides this PR's performance improvement is not asserted by the tests: the existing boundary test creates one client and would still pass if a fresh SSL context were built for every client. Add a test that creates multiple clients (or calls this helper repeatedly) while spying on ssl.create_default_context, and assert that context creation occurs only once.

@rodrigobr-msft
Rodrigo Brandão (rodrigobr-msft) merged commit 92c6aaf into main Oct 1, 2026
9 of 10 checks passed
@rodrigobr-msft
Rodrigo Brandão (rodrigobr-msft) deleted the users/robrandao/teams branch October 1, 2026 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants