Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: AzureAD/microsoft-authentication-library-for-dotnet
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 4.85.1
Choose a base ref
...
head repository: AzureAD/microsoft-authentication-library-for-dotnet
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 4.85.2
Choose a head ref
  • 5 commits
  • 36 files changed
  • 4 contributors

Commits on Jun 23, 2026

  1. Post-release 4.85.1: changelog and public API shipped move (#6085)

    Post-release 4.85.1: update changelog and move unshipped API to shipped
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    neha-bhargava and Copilot authored Jun 23, 2026
    Configuration menu
    Copy the full SHA
    e3784d8 View commit details
    Browse the repository at this point in the history

Commits on Jun 24, 2026

  1. Configuration menu
    Copy the full SHA
    3680c2f View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    cc4328d View commit details
    Browse the repository at this point in the history

Commits on Jun 25, 2026

  1. Add refresh token cache partitioning support (#6077)

    * Add refresh token cache partitioning support
    
    Extend the existing access token cache partition mechanism to refresh tokens,
    allowing callers who use WithCachePartitionKey to also partition their RTs.
    
    Changes:
    - MsalRefreshTokenCacheItem: add AdditionalCacheKeyComponents property,
      SHA256 hash appended to cache key, JSON serialization under 'ext' field
    - TokenCache: thread CacheKeyComponents to RT constructor, add
      FilterRefreshTokensByAdditionalKeyComponents filter in FindRefreshTokenAsync
    - FRT guard: Family Refresh Tokens are never partitioned (shared by design);
      partition filter is skipped during FOCI lookups (familyId non-null)
    - Backward compatible: old clients preserve the new 'ext' field via
      AdditionalFieldsJson round-trip; new clients handle missing 'ext' gracefully
    
    Tests:
    - 10 new unit tests covering cache key generation, FRT guard, serialization
      round-trip, backward compatibility, and integration with token acquisition
    - All existing AT partition, serialization, and FOCI tests continue to pass
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Address PR review feedback on RT cache partition
    
    Fix cache key casing by passing partition hash through GetCredentialKey's
    additionalKeys parameter so it gets lower-cased consistently.
    
    Fix iOS keychain collision by including partition hash in GetiOSService()
    for partitioned RTs.
    
    Rewrite tests with meaningful assertions: compare partitioned vs
    non-partitioned keys, simulate old MSAL by renaming ext field before
    deserialization, and validate lower-cased hash expectations.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Add silent acquire tests for RT partition filter
    
    Three new tests exercise the FindRefreshTokenAsync filter with
    mixed partitioned and non-partitioned RTs in cache:
    
    1. Silent with partition key finds partitioned RT and refreshes
    2. Silent without partition key does not find partitioned RT (MsalUiRequired)
    3. Mixed cache: partition isolates the correct RT for each flow
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Add partitionRefreshToken parameter to WithCachePartitionKey
    
    Existing callers use WithCachePartitionKey for AT-only partition.
    Adding RT partition to the same API would break them, so RT partition
    is opt-in via a new bool parameter (default false).
    
    WithCachePartitionKey(key, value) remains AT-only (backward compat).
    WithCachePartitionKey(key, value, partitionRefreshToken: true) partitions
    both AT and RT.
    
    Adds a warning log when a non-partitioned silent call finds a partitioned
    RT, helping developers catch mismatched partition usage.
    
    Adds backward-compat test verifying silent calls without partitionRefreshToken
    still find partitioned RTs.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Remove partitioned RT warning log
    
    The warning fires in the normal account transfer scenario where a
    partitioned RT coexists with a regular OIDC RT after session expiry.
    Not a misuse case, so the log would be noisy.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Make PartitionRefreshToken sticky across chained calls
    
    Use |= so that once partitionRefreshToken is set to true by any
    WithCachePartitionKey call, a subsequent call without it cannot
    accidentally reset it to false.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Add test for sticky PartitionRefreshToken across chained calls
    
    Verifies that calling WithCachePartitionKey with partitionRefreshToken
    true followed by a call without it does not reset the flag.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    * Include partition hash in ToLogString for partitioned RTs
    
    Ensures debug logs show the actual cache key including the partition
    hash, matching InitCacheKey and GetiOSService behavior.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    
    ---------
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    iNinja and Copilot authored Jun 25, 2026
    Configuration menu
    Copy the full SHA
    9fc3dc4 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    a06df82 View commit details
    Browse the repository at this point in the history
Loading