Releases: AzureAD/microsoft-authentication-library-for-dotnet
Releases · AzureAD/microsoft-authentication-library-for-dotnet
Release list
4.90.1
New Features
- Added
IMsalWsTrustHttpClientFactory, allowing custom HTTP client factories to provide redirect-disabled, credential-policy-aware clients for federation metadata (MEX) and WS-Trust requests. AddedMsalError.TooManyRedirectsandMsalError.WsTrustCrossOriginRedirectNotSupportedfor redirect failures. #6165
Bug Fixes
- Hardened federation metadata and WS-Trust requests by requiring HTTPS, securely validating redirects, rejecting credential-bearing cross-origin redirects, and limiting redirect chains. #6165
- Fixed instance discovery so a custom authority port is not forwarded to the global discovery host, while preserving the port when discovery uses the authority host. #6155
- Fixed KeyGuard attestation to send the tenant ID as the MAA
client_idmetadata value without changing managed-identity client-ID handling or attestation-cache partitioning. #6200
Changes
- Updated
Microsoft.Azure.Security.KeyGuardAttestationfrom version 1.1.7 to 1.1.8. #6202
4.90.0
4.89.0
What's Changed
- Add repository guidance for AI agents by Bogdan Gavril (@bgavrilMS) in #6158
- Add Linux Attested Managed Identity Flow documentation by Gladwin Johnson VR (@gladjohn) in #6149
- Remove internal authority example from API docs by Bogdan Gavril (@bgavrilMS) in #6170
- Update SNI MTLS PoP Token Design documentation by Bogdan Gavril (@bgavrilMS) in #6171
- Add SNI mTLS E2E coverage for a non-exportable VBS-protected certificate by Gladwin Johnson VR (@gladjohn) in #6167
- Revise mTLS PoP acceptance-test matrix structure by Gladwin Johnson VR (@gladjohn) in #6161
- Add ICloudConfiguration for cross-cloud metadata resolution by Avery-Dunn in #6104
- Fix IMDSv2 SCHANNEL failures bypassing certificate re-mint retry by Robbie-Microsoft in #6173
- Always record RawStsErrorCode on MsalFailure metric by Sergei Smelov (@ssmelov) in #6175
- Add MSAL_MI_DISABLE_IMDS_V2 kill switch for managed identity by Robbie-Microsoft in #6178
- Add timeout for managed identity capability discovery by Robbie-Microsoft in #6181
- Pin GitHub Actions to full-length commit SHAs by Dan Fiedler (@danfiedler-msft) in #6182
New Contributors
- Dan Fiedler (@danfiedler-msft) made their first contribution in #6182
Full Changelog: 4.88.0...4.89.0
4.88.0
New Features
- Added user-assigned managed identity support for Azure Arc, including selecting the identity by client ID and validating the identity returned in the token response. #6128
- Added
WithRequestOverMtls()to managed identity token requests, enabling attested bearer-token acquisition over the IMDSv2 mTLS transport. #6086
Bug Fixes
- Fixed token-cache key collisions by length-prefixing additional cache-key components before hashing. #6137
- Populated authentication-result telemetry metadata on proactive background-refresh results. #6157
- Fixed mTLS PoP authority validation incorrectly rejecting sovereign-cloud aliases such as
login.chinacloudapi.cnandlogin.usgovcloudapi.net. #6153
4.87.0
What's Changed
- Expose
MsalServiceException.ErrorCodesForLoggingfor diagnostics in #6138 - Expose
WithOtelTagsEnricherfor managed identity requests in #6144 - Forward OpenTelemetry tags enricher to the client-assertion callback in #6142
- Add client-side opaque-token log scrubber in #6119
- Populate
ExecutionResult.Exceptionfor non-MSAL failures in #6139 - Use PSS padding in KeyGuard liveness probe (CodeQL SM03799) in #6141
- Remove managed identity support from
WithClaimsFromClient(confidential-client only) in #6113 - Remove experimental features from client setup in #6143
- Update Azure Arc managed identity API version from 2019-11-01 to 2020-06-01 in #6130
Full Changelog: 4.86.1...4.87.0
4.86.1
Bug Fixes
- Fixed the mTLS Proof-of-Possession token cache to key on the certificate's full DER (
x5t#S256) instead of only the public key, preventing a stale token (andAADSTS500181) after a same-key certificate renewal. #6123 - Fell back to RS256 when a certificate's PSS signing operation is rejected by
RSACryptoServiceProvider, rebuilding the client assertion so authentication can proceed. #6126 - Detect and reject symbolic links in the Unix cache-file write path (lstat pre-check plus
O_NOFOLLOW), closing a TOCTOU window. #6115 - Corrected misleading "region required" error messages and doc comments in the mTLS PoP flow. #6127
4.86.0
What's Changed
- Propagate KeyGuard attestation failures and bridge native MAA logs to the MSAL logger by Gladwin Johnson VR (@gladjohn) in #6081
- Token Binding Demo Helper by Gladwin Johnson VR (@gladjohn) in #6097
- Include ManagedIdentitySource in managed identity error messages and request-failure logs by Robbie-Microsoft in #6101
- Remove Mooncake (AzureChinaCloud) lab client from WAM dev apps by Ryan Auld (@RyAuld) in #6103
- Surface token-acquisition failure metadata on MsalException by Neha Bhargava (@neha-bhargava) in #6096
- Skip IMDS lookup for explicit regions by Nilesh Choudhary (@4gust) in #6092
- Fix region failure-metadata test broken by explicit-region IMDS skip by Neha Bhargava (@neha-bhargava) in #6105
Full Changelog: 4.85.2...4.86.0
4.85.2
What's Changed
- Delegate IMDSv2 mTLS-PoP token leg to internal TokenClient exchange (MSIv2 WithClaimsFromClient) by Robbie-Microsoft in #6070
- Enforce mTLS PoP minimum binding strength for Managed Identity (#6049 Phase 2) by Robbie-Microsoft in #6059
- Add refresh token cache partitioning support by Ignacio Inglese (@iNinja) in #6077
- Detach ImdsV2ManagedIdentitySource from AbstractManagedIdentity (refused-bequest cleanup) by Robbie-Microsoft in #6089
Full Changelog: 4.85.1...4.85.2
4.85.1
What's Changed
- Migrate OBO tests from old lab to ID4SLAB1 by Ryan Auld (@RyAuld) in #6021
- Mark regional SNI mTLS PoP test inconclusive on AAD test-slice Bearer downgrade by Neha Bhargava (@neha-bhargava) in #6084
- Expose canonical tag names per-metric by Sergei Smelov (@ssmelov) in #6076
Full Changelog: 4.85.0...4.85.1
4.85.0
What's Changed
- Fix proactive token refresh bypassing cancellation, leading to unbounded semaphore wait by Jayesh Shah (@jayesh-a-shah) in #6054
- Add GovFr, GovDe, GovSg to AzureCloudInstance enum by Bogdan Gavril (@bgavrilMS) in #6023
- Take home account from request, if not available elsewhere. by yowl in #5657
- Validate Azure region format to prevent region poisoning (fixes #6060) by Robbie-Microsoft in #6061
- Promote MsalServiceException.SubError to public by Neha Bhargava (@neha-bhargava) in #6063
- Migrate region discovery to IMDS /compute JSON endpoint (#6039) by Robbie-Microsoft in #6057
- fix: Service Fabric MI sends principalId for ObjectId; reject ClientId/ResourceId (mirror of #6066) by Neha Bhargava (@neha-bhargava) in #6069
- Exclude caller SDK telemetry from access token cache keys by Bogdan Gavril (@bgavrilMS) in #6074
- Add MSAL.NET telemetry enrichment by Sergei Smelov (@ssmelov) in #6071
New Contributors
- Jayesh Shah (@jayesh-a-shah) made their first contribution in #6054
- yowl made their first contribution in #5657
Full Changelog: 4.84.2...4.85.0