Skip to content

Releases: AzureAD/microsoft-identity-web

4.16.0

Choose a tag to compare

@neha-bhargava neha-bhargava released this 01 Oct 17:47
9c5066e

What's Changed

Full Changelog: 4.15.0...4.16.0

4.15.0

Choose a tag to compare

@iarekk iarekk released this 21 Sep 11:13
2f227c6

Federated credentials and proof of possession

  • Federated credential token exchange derives cloud-specific audience and scope metadata from the authority host, with explicit overrides still supported. #3994
  • The Entra Sidecar /Validate endpoint accepts Signed HTTP Request proof-of-possession tokens for app-only client-credential flows. #4008
  • Credential Guard key attestation is available through the optional Microsoft.Identity.Web.KeyAttestation package and AddMicrosoftIdentityWebKeyAttestation() registration. #4004

Authentication and token acquisition

  • EasyAuth app-token acquisition returns an app-only authentication result produced through client credentials. #4015
  • Graph v4 credentials are attached only to destinations matching the configured absolute HTTPS origin; custom Graph proxy base URLs remain supported. #4012

Authorization and request validation

  • OWIN web APIs require a non-empty recognized scope or role unless ACL-based authorization is explicitly enabled. #4006 #4009
  • Explicitly configured missing scope or app-permission requirements now fail authorization. #4010
  • Local redirect paths containing control characters are rejected. #4028

Entra Sidecar reliability and validation

  • Invalid selected AgentUserId values return HTTP 400. #4011
  • Automatic forwarded-header processing is rejected outside Development when ForwardedHeaders_Enabled=true. #4018
  • Non-local Host headers are rejected outside Development except on /healthz. #4023
  • Windows containers use ContainerUser, and ACL authorization defaults are correctly applied to named bearer options. #4042

Dependency updates

  • Microsoft.Identity.Client and Microsoft.Identity.Client.KeyAttestation: 4.87.0 -> 4.90.0. #4003 #3994 #4052
  • Microsoft.Identity.Abstractions: 12.6.0 -> 12.7.0. #4020 #3994

Full changelog: 4.14.2...4.15.0

4.14.2

Choose a tag to compare

@gladjohn gladjohn released this 30 Jul 17:45
7f5a0b5

Dependencies updates

  • Bump the Microsoft.IdentityModel.* (Wilson) version to 8.22.0. See #3986.
  • Fix the net8.0 crypto floor to use the patched System.Security.Cryptography.Xml 8.0.4 (and its System.Security.Cryptography.Pkcs 8.0.1 dependency) instead of over-bumping to the 9.0.18 servicing line (CVE-2026-47302, -47304, -50525, -50648). net9.0 (9.0.18) and net10.0 (10.0.10) are unchanged. See #3989.

4.14.0

Choose a tag to compare

@neha-bhargava neha-bhargava released this 27 Jul 20:06
dc242d6

New features

  • Add MicrosoftIdentityOptions.PartitionAppTokenCacheByAudience to partition the app token cache by resource/audience. See #3979.
  • Expose MSAL's background token-refresh callback through Id.Web via TokenAcquisitionExtensionOptions.OnBackgroundTokenRefreshCompleted. See #3973.
  • Add MicrosoftIdentityOptions.UseFastUnboundedCache; stop short-circuiting the in-memory token cache serialization provider. See #3970.
  • OIDC FIC (Microsoft.Identity.Web.OidcFIC) now supports mTLS token binding. See #3851.

Bug fixes

  • Token binding: the CCA cache key now distinguishes a bound credential (UseBoundCredential = true) from its unbound equivalent; the certificate-error retry path invalidates the cache entry for the actual request mode (bearer vs mTLS PoP).
  • Forward the OpenTelemetry tags enricher onto the inner FIC client-assertion leg. See #3968.

Dependencies updates

  • Microsoft.Identity.Client → 4.87.0 (#3975)
  • Microsoft.Identity.Abstractions → 12.6.0 (#3976)
  • System.Security.Cryptography.Xml / System.Security.Cryptography.Pkcs → patched (CVE-2026-47302, -47304, -50525, -50648) (#3964)
  • notsecurity group: 1 update (#3965)

Full changelog: 4.13.2...4.14.0

4.13.2

Choose a tag to compare

@neha-bhargava neha-bhargava released this 16 Jul 21:47
bd0791c

What's Changed

Full Changelog: 4.13.0...4.13.2

4.13.0

Choose a tag to compare

@neha-bhargava neha-bhargava released this 10 Jul 06:28
f6d7aef

What's Changed

Full Changelog: 4.12.2...4.13.0

4.12.2

Choose a tag to compare

@gladjohn gladjohn released this 03 Jul 15:51
1253aee

Bug fixes

  • Make the Microsoft.Identity.Client.KeyAttestation dependency conditional on modern .NET (.NETCoreApp) targets. It transitively pulls the native-only Microsoft.Azure.Security.KeyGuardAttestation package, which ships no .NET Framework/netstandard-compatible assets and broke NuGet restore for .NET Framework (packages.config) projects. Microsoft.Identity.Web.Certificateless now multi-targets, and .NET Framework consumers use the netstandard2.0 asset without this dependency. See #3894.

4.12.1

Choose a tag to compare

@gladjohn gladjohn released this 03 Jul 13:46
5c00e04

Bug fixes

  • Preserve ManagedIdentity when converting AcquireTokenOptions to TokenAcquisitionOptions in TokenAcquirer. Previously the ITokenAcquirer.GetTokenForAppAsync / GetTokenForUserAsync paths silently dropped ManagedIdentity and fell back to the confidential-client path, breaking managed-identity mTLS PoP (e.g. MISE Native). See #3914.

Behavior changes

  • Sidecar: outbound HTTP redirects suppressed by default. The sidecar no longer follows outbound HTTP redirects; a new opt-in Sidecar:AllowOutboundRedirects flag (default false) restores the previous behavior. See #3906.
  • Sidecar: per-request isolation of downstream API options. Downstream API options resolved from the singleton IOptionsMonitor are now cloned per request (including fresh ExtraParameters / ExtraHeaderParameters / ExtraQueryParameters dictionaries), preventing request-scoped values from leaking across requests or racing under concurrency. See #3919.

Fundamentals

  • Build the solution in the PR pipeline before running tests. See #3911.
  • Restore OWIN 5.7.1 packages from the internal IDDP feed in the PR pipeline. See #3912.
  • Run the PR pipeline on the Wilson pool so integration/E2E tests can access the lab KeyVault. See #3913.

4.12.0

Choose a tag to compare

@iarekk iarekk released this 03 Jul 13:34
b192389

New features

  • Implement IAuthorizationHeaderProvider2 (from Microsoft.Identity.Abstractions 12.3.0) on DefaultAuthorizationHeaderProvider and the public BaseAuthorizationHeaderProvider, exposing the metadata-rich CreateAuthorizationHeaderInformation* surface (returning OperationResult) with binding-certificate propagation. DownstreamApi and MicrosoftIdentityMessageHandler now prefer IAuthorizationHeaderProvider2 for mTLS PoP and soft-deprecate the bound-only IBoundAuthorizationHeaderProvider path (kept as a fallback for source/binary compatibility). See #3899.
  • Populate TokenAcquisitionMetadata.ExpiresOn on AcquireTokenResult from the MSAL AuthenticationResult.ExpiresOn value. See #3905.

Bug fixes

  • Finalize the DownstreamApi request (headers, query parameters, content, and customizations) before creating the authorization header, adding Authorization only after signing so request-binding providers do not include it in their signed material. See #3902.

Dependencies updates

  • Update Microsoft.Identity.Abstractions to 12.4.0. See #3899, #3905.
  • Update MSAL.NET (Microsoft.Identity.Client / Microsoft.Identity.Client.KeyAttestation) to 4.85.2. See #3896.
  • Update Microsoft.IdentityModel.Protocols.WsFederation (Microsoft.Identity.Web.OWIN) to 5.7.1. See #3900.

4.11.0

Choose a tag to compare

@neha-bhargava neha-bhargava released this 23 Jun 23:01
72f20d1

What's Changed

New Contributors

Full Changelog: 4.10.0...4.11.0