github Azure/azure-sdk-for-net Azure.Security.KeyVault.Secrets_4.12.0-beta.2

pre-release3 hours ago

4.12.0-beta.2 (2026-09-27)

Features Added

  • Added IDisposable to SecretClient to release its internally owned HTTP pipeline and transport. Reuse clients and dispose them after all operations have completed; caller-provided transports are not disposed.
  • Added a narrowly scoped bearer-token fallback for attested managed-identity tenant eligibility denials, with the decision remembered by the Key Vault client for subsequent token acquisitions.
  • Added support for Proof-of-Possession (PoP) token binding in the Key Vault authentication policy.

Bugs Fixed

  • Fixed intermittent authentication failures by retrying requests rejected because the mTLS Proof-of-Possession certificate did not match the token binding.
  • Fixed a NullReferenceException in the challenge-based authentication policy that could occur when a Continuous Access Evaluation (CAE) claims challenge was received for an authority that had not yet been cached.
  • Fixed an issue in the challenge-based authentication policy where a cached authentication challenge, and the access token acquired for it, could be reused for a request to a different Key Vault or Managed HSM endpoint. The policy now resolves the challenge per request endpoint, ensuring a token acquired for one vault is never attached to a request to another.

Other Changes

  • Internal: the SecretClient transport now delegates to a TypeSpec-generated implementation. Public API surface, default service version, exception contracts, on-the-wire requests, and OpenTelemetry / DiagnosticListener activity names are all unchanged. SecretClientOptions (custom retry, transport, diagnostics allow-lists, AddPolicy entries) continues to flow end-to-end. The TypeSpec emitter incidentally adds one additive public type (AzureSecurityKeyVaultSecretsContext, the ModelReaderWriterContext required for AOT-friendly ModelReaderWriter round-trip), matching the sibling Azure.Security.KeyVault.Administration package convention.

Don't miss a new azure-sdk-for-net release

NewReleases is sending notifications on new releases.