github DuendeSoftware/products is-7.0.10
Duende IdentityServer 7.0.10

latest releases: is-8.0.9, is-7.4.13, is-7.3.5...
3 hours ago

This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.0.x users upgrade.

GHSA-mxv6-xwqj-ww2p

What's changed

  • PAR: Pushed authorization requests are now rejected when the request's client_id does not exactly match the authenticated client, as required by RFC 9126. Custom IPushedAuthorizationRequestValidator implementations remain responsible for enforcing this binding.
  • PAR: Implicit-only clients can no longer use AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs.
  • PAR: When AllowUnregisteredPushedRedirectUris is enabled, unregistered redirect URIs must now use the https scheme and must not match ValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.

Upgrade notes

  • Implicit-only clients that relied on unregistered pushed redirect URIs must register those redirect URIs.
  • Unregistered non-https PAR redirect URIs (for example http://localhost during local development) must be registered or moved to https.

Full Changelog: f28cac9...is-7.0.10

Don't miss a new products release

NewReleases is sending notifications on new releases.