This is a security patch release of IdentityServer that hardens validation of pushed authorization requests (PAR). We recommend all 7.0.x users upgrade.
What's changed
- PAR: Pushed authorization requests are now rejected when the request's
client_iddoes not exactly match the authenticated client, as required by RFC 9126. CustomIPushedAuthorizationRequestValidatorimplementations remain responsible for enforcing this binding. - PAR: Implicit-only clients can no longer use
AllowUnregisteredPushedRedirectUris. These clients do not authenticate at the PAR endpoint, so they must register their redirect URIs. - PAR: When
AllowUnregisteredPushedRedirectUrisis enabled, unregistered redirect URIs must now use thehttpsscheme and must not matchValidationOptions.InvalidRedirectUriPrefixes. Registered redirect URIs, loopback handling, and custom redirect URI validators are unchanged.
Upgrade notes
- Implicit-only clients that relied on unregistered pushed redirect URIs must register those redirect URIs.
- Unregistered non-
httpsPAR redirect URIs (for examplehttp://localhostduring local development) must be registered or moved tohttps.
Full Changelog: f28cac9...is-7.0.10