github DuendeSoftware/products is-8.1.0-preview.4
Duende IdentityServer 8.1.0-preview.4

pre-release4 hours ago

This is a preview release of IdentityServer 8.1.

Breaking changes

  • Structured log property names are now PascalCase, and log event IDs have changed. Update any log queries or alerts that match on property names or event IDs.
  • The caching configuration stores (CachingClientStore, CachingResourceStore, CachingCorsPolicyService, CachingIdentityProviderStore and CachingSamlServiceProviderStore) now take an IHybridCacheFactory instead of a keyed HybridCache in their constructors.
  • Unregistered PAR redirect URIs must use https and must not match ValidationOptions.InvalidRedirectUriPrefixes, and implicit-only clients can no longer use them. These fixes also shipped in 8.0.9.

What's changed

Spaces

  • Authentication cookies per space. With path-based spaces, IdentityServer's authentication cookies are scoped to the space's path, so sessions in different spaces on the same host stay separate.
  • Dynamic providers per space. Two spaces can configure a dynamic provider with the same scheme name without sharing options such as client id, secret or authority.
  • Cached configuration lookups per space. Clients, resources, CORS policies, identity providers and SAML service providers are cached under the correct space.

Storage

  • Configuration and operational data can each use their own Duende Storage instance.
  • The built-in OIDC and SAML identity provider schemas are public, so you can reuse and extend them.
  • IdentityServer and User Management work together without any schema setup. Each product registers the schemas it needs, and your own schema replaces a product default with the same id.
  • AddConfigurationStore for Entity Framework is now AddEntityFrameworkConfigurationStore. The old name still works but is marked obsolete.

Fixes and improvements

  • A signed JWT access token without a client_id is now rejected with invalid_token instead of throwing.
  • Calling AddInMemoryOidcProviders, AddInMemorySamlProviders or AddInMemoryIdentityProviders more than once now adds up the providers instead of keeping only the last set.
  • SAML service provider AuthnRequests can be signed. The default stays unsigned.
  • SAML logout no longer fails when the logout message handle is too long for the session ID column.
  • ClientAdmin and ApiResourceAdmin no longer hash JWK and X.509 certificate secrets, which broke mTLS and private_key_jwt client authentication.
  • Rejected requests and tokens from external callers are logged at Information instead of Error.
  • Length checks now happen before IdentityServer scans long input. The new InputLengthRestrictions.Prompt (default 100) applies to prompt and suppressed_prompt.

Full Changelog: is-8.1.0-preview.3...is-8.1.0-preview.4

Don't miss a new products release

NewReleases is sending notifications on new releases.