This is a preview release of IdentityServer 8.1.
Breaking changes
- Structured log property names are now PascalCase, and log event IDs have changed. Update any log queries or alerts that match on property names or event IDs.
- The caching configuration stores (
CachingClientStore,CachingResourceStore,CachingCorsPolicyService,CachingIdentityProviderStoreandCachingSamlServiceProviderStore) now take anIHybridCacheFactoryinstead of a keyedHybridCachein their constructors. - Unregistered PAR redirect URIs must use
httpsand must not matchValidationOptions.InvalidRedirectUriPrefixes, and implicit-only clients can no longer use them. These fixes also shipped in 8.0.9.
What's changed
Spaces
- Authentication cookies per space. With path-based spaces, IdentityServer's authentication cookies are scoped to the space's path, so sessions in different spaces on the same host stay separate.
- Dynamic providers per space. Two spaces can configure a dynamic provider with the same scheme name without sharing options such as client id, secret or authority.
- Cached configuration lookups per space. Clients, resources, CORS policies, identity providers and SAML service providers are cached under the correct space.
Storage
- Configuration and operational data can each use their own Duende Storage instance.
- The built-in OIDC and SAML identity provider schemas are public, so you can reuse and extend them.
- IdentityServer and User Management work together without any schema setup. Each product registers the schemas it needs, and your own schema replaces a product default with the same id.
AddConfigurationStorefor Entity Framework is nowAddEntityFrameworkConfigurationStore. The old name still works but is marked obsolete.
Fixes and improvements
- A signed JWT access token without a
client_idis now rejected withinvalid_tokeninstead of throwing. - Calling
AddInMemoryOidcProviders,AddInMemorySamlProvidersorAddInMemoryIdentityProvidersmore than once now adds up the providers instead of keeping only the last set. - SAML service provider AuthnRequests can be signed. The default stays unsigned.
- SAML logout no longer fails when the logout message handle is too long for the session ID column.
ClientAdminandApiResourceAdminno longer hash JWK and X.509 certificate secrets, which broke mTLS andprivate_key_jwtclient authentication.- Rejected requests and tokens from external callers are logged at
Informationinstead ofError. - Length checks now happen before IdentityServer scans long input. The new
InputLengthRestrictions.Prompt(default 100) applies topromptandsuppressed_prompt.
Full Changelog: is-8.1.0-preview.3...is-8.1.0-preview.4