Trigger metadata refresh for token decryption errors#3149
Merged
Conversation
SummarySummary
CoverageMicrosoft.IdentityModel.JsonWebTokens - 80.3%
|
jennyf19
approved these changes
Feb 26, 2025
GeoK
reviewed
Feb 26, 2025
GeoK
reviewed
Mar 5, 2025
jmprieur
reviewed
Mar 6, 2025
Contributor
jmprieur
left a comment
There was a problem hiding this comment.
@pmaytak
You changed the public API, but didn't update the PublicApi.Unshipped.txt files (you didn't use the fixer in the IDE)
- IDX10603 is not part of the declared API in LogMessages.cs.
- IDX10907 is not part of the declared API in LogMessages.cs.
- IsRecoverableException is not part of the declared API in TokenUtilities.cs.
- IsRecoverableExceptionType is not part of the declared API in TokenUtilities.cs.
SummarySummary
CoverageMicrosoft.IdentityModel.JsonWebTokens - 80.3%
|
GeoK
reviewed
Mar 6, 2025
SummarySummary
CoverageMicrosoft.IdentityModel.JsonWebTokens - 80.3%
|
SummarySummary
CoverageMicrosoft.IdentityModel.JsonWebTokens - 80.3%
|
GeoK
approved these changes
Mar 6, 2025
SummarySummary
CoverageMicrosoft.IdentityModel.JsonWebTokens - 80.3%
|
14 tasks
This was referenced Jul 22, 2025
This was referenced May 4, 2026
Open
Closed
This was referenced May 11, 2026
chore(deps): Bump System.IdentityModel.Tokens.Jwt from 8.3.0 to 8.18.0
marcelocamargosjr/cashflow#38
Open
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3148
Summary
aims to address decryption issues by triggering a metadata refresh when token decryption fails due to the token's Key ID (Kid) not matching any of the decryption keys' IDs. It introduces changes to handle SecurityTokenEncryptionKeyNotFoundException as a recoverable exception when the current configuration contains decryption keys.
Key changes include:
Details:
SecurityTokenEncryptionKeyNotFoundExceptionwhen decryption fails and token's Kid doesn't match the decryption keys' IDs.SecurityTokenEncryptionKeyNotFoundExceptionis considered a recoverable exception when the current configuration contains decryption keys and in that case a metadata refresh will be triggered.SecurityTokenEncryptionKeyNotFoundExceptionalready existed but it seems like it has never been used since it was created years ago and seems like the purpose was for this exact scenario.