Skip to content

DBSC derived session cookie should preserve source cookie path #69618

Description

@rokonec

Summary

The experimental DBSC implementation derived its session-cookie settings from a source cookie scheme but did not preserve an explicitly configured source cookie path. The derived session cookie must remain within the same path scope as the source credential.

Related to #66478 and the API proposal in #68117. The implementation was removed from .NET 11 by #69462 and backported by #69479, so this issue tracks a requirement for any future DBSC reintroduction rather than a .NET 11 servicing change.

What is wrong

  • PostConfigureDeviceBoundSessionDerivedCookieOptions.CopyFromSource copied HttpOnly, SecurePolicy, SameSite, Domain, and lifetime settings, but omitted Cookie.Path.
  • The session-derived scheme therefore used its own default path instead of preserving an explicit path configured on the source cookie scheme.
  • The refresh-derived scheme has separate intentional path behavior and should remain scoped to the configured DBSC refresh endpoint.

Why it matters (defense in depth)

  • Cookie derivation should not broaden the source cookie's configured scope as an unintended side effect.
  • Preserving the source path maintains application-boundary isolation for deployments that host multiple applications under one origin.

Affected code

Recommended fix

When DBSC is reintroduced, copy source.Cookie.Path to the derived session cookie alongside the other inherited cookie attributes. Keep the refresh cookie's explicitly computed DBSC endpoint path unchanged. Add focused tests with a non-root source-cookie path that assert the session cookie builds with the same path and the refresh cookie continues to use its dedicated endpoint scope.

Copying the complete CookieBuilder was considered but is not preferred because the derived schemes intentionally differ in name, lifetime behavior, and refresh-path handling. Changing the global cookie defaults was also rejected because the invariant belongs specifically to derivation from the configured source scheme.

This is an internal options-wiring correction with no expected public API change or migration requirement. Because the implementation is no longer present in .NET 11, the correction should be included in the branch where DBSC development resumes and covered before another package is published.

Acceptance criteria

  • A derived DBSC session cookie preserves an explicitly configured Cookie.Path from its source cookie scheme.
  • A derived DBSC refresh cookie remains scoped to the configured refresh endpoint rather than inheriting the source path.
  • Regression tests cover a non-root source path and assert both derived-cookie behaviors.
  • Default-path and request-path-base behavior remain unchanged when the source does not explicitly configure Cookie.Path.
  • The DBSC tracking issue Support Device Bound Session Credentials (DBSC) #66478 records this requirement before the feature is reintroduced.

Activity

  1. added
    area-authIncludes: authentication, authorization, OAuth, OIDC, and access token validation
    on Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-authIncludes: authentication, authorization, OAuth, OIDC, and access token validation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions