Summary
The experimental DBSC implementation derived its session-cookie settings from a source cookie scheme but did not preserve an explicitly configured source cookie path. The derived session cookie must remain within the same path scope as the source credential.
Related to #66478 and the API proposal in #68117. The implementation was removed from .NET 11 by #69462 and backported by #69479, so this issue tracks a requirement for any future DBSC reintroduction rather than a .NET 11 servicing change.
What is wrong
PostConfigureDeviceBoundSessionDerivedCookieOptions.CopyFromSource copied HttpOnly, SecurePolicy, SameSite, Domain, and lifetime settings, but omitted Cookie.Path.
- The session-derived scheme therefore used its own default path instead of preserving an explicit path configured on the source cookie scheme.
- The refresh-derived scheme has separate intentional path behavior and should remain scoped to the configured DBSC refresh endpoint.
Why it matters (defense in depth)
- Cookie derivation should not broaden the source cookie's configured scope as an unintended side effect.
- Preserving the source path maintains application-boundary isolation for deployments that host multiple applications under one origin.
Affected code
Recommended fix
When DBSC is reintroduced, copy source.Cookie.Path to the derived session cookie alongside the other inherited cookie attributes. Keep the refresh cookie's explicitly computed DBSC endpoint path unchanged. Add focused tests with a non-root source-cookie path that assert the session cookie builds with the same path and the refresh cookie continues to use its dedicated endpoint scope.
Copying the complete CookieBuilder was considered but is not preferred because the derived schemes intentionally differ in name, lifetime behavior, and refresh-path handling. Changing the global cookie defaults was also rejected because the invariant belongs specifically to derivation from the configured source scheme.
This is an internal options-wiring correction with no expected public API change or migration requirement. Because the implementation is no longer present in .NET 11, the correction should be included in the branch where DBSC development resumes and covered before another package is published.
Acceptance criteria
Summary
The experimental DBSC implementation derived its session-cookie settings from a source cookie scheme but did not preserve an explicitly configured source cookie path. The derived session cookie must remain within the same path scope as the source credential.
Related to #66478 and the API proposal in #68117. The implementation was removed from .NET 11 by #69462 and backported by #69479, so this issue tracks a requirement for any future DBSC reintroduction rather than a .NET 11 servicing change.
What is wrong
PostConfigureDeviceBoundSessionDerivedCookieOptions.CopyFromSourcecopiedHttpOnly,SecurePolicy,SameSite,Domain, and lifetime settings, but omittedCookie.Path.Why it matters (defense in depth)
Affected code
PostConfigureDeviceBoundSessionDerivedCookieOptions.cs:80-92(lastmaincommit before removal) -CopyFromSourcecopied source-cookie attributes without copyingCookie.Path.DeviceBoundSessionCookieProtectionTests.cs:130-160(lastmaincommit before removal) - covered inherited attributes but did not assert path inheritance.Microsoft.AspNetCore.Authentication.DeviceBoundSessions0.11.0-rc.1.26425.128- experimental prerelease package containing the implementation. The package was subsequently removed from .NET 11 by Delete implementation of DeviceBoundSessions #69462 and [release/11.0-rc2] Delete implementation of DeviceBoundSessions #69479.Recommended fix
When DBSC is reintroduced, copy
source.Cookie.Pathto the derived session cookie alongside the other inherited cookie attributes. Keep the refresh cookie's explicitly computed DBSC endpoint path unchanged. Add focused tests with a non-root source-cookie path that assert the session cookie builds with the same path and the refresh cookie continues to use its dedicated endpoint scope.Copying the complete
CookieBuilderwas considered but is not preferred because the derived schemes intentionally differ in name, lifetime behavior, and refresh-path handling. Changing the global cookie defaults was also rejected because the invariant belongs specifically to derivation from the configured source scheme.This is an internal options-wiring correction with no expected public API change or migration requirement. Because the implementation is no longer present in .NET 11, the correction should be included in the branch where DBSC development resumes and covered before another package is published.
Acceptance criteria
Cookie.Pathfrom its source cookie scheme.Cookie.Path.