Skip to content

[release/11.0-rc1] SignInManager: return SignInResult.Failed for expired passkey session challenge - #68654

Merged
wtgodbe merged 1 commit into
release/11.0-rc1from
backport/pr-67539-to-release/11.0-rc1
Aug 21, 2026
Merged

[release/11.0-rc1] SignInManager: return SignInResult.Failed for expired passkey session challenge#68654
wtgodbe merged 1 commit into
release/11.0-rc1from
backport/pr-67539-to-release/11.0-rc1

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Backport of #67539 to release/11.0-rc1

/cc @halter73 @GrantTotinov

SignInManager: return SignInResult.Failed for expired passkey session challenge

Return a normal sign-in failure when the passkey challenge has expired.

Description

Passkey sign-in stores its challenge in the temporary two-factor user ID cookie, which expires after five minutes by default. If that cookie is missing or expired when the user submits the passkey assertion, PerformPasskeyAssertionAsync throws an InvalidOperationException and the application can return a 500 response.

This change checks the passkey authentication state before performing the assertion and returns SignInResult.Failed when the state is missing. Missing handler configuration and mismatched passkey operations continue to throw their existing diagnostic exceptions.

Fixes #67410

Customer Impact

Users who leave a passkey login page open until the challenge expires can receive an unhandled exception instead of a normal failed sign-in result. With this fix, applications can display their standard invalid-login response and allow the user to retry with a new challenge.

Regression?

  • Yes
  • No

The behavior has existed since passkey support was introduced.

Risk

  • High
  • Medium
  • Low

The change is limited to the missing passkey-state path, does not change public API or packaging, and preserves the existing behavior for valid state, missing handler configuration, and mismatched operations.

Verification

  • Manual (required)
  • Automated

Manual verification used IdentitySample.PasskeyUI with headless Chrome and a virtual WebAuthn platform authenticator. A passkey was registered and used for a successful sign-in. A second assertion was then created, the temporary challenge cookie was removed to simulate expiration, and submitting the assertion displayed the normal Error: Could not sign in with the provided credential. response instead of producing an unhandled exception or 500.

PasskeySignInReturnsFailedWhenSessionChallengeHasExpired covers the missing/expired challenge path and verifies that the passkey handler is not invoked. The test passes with this fix and fails without it with the expected InvalidOperationException.

Packaging changes reviewed?

  • Yes
  • No
  • N/A

When servicing release/2.3

  • Make necessary changes in eng/PatchConfig.props

@halter73
halter73 requested a review from BrennanConroy August 20, 2026 00:04
@wtgodbe
wtgodbe merged commit 555ae4e into release/11.0-rc1 Aug 21, 2026
24 checks passed
@wtgodbe
wtgodbe deleted the backport/pr-67539-to-release/11.0-rc1 branch August 21, 2026 15:47
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 11.0-rc1 milestone Aug 21, 2026
wtgodbe added a commit that referenced this pull request Aug 22, 2026
* [SignalR] Reject duplicate SignalR upload stream IDs (#68525) (#68638)

* Reject duplicate SignalR upload stream IDs



* Simplify upload stream ownership cleanup



* Avoid upload stream ownership allocations



* Simplify upload stream registration ownership



* Defer upload stream reader creation





* Dispose cancellation source after binding failure





* Reuse upload stream test helper





---------

Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2

* Honor all sign-in confirmation requirements after registration (#68631) (#68655)

Co-authored-by: Brennan <brecon@microsoft.com>

* Preserve BadHttpRequestException status codes (#68632) (#68649)

* Preserve BadHttpRequestException status codes



* Preserve exception handler 404 safeguard



---------

Co-authored-by: Stephen Halter <halter73@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* SignInManager: return SignInResult.Failed for expired passkey session challenge (#67539) (#68654)

Co-authored-by: Grant Totinov <granttotinov604@gmail.com>

* Don't apply the CSRF verdict to remote authentication callbacks (#68669)

* Don't apply the CSRF verdict to remote authentication callbacks

A remote provider's callback (OIDC response_mode=form_post, WS-Federation)
is a cross-site form POST by protocol design, so the auto-injected CSRF
protection records an invalid IAntiforgeryValidationFeature verdict for it.
The handler then throws while reading its own callback body, before any of
its events can run, so apps have no way to opt out.

Suppress the verdict while a remote handler owns the request, and restore it
if the handler declines so the rest of the pipeline still sees it.

Fixes #68666

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd

* test both antiforgery & csrf

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd

* Use model display names in Blazor input parsing errors (#68667) (#68688)

* Use display attributes in input parsing errors

* Address test coverage feedback from review.

* Apply dedup cleanup from feedback.

Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>

* [release/11.0-rc1] Extract IsAuthenticated helper method (#68658)

* Extract IsAuthenticated helper method

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

* Reorder using

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

* Use SecurityHelper for authentication revalidation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

---------

Co-authored-by: Youssef1313 <youssefvictor00@gmail.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com>

* Fix  InitialItemIndex viewport underfill for small items in big container or on window resize (#67936) (#68689)

Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>

* fix nullable<union> for openapi gen (#68665)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Brennan <brecon@microsoft.com>
Co-authored-by: Stephen Halter <halter73@gmail.com>
Co-authored-by: Grant Totinov <granttotinov604@gmail.com>
Co-authored-by: Korolev Dmitry <dmkorolev@microsoft.com>
Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Youssef1313 <youssefvictor00@gmail.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com>
Co-authored-by: William Godbe <wigodbe@microsoft.com>
Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants