[release/11.0-rc1] SignInManager: return SignInResult.Failed for expired passkey session challenge - #68654
Merged
Conversation
halter73
approved these changes
Aug 20, 2026
wtgodbe
added a commit
that referenced
this pull request
Aug 22, 2026
* [SignalR] Reject duplicate SignalR upload stream IDs (#68525) (#68638) * Reject duplicate SignalR upload stream IDs * Simplify upload stream ownership cleanup * Avoid upload stream ownership allocations * Simplify upload stream registration ownership * Defer upload stream reader creation * Dispose cancellation source after binding failure * Reuse upload stream test helper --------- Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2 * Honor all sign-in confirmation requirements after registration (#68631) (#68655) Co-authored-by: Brennan <brecon@microsoft.com> * Preserve BadHttpRequestException status codes (#68632) (#68649) * Preserve BadHttpRequestException status codes * Preserve exception handler 404 safeguard --------- Co-authored-by: Stephen Halter <halter73@gmail.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * SignInManager: return SignInResult.Failed for expired passkey session challenge (#67539) (#68654) Co-authored-by: Grant Totinov <granttotinov604@gmail.com> * Don't apply the CSRF verdict to remote authentication callbacks (#68669) * Don't apply the CSRF verdict to remote authentication callbacks A remote provider's callback (OIDC response_mode=form_post, WS-Federation) is a cross-site form POST by protocol design, so the auto-injected CSRF protection records an invalid IAntiforgeryValidationFeature verdict for it. The handler then throws while reading its own callback body, before any of its events can run, so apps have no way to opt out. Suppress the verdict while a remote handler owns the request, and restore it if the handler declines so the rest of the pipeline still sees it. Fixes #68666 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd * test both antiforgery & csrf --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd * Use model display names in Blazor input parsing errors (#68667) (#68688) * Use display attributes in input parsing errors * Address test coverage feedback from review. * Apply dedup cleanup from feedback. Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com> * [release/11.0-rc1] Extract IsAuthenticated helper method (#68658) * Extract IsAuthenticated helper method Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com> * Reorder using Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com> * Use SecurityHelper for authentication revalidation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com> --------- Co-authored-by: Youssef1313 <youssefvictor00@gmail.com> Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com> Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com> * Fix InitialItemIndex viewport underfill for small items in big container or on window resize (#67936) (#68689) Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com> * fix nullable<union> for openapi gen (#68665) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Brennan <brecon@microsoft.com> Co-authored-by: Stephen Halter <halter73@gmail.com> Co-authored-by: Grant Totinov <granttotinov604@gmail.com> Co-authored-by: Korolev Dmitry <dmkorolev@microsoft.com> Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com> Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com> Co-authored-by: Youssef1313 <youssefvictor00@gmail.com> Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com> Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com> Co-authored-by: William Godbe <wigodbe@microsoft.com> Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2 Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #67539 to release/11.0-rc1
/cc @halter73 @GrantTotinov
SignInManager: return SignInResult.Failed for expired passkey session challenge
Return a normal sign-in failure when the passkey challenge has expired.
Description
Passkey sign-in stores its challenge in the temporary two-factor user ID cookie, which expires after five minutes by default. If that cookie is missing or expired when the user submits the passkey assertion,
PerformPasskeyAssertionAsyncthrows anInvalidOperationExceptionand the application can return a 500 response.This change checks the passkey authentication state before performing the assertion and returns
SignInResult.Failedwhen the state is missing. Missing handler configuration and mismatched passkey operations continue to throw their existing diagnostic exceptions.Fixes #67410
Customer Impact
Users who leave a passkey login page open until the challenge expires can receive an unhandled exception instead of a normal failed sign-in result. With this fix, applications can display their standard invalid-login response and allow the user to retry with a new challenge.
Regression?
The behavior has existed since passkey support was introduced.
Risk
The change is limited to the missing passkey-state path, does not change public API or packaging, and preserves the existing behavior for valid state, missing handler configuration, and mismatched operations.
Verification
Manual verification used
IdentitySample.PasskeyUIwith headless Chrome and a virtual WebAuthn platform authenticator. A passkey was registered and used for a successful sign-in. A second assertion was then created, the temporary challenge cookie was removed to simulate expiration, and submitting the assertion displayed the normalError: Could not sign in with the provided credential.response instead of producing an unhandled exception or 500.PasskeySignInReturnsFailedWhenSessionChallengeHasExpiredcovers the missing/expired challenge path and verifies that the passkey handler is not invoked. The test passes with this fix and fails without it with the expectedInvalidOperationException.Packaging changes reviewed?
When servicing release/2.3