Skip to content

Delete implementation of DeviceBoundSessions - #69462

Merged
wtgodbe merged 1 commit into
release/11.0from
copilot/delete-device-bound-sessions
Sep 23, 2026
Merged

wtgodbe merged 1 commit into
release/11.0from
copilot/delete-device-bound-sessions

Conversation

Copilot AI commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Delete implementation of DeviceBoundSessions

This removes the DeviceBoundSessionCredentials (DBSC) implementation that we were planning to ship experimentally in .NET 11 (And we shipped it for RC1 at this point already https://nuget.org/packages/Microsoft.AspNetCore.Authentication.DeviceBoundSessions)

Description

The current implementation is incomplete, and we are not satisfied with it. We think it's best to re-iterate and possibly get it in .NET 12.

Customer Impact

Experimental feature shipped in .NET 11 is gone. But as it's experimental, there shouldn't have been any expectations to use the feature in production.

Regression?

N/A - this removes a feature completely.

Risk

Low.

New feature in .NET 11, already experimental.

Verification

Not required. This simply deletes a whole package https://nuget.org/packages/Microsoft.AspNetCore.Authentication.DeviceBoundSessions that we will no longer ship.

Packaging changes reviewed?

N/A

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
@Youssef1313
Youssef1313 marked this pull request as ready for review September 23, 2026 13:00
Copilot AI lite review requested due to automatic review settings September 23, 2026 13:00
@Youssef1313 Youssef1313 added the Servicing-consider Shiproom approval is required for the issue label Sep 23, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Hi @copilot. Please make sure you've updated the PR description to use the Shiproom Template. Also, make sure this PR is not marked as a draft and is ready-to-merge.

To learn more about how to prepare a servicing PR click here.

@Youssef1313 Youssef1313 changed the title Deleting implementation of DeviceBoundSessions Delete implementation of DeviceBoundSessions Sep 23, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Remove the stale ASP0031 diagnostics entry from docs/list-of-diagnostics.md.

Review effort: Lite
Findings: None

What changed in this PR

This pull request removes the unshipped experimental Device Bound Sessions implementation and its supporting tests, sample, API baselines, and build registrations.

Changes:

  • Deletes Device Bound Sessions production and test code.
  • Removes the debug sample and public API baselines.
  • Removes project, solution, shipping, trimming, and reference registrations.
File Reviewed change
src/​Security/​Authentication/​test/​Microsoft.AspNetCore.Authentication.Test.csproj Removes the Device Bound Sessions test reference.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionSignOutTests.cs Deletes sign-out tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionRevocationTests.cs Deletes revocation tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionRegistrationHeaderTests.cs Deletes registration-header tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionOptionsTests.cs Deletes options tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionLifetimeTests.cs Deletes lifetime tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionJwtValidatorTests.cs Deletes JWT validator tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionInstructionTests.cs Deletes instruction tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionCredentialTests.cs Deletes credential tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionCookieProtectionTests.cs Deletes cookie protection tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionChallengeProtectorTests.cs Deletes challenge-protector tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DeviceBoundSessionAuthenticationOptionsTests.cs Deletes authentication-options tests.
src/​Security/​Authentication/​test/​DeviceBoundSessions/​DbscProofKey.cs Deletes the test JWT helper.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​SessionScopeRule.cs Deletes the session scope-rule model.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​SessionScope.cs Deletes the session scope model.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​SessionInstruction.cs Deletes the session instruction model.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​SessionCredential.cs Deletes the session credential model.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​PublicAPI.Unshipped.txt Removes unshipped API declarations.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​PublicAPI.Shipped.txt Removes the shipped API baseline.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​PostConfigureDeviceBoundSessionDerivedCookieOptions.cs Deletes derived-cookie configuration.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​PostConfigureDeviceBoundSessionCookieOptions.cs Deletes source-cookie configuration.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​PostConfigureDeviceBoundSessionAuthenticationOptions.cs Deletes authentication post-configuration.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​Microsoft.AspNetCore.Authentication.DeviceBoundSessions.csproj Deletes the production project.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​LoggingExtensions.cs Deletes logging extensions.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionSourceSchemes.cs Deletes source-scheme mappings.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionScopeRule.cs Deletes scope-rule options.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionRegistrationHeader.cs Deletes registration-header handling.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionOptions.cs Deletes handler options.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionJwtValidator.cs Deletes JWT validation.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionJwtResult.cs Deletes JWT validation results.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionJsonContext.cs Deletes the JSON serialization context.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionHttpContextExtensions.cs Deletes HTTP context extensions.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionHandler.cs Deletes the protocol handler.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionExtensions.cs Deletes service-registration extensions.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionDefaults.cs Deletes default constants.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionCookieEvents.cs Deletes cookie event integration.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionConstants.cs Deletes protocol constants.
src/​Security/​Authentication/​DeviceBoundSessions/​src/​DeviceBoundSessionChallengeProtector.cs Deletes challenge protection.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​Properties/​launchSettings.json Deletes sample launch settings.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​Program.cs Deletes sample startup and endpoints.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​HarLoggingMiddleware.cs Deletes sample HAR logging.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​DbscDebugServer.csproj Deletes the sample project.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​DbscDebug.cs Deletes sample diagnostics and decoding.
src/​Security/​Authentication/​DeviceBoundSessions/​samples/​DbscDebugServer/​Dashboard.cs Deletes the sample dashboard.
eng/​TrimmableProjects.props Removes trimming registration.
eng/​ShippingAssemblies.props Removes shipping registration.
eng/​ProjectReferences.props Removes project-reference registration.
AspNetCore.slnx Removes solution entries.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@Youssef1313 Youssef1313 added Servicing-approved Shiproom has approved the issue and removed Servicing-consider Shiproom approval is required for the issue labels Sep 23, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Hi @copilot. This PR was just approved to be included in the upcoming servicing release. Somebody from the @dotnet/aspnet-build team will get it merged when the branches are open. Until then, please make sure all the CI checks pass and the PR is reviewed.

@Youssef1313

Copy link
Copy Markdown
Member

/ba-g Intentional deletion of PublicAPI.Shipped.txt and a flaky test.

@wtgodbe
wtgodbe merged commit 8c3512e into release/11.0 Sep 23, 2026
40 of 43 checks passed
@wtgodbe
wtgodbe deleted the copilot/delete-device-bound-sessions branch September 23, 2026 16:53
wtgodbe added a commit that referenced this pull request Sep 23, 2026
* Merge pull request #69426 from dotnet/darc-release/11.0-1a353f84-3fb6-4f62-815a-b32e480af1f0

[release/11.0] Source code updates from dotnet/dotnet

* Replace explicit command after navigation with automatic dismissing by ChromeDriver. (#69416) (#69440)

* Replace explicit command after navigation with automatic dismissing by ChromeDriver.

* Feedback: dismissing should be opt-in.

Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>

* Fix Native AOT completion for JS-invoked Tasks (#69437)

* Fix Native AOT completion for JS-invoked Tasks

Use the declared JS-invokable return type to avoid dynamically constructing a result getter for non-generic Task and ValueTask completions. Keep unsuccessful asynchronous completions mutually exclusive and cover the Native AOT browser promise boundary.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Expand Native AOT async JS interop coverage

Exercise Task, ValueTask, Task<T>, and ValueTask<T> through invokeMethodAsync in the Native AOT browser test. Preserve the existing fault-path structure while handling cancellation separately.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Support generic JS interop tasks under Native AOT

Use preserved Task<T>.Result and ValueTask<T>.AsTask members when dynamic code is unavailable. Expand Native AOT browser coverage to completed and asynchronous task shapes with an application-defined value type.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* Remove DeviceBoundSessions implementation (#69462)

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

* Update dependencies from build 333446 (#69444)

Updated Dependencies:
Microsoft.NET.Runtime.WebAssembly.Sdk, Microsoft.NETCore.BrowserDebugHost.Transport, Microsoft.NET.Runtime.MonoAOTCompiler.Task, dotnet-ef, Microsoft.Bcl.AsyncInterfaces, Microsoft.Bcl.Cryptography, Microsoft.Bcl.TimeProvider, Microsoft.EntityFrameworkCore, Microsoft.EntityFrameworkCore.Design, Microsoft.EntityFrameworkCore.InMemory, Microsoft.EntityFrameworkCore.Relational, Microsoft.EntityFrameworkCore.Sqlite, Microsoft.EntityFrameworkCore.SqlServer, Microsoft.EntityFrameworkCore.Tools, Microsoft.Extensions.Caching.Abstractions, Microsoft.Extensions.Caching.Memory, Microsoft.Extensions.Configuration, Microsoft.Extensions.Configuration.Abstractions, Microsoft.Extensions.Configuration.Binder, Microsoft.Extensions.Configuration.CommandLine, Microsoft.Extensions.Configuration.EnvironmentVariables, Microsoft.Extensions.Configuration.FileExtensions, Microsoft.Extensions.Configuration.Ini, Microsoft.Extensions.Configuration.Json, Microsoft.Extensions.Configuration.UserSecrets, Microsoft.Extensions.Configuration.Xml, Microsoft.Extensions.DependencyInjection, Microsoft.Extensions.DependencyInjection.Abstractions, Microsoft.Extensions.DependencyModel, Microsoft.Extensions.Diagnostics, Microsoft.Extensions.Diagnostics.Abstractions, Microsoft.Extensions.FileProviders.Abstractions, Microsoft.Extensions.FileProviders.Composite, Microsoft.Extensions.FileProviders.Physical, Microsoft.Extensions.FileSystemGlobbing, Microsoft.Extensions.HostFactoryResolver.Sources, Microsoft.Extensions.Hosting, Microsoft.Extensions.Hosting.Abstractions, Microsoft.Extensions.Http, Microsoft.Extensions.Logging, Microsoft.Extensions.Logging.Abstractions, Microsoft.Extensions.Logging.Configuration, Microsoft.Extensions.Logging.Console, Microsoft.Extensions.Logging.Debug, Microsoft.Extensions.Logging.EventLog, Microsoft.Extensions.Logging.EventSource, Microsoft.Extensions.Logging.TraceSource, Microsoft.Extensions.Options, Microsoft.Extensions.Options.ConfigurationExtensions, Microsoft.Extensions.Options.DataAnnotations, Microsoft.Extensions.Primitives, Microsoft.Internal.Runtime.AspNetCore.Transport, Microsoft.NETCore.App.Ref, Microsoft.NETCore.Platforms, System.Collections.Immutable, System.Composition, System.Configuration.ConfigurationManager, System.Diagnostics.DiagnosticSource, System.Diagnostics.EventLog, System.Diagnostics.PerformanceCounter, System.DirectoryServices.Protocols, System.Formats.Asn1, System.Formats.Cbor, System.IO.Hashing, System.IO.Pipelines, System.Memory.Data, System.Net.Http.Json, System.Net.Http.WinHttpHandler, System.Net.ServerSentEvents, System.Numerics.Tensors, System.Reflection.Metadata, System.Resources.Extensions, System.Runtime.Caching, System.Security.Cryptography.Pkcs, System.Security.Cryptography.Xml, System.Security.Permissions, System.ServiceProcess.ServiceController, System.Text.Encodings.Web, System.Text.Json, System.Threading.AccessControl, System.Threading.Channels, System.Threading.RateLimiting (Version 11.0.0-rc.2.26471.109 -> 11.0.0-rc.2.26472.108)
Microsoft.DotNet.Arcade.Sdk, Microsoft.DotNet.Build.Tasks.Archives, Microsoft.DotNet.Build.Tasks.Installers, Microsoft.DotNet.Build.Tasks.Templating, Microsoft.DotNet.Helix.JobMonitor, Microsoft.DotNet.Helix.Sdk, Microsoft.DotNet.RemoteExecutor, Microsoft.DotNet.SharedFramework.Sdk (Version 11.0.0-beta.26471.109 -> 11.0.0-beta.26472.108)
Microsoft.Web.Xdt (Version 3.3.0-rc.2.26471.109 -> 3.3.0-rc.2.26472.108)
NuGet.Frameworks, NuGet.Packaging, NuGet.Versioning (Version 7.12.0-rc.47209 -> 8.0.0-rc.47408)
[[ commit created by automation ]]

Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>

---------

Co-authored-by: dotnet-maestro[bot] <42748379+dotnet-maestro[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>
Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>
Co-authored-by: William Godbe <wigodbe@microsoft.com>
@Youssef1313

Copy link
Copy Markdown
Member

/backport to release/11.0-rc2

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/11.0-rc2 (link to workflow run)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Servicing-approved Shiproom has approved the issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants