Reinstate Microsoft.IdentityModel.Protocols.WsTrust as a supported 8.x package - #3547
Merged
Merged
Conversation
…trust to dev8x Port the WS-Trust implementation from the origin/wstrust feature branch (based on 6.x) to the current dev8x branch (8.x). This package provides the active WS-Trust SOAP profile needed by System.ServiceModel.Federation (WCF), which cannot be replaced by WsFederation (passive/browser SSO). Addresses: #3463 Changes from the original branch code: - Modernized csproj: removed FxCopAnalyzers, PackageReference -> ProjectReference, added PublicApiAnalyzers/InternalApiAnalyzers support, trimming annotations - Updated file headers to match current .editorconfig conventions - Replaced obsolete RNGCryptoServiceProvider with RandomNumberGenerator.Create() - Added DynamicallyAccessedMembers annotations for AOT/trimming compatibility - Added using Microsoft.IdentityModel.Xml to test files for XmlReadException - Fixed CLSCompliant attribute in test AssemblyInfo (true -> false) - Generated PublicAPI.Unshipped.txt (588 entries) and InternalAPI.Unshipped.txt Test results: 117 tests pass across net8.0, net9.0, and net10.0 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
AOT compatibility: - Replace Type.InvokeMember reflection in WsTrustSerializer.TryWriteSourceData with direct access to the internal XmlTokenStream property - Add InternalsVisibleTo from Tokens.Saml to Protocols.WsTrust - Zero trimming/AOT warnings Security hardening: - Set XmlResolver = null on all XmlDocument instances (XXE defence) - IDX15101 error uses reader.LocalName instead of ReadOuterXml (prevents token content leakage in exception messages) - Add DepthLimitingXmlReader (MaxDepth=32) to ReadUnknownElement and ReadEndpointReference (XML nesting DoS defence) - Apply BoundedXmlDictionaryReaderQuotas in ReadAsXmlElement and CreateXmlElement - Replace XmlTextReader with XmlDictionaryReader.CreateTextReader in WsSecuritySerializer.CreateXmlElement - Fix ReadBinarySecrect to read attributes before empty-element check; return null for empty elements to avoid NullReferenceException on .Data - Add missing throw to null guards in Entropy static helpers and Psha1KeyGenerator.FillRandomBytes - Fix double-wrapped FormatInvariant in Psha1KeyGenerator entropy size checks, restoring ArgumentException.ParamName Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Contributor
There was a problem hiding this comment.
Pull request overview
This PR reinstates Microsoft.IdentityModel.Protocols.WsTrust as a supported Wilson 8.x package by forward-porting the WS-Trust implementation and adding modern TFMs, build integration, and unit tests so downstream consumers (notably WCF System.ServiceModel.Federation) can continue to use WS-Trust without a migration path.
Changes:
- Adds the
Microsoft.IdentityModel.Protocols.WsTrustpackage project (plus supporting WS-* protocol/object-model types) and integrates it into the solution/build. - Adds a new
Microsoft.IdentityModel.Protocols.WsTrust.Teststest project with coverage for core serializer/object-model functionality. - Adds an
InternalsVisibleTobridge fromMicrosoft.IdentityModel.Tokens.Samlto the new WsTrust assembly to enable trimming/AOT-safe internal access paths.
Reviewed changes
Copilot reviewed 97 out of 99 changed files in this pull request and generated 14 comments.
Show a summary per file
| File | Description |
|---|---|
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/WsTrustTheoryData.cs | Adds shared test data container for WS-Trust tests. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/WsDefaults.cs | Adds common WS-* default objects/values for tests. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/UseKeyTests.cs | Adds tests for reading/writing <wst:UseKey>. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/RequestSecurityTokenResponseTests.cs | Adds tests for reading/writing WS-Trust responses and token validation path. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/RequestedProofTokenTests.cs | Adds tests for <wst:RequestedProofToken> read/write. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/Properties/AssemblyInfo.cs | Test assembly metadata (CLS compliance, ComVisible). |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/Microsoft.IdentityModel.Protocols.WsTrust.Tests.csproj | Introduces WS-Trust test project and references. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/EntropyTests.cs | Adds tests for <wst:Entropy> read/write. |
| test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/DerivedKeyTests.cs | Adds tests for PSHA1 combined/derived key generation behavior. |
| src/Microsoft.IdentityModel.Tokens.Saml/Properties/AssemblyInfo.cs | Grants WsTrust assembly internal access for trimming/AOT-safe paths. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionElements.cs | Adds XML Encryption element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionDataTypes.cs | Adds XML Encryption datatype constants container. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionConstants.cs | Adds XML Encryption namespace/prefix constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionAttributes.cs | Adds XML Encryption attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/EncryptedKey.cs | Adds placeholder model for encrypted key representation. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/EncryptedData.cs | Adds placeholder model for encrypted data representation. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/XmlAttributeHolder.cs | Adds internal attribute buffering utility for WS-* readers. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityElements.cs | Adds WS-Utility element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityConstants.cs | Adds WS-Utility namespace/prefix constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityAttributes.cs | Adds WS-Utility attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustVersion.cs | Adds WS-Trust version discriminator types. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustResponse.cs | Adds WS-Trust response model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustRequest.cs | Adds WS-Trust request model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustKeyTypes.cs | Adds WS-Trust KeyType URI constants by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustFaultCodes.cs | Adds WS-Trust fault-code constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustElements.cs | Adds WS-Trust element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustConstants.cs | Adds WS-Trust namespace/prefix/constants container by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustBinarySecrectTypes.cs | Adds WS-Trust BinarySecret type URI constants by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustAttributes.cs | Adds WS-Trust attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustActions.cs | Adds WS-Trust Action URI constants by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityVersion.cs | Adds WS-Security version discriminator types. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecuritySerializer.cs | Adds WS-Security read/write helpers for key identifiers and STRs. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityKeyTypes.cs | Adds WS-Security key type URI constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityEncodingTypes.cs | Adds WS-Security encoding-type URI constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityElements.cs | Adds WS-Security element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityConstants.cs | Adds WS-Security namespace/prefix/constants container. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityAttributes.cs | Adds WS-Security attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/SecurityTokenReference.cs | Adds WS-Security SecurityTokenReference model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/KeyIdentifier.cs | Adds WS-Security KeyIdentifier model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyVersion.cs | Adds WS-Policy version discriminator types. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicySerializer.cs | Adds WS-Policy read/write helpers (AppliesTo/PolicyReference). |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyElements.cs | Adds WS-Policy element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyConstants.cs | Adds WS-Policy namespace/prefix constants container by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyAttributes.cs | Adds WS-Policy attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/PolicyReference.cs | Adds WS-Policy PolicyReference model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/AppliesTo.cs | Adds WS-Policy AppliesTo model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedVersion.cs | Adds WS-Federation version discriminator types. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedSerializer.cs | Adds WS-Federation read/write helpers for claims/additional context. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedElements.cs | Adds WS-Federation element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedConstants.cs | Adds WS-Federation namespace/prefix constants container. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedAttributes.cs | Adds WS-Federation attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/ContextItem.cs | Adds WS-Federation ContextItem model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/ClaimType.cs | Adds WS-Federation ClaimType model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/AdditionalContext.cs | Adds WS-Federation AdditionalContext model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingSerializer.cs | Adds WS-Addressing read/write for endpoint references with depth limiting. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingElements.cs | Adds WS-Addressing element-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingConstants.cs | Adds WS-Addressing namespace/prefix constants container by version. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingAttributes.cs | Adds WS-Addressing attribute-name constants. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddresingVersion.cs | Adds WS-Addressing version discriminator types. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/EndpointReference.cs | Adds WS-Addressing EndpointReference model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/UseKey.cs | Adds WS-Trust UseKey model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/SecurityTokenElement.cs | Adds wrapper model for token/token-reference serialization. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/RequestSecurityTokenResponse.cs | Adds WS-Trust RSTR model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/RequestedSecurityToken.cs | Adds WS-Trust requested-token model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/RequestedProofToken.cs | Adds WS-Trust proof-token model type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Renewing.cs | Adds WS-Trust renewing preference model. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/PublicAPI.Shipped.txt | Adds/updates shipped public API declarations for the package. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/PshaDerivedKeyGenerator.cs | Adds PSHA-based derived key generator implementation. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs | Adds PSHA1 key generation utilities used by WS-Trust. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsUtils.cs | Adds WS-* XML utilities including bounded quotas and depth limiting reader. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsSerializationContext.cs | Adds per-WS-Trust-version protocol constants binding context. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsConstantsBase.cs | Adds base type for WS-* constants (Namespace/Prefix). |
| src/Microsoft.IdentityModel.Protocols.WsTrust/ProtectedKey.cs | Adds protected-key model for entropy handling. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Properties/AssemblyInfo.cs | Adds assembly metadata and InternalsVisibleTo for tests. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Participants.cs | Adds WS-Trust participants model. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Microsoft.IdentityModel.Protocols.WsTrust.csproj | Introduces the new supported WS-Trust package project and references. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/LogMessages.cs | Adds WS-Trust log message IDs used for XML/serializer diagnostics. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Lifetime.cs | Adds WS-Trust lifetime model with UTC normalization and warnings. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/IXmlOpenItem.cs | Adds extensibility interface for additional XML items. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/InternalAPI.Shipped.txt | Adds shipped internal API declarations (currently empty placeholder). |
| src/Microsoft.IdentityModel.Protocols.WsTrust/GlobalSuppressions.cs | Adds analyzers suppressions for the new package surface. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustWriteException.cs | Adds WS-Trust write exception type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustReadException.cs | Adds WS-Trust read exception type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustException.cs | Adds base WS-Trust exception type. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/ExceptionLogger.cs | Adds helper for WS-Trust exception logging/wrapping. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Entropy.cs | Adds entropy model type for key material/protected key. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/Claims.cs | Adds WS-Trust claims request model. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/BinarySecret.cs | Adds binary secret model for entropy material. |
| src/Microsoft.IdentityModel.Protocols.WsTrust/BinaryExchange.cs | Adds binary exchange model for WS-Trust exchanges. |
| .gitignore | Ignores local NuGet folder used for local packaging. |
Bugs: - WsTrustResponse: add missing throw to null guard (null was silently accepted into RequestSecurityTokenResponseCollection) - WsTrustBinarySecrectTypes: fix WS-Trust 1.4 AsymmetricKey URI (was Bearer URI; correct value is 200802/AsymmetricKey) - Psha1KeyGenerator.GenerateSymmetricKey: fix swapped issuer/requestor entropy in ComputeCombinedKey call - WsSecuritySerializer: read wsu:Id using WS-Utility namespace instead of WS-Security namespace - WsSecuritySerializer: write Id as wsu:Id with correct namespace/prefix - WsFedSerializer: fix error message for missing ClaimType Uri attribute (was referencing ContextItem/Name) Minor: - WsSecurityConstants: cache WsSecurity10/WsSecurity11 as static fields instead of allocating on each property access - Psha1KeyGenerator: align XML doc param order with method signature Cleanup: - Remove trailing semicolon in WsTrustBinarySecrectTypes - Fix test method name misspelling (ReadRequestSeurityTokenResponse) - Fix pragma comment typo in WsDefaults (nEndoot) - Remove commented-out dead assertion in EntropyTests Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
The solution file was opened in Visual Studio which regenerated all platform configuration entries adding Debug|x64, Debug|x86, Release|x64 and Release|x86 for every project. Restore to the original Any CPU-only format and retain only the two new WsTrust project entries. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
BinarySecret URI fix: - WsTrust14BinarySecretTypes: update Nonce and SymmetricKey to 200802 namespace (AsymmetricKey was already fixed; Actions and KeyTypes use 200512 intentionally per the WS-Trust 1.4 spec WSDL) ReadBinarySecrect empty element: - Return BinarySecret with EncodingType set instead of null for empty elements, preserving the Type attribute per spec (BinarySecret content is optional, Type attribute is OPTIONAL but meaningful) BoundedReaderQuotas consistency: - WsSecuritySerializer.CreateXmlElement: use WsUtils.BoundedReaderQuotas instead of XmlDictionaryReaderQuotas.Max GenerateSymmetricKey naming: - Rename senderEntropy/receiverEntropy to requestorEntropy/issuerEntropy to match ComputeCombinedKey parameter names and eliminate ambiguity Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
CredScan's CodeConnString searcher flags the base64 PSHA1 key derivation reference vectors in ComputedKeyReferences.cs as storage credentials (5 matches). These are deterministic test vectors for verifying the PSHA1 combined-key algorithm, not secrets. The existing 'References.cs' entry does not cover this file as CredScan matches on exact filename, so an explicit entry is required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
An earlier change moved the WsTrust14BinarySecretTypes constants to the http://docs.oasis-open.org/ws-sx/ws-trust/200802 namespace. That was wrong and this reverts it. WS-Trust 1.4 is an addendum to 1.3, not a standalone schema. The 1.4 XSD declares targetNamespace 200802 but binds xmlns:wst to 200512, and it only defines the 1.4 additions (InteractiveChallenge, TextChallenge, ChoiceChallenge, ContextData). It never redefines BinarySecretTypeEnum, so the BinarySecret @type URIs stay at 200512. The same reasoning applies to WsTrust14Actions and WsTrust14KeyTypes, which were already correct. The one genuine bug from 6.8.0 is retained: WsTrust14BinarySecretTypes .AsymmetricKey pointed at the 200512 Bearer KeyType URI instead of AsymmetricKey. Adds WsTrustConstantsTests to pin the expected URIs so these values are not "corrected" again. Verified end to end against a self hosted WCF STS: all 10 System.ServiceModel.Federation federation scenario tests pass over wstrust13 and wstrustFeb2005, Text and Mtom, with and without secure conversation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Ensure unknown and empty extension elements advance their outer readers, reset per-element AppliesTo dispatch state, and preserve request attribute values without duplicating Context or namespace declarations. Keep accepted empty request and response models within their own XML boundaries so they do not inspect or consume following siblings. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Capture and round-trip parsed XML Encryption EncryptedKey elements in RequestedProofToken. Reject manually constructed empty EncryptedKey values and protected entropy before mutating the XML writer instead of emitting misleading empty wrappers. Add regression tests for parsed encrypted-key round-tripping and atomic unsupported-state failures. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Share token, security-token-reference, and preserved raw XML handling across OnBehalfOf, ProofEncryption, UseKey, and RequestedSecurityToken. Use capable token handlers when source XML is unavailable and validate representability before writing wrappers. Preserve existing empty ProofEncryption skip behavior and TokenElement precedence. Add round-trip coverage for references, SAML tokens, and raw EndpointReference content. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Preserve response Context, custom attributes, and unknown elements. Add a typed XML attribute collection for BinarySecret, retain empty BinarySecret Type values with safe data, and serialize SecurityTokenReference Usage. Recognize typed WS-* children by exact QName while skipping or capturing wrong-namespace lookalikes, including lookalikes that precede valid reference children. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Apply parse-scoped cumulative budgets for elements, attributes, characters, and buffered bytes. Stream string, Base64, and attribute values through the budget and bound every XML materialization before allocating its DOM. Use finite dictionary-reader quotas and expose IDX15026 directly for quota failures. Add coverage for quota boundaries across extensions, known strings, decoded binary secrets, sibling collections, attributes, and comment-interleaved text. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Apply the shared parse budget to skipped subtrees and reference wrappers, preflight nested request and response states before writing parent elements, and validate EndpointReference Address by exact QName. Add static UseKey and ProofEncryption overloads for custom token handlers, with coverage for custom handlers, top-level writer atomicity, bounded skips, reference child quotas, and wrong-namespace Address handling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Replace eager subtree and DOM copying with a shared bounded streaming copier that reads text and attribute values in chunks. Route unknown, skipped, endpoint-reference, and token XML through the same path before constructing an XmlDocument. Add guard-reader, attribute-boundary, chunk-boundary, and special-node tests for the library-owned buffering paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Add a WriteRequest overload that emits the existing ActAs property in the WS-Trust 1.4 extension namespace when explicitly requested. Keep the existing overload and disabled path byte-for-byte compatible. Reuse source-preserving token, SecurityTokenReference, and custom-handler serialization with preflight validation before writing the request root. Add coverage for namespace, ordering, SAML 1.1 and 2.0, signatures, custom handlers, coexistence, and atomic unsupported-state failure. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Fre Berhane (fre-berhane)
approved these changes
Aug 24, 2026
Bogdan Gavril (bgavrilMS)
approved these changes
Aug 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reinstates
Microsoft.IdentityModel.Protocols.WsTrustas a supported package in the Wilson 8.x line. The package was deprecated in 6.x, whileSystem.ServiceModel.Federationstill depends on it and has no replacement path. See #3463.This forward-port preserves the 6.8 public surface and the behaviour required by WCF, adds current target frameworks and build integration, and addresses the parser, serializer, and resource-handling defects found during review.
Review guide
The implementation evolved through review. Please assess the final diff rather than relying on intermediate commit states.
Suggested review order:
OnBehalfOf,ProofEncryption,UseKey, and requested tokensActAsForward-port
The WS-Trust source was ported from the original 6.8 codebase to
dev8x.net462,net472,netstandard2.0,net6.0,net8.0,net9.0,net10.0RNGCryptoServiceProviderusageMicrosoft.IdentityModel.Tokens.SamlParser and serializer corrections
The updated serializer guarantees progress when reading unknown or empty elements and keeps each reader within its own wrapper. This covers unknown proof-token content, endpoint-reference extensions, duplicate
AppliesTolocal names, non-empty request extensions, empty context items, empty request and response containers, and reference wrappers.Request and response extension attributes now preserve their names, namespaces, and values without duplicating typed
Contextor namespace declarations. Response context and open content round-trip through the public model.Typed WS-* elements are recognised by exact QName. Wrong-namespace lookalikes remain non-fatal and are captured as extensions or skipped according to the containing element.
Token, security-token-reference, and preserved raw XML forms now share the same read and write paths for
OnBehalfOf,ProofEncryption,UseKey, andRequestedSecurityToken. ExistingTokenElementprecedence and emptyProofEncryptionread behaviour are preserved. StaticUseKeyandProofEncryptionAPIs also accept explicit token-handler collections.An additive
WriteRequestoverload can opt in to serialising the existingActAsproperty. The existing overload remains unchanged and continues to omitActAsfor compatibility. The opt-in path writes the WS-Trust 1.4200802extension inside the selected core request namespace, preserves SAML source XML, supports security-token references and custom handlers, and writesActAsbeforeAdditionalContext.Parsed XML Encryption
EncryptedKeycontent can be retained and round-tripped. A manually constructed emptyEncryptedKey, protected entropy, or another in-scope token state without a serialisable representation fails before any parent XML is written rather than producing an empty wrapper.Empty
BinarySecretelements retain theirTypewith an empty data array. Additional XML attributes andSecurityTokenReference.Usagenow round-trip.XML resource limits
Buffered and streamed XML processing now uses a shared parse-scoped budget. Limits are applied before internal buffering and cover depth, buffered bytes, text and Base64 content, element counts, attribute counts, names, and cumulative extension content.
Library-owned XML copying reads text and attribute values in chunks before materialising DOM content. Unknown, skipped, endpoint-reference, and token subtrees all use this bounded path. Quota failures use
IDX15026.The current internal defaults allow up to 4 MB of buffered or textual XML content and 4,096 elements or attributes within one parse.
Compatibility
This is a compatibility-first forward-port of a legacy protocol implementation. Where schema purity and established 6.8 wire behaviour differ, this PR preserves the deployed behaviour unless a change is required to address a concrete safety, correctness, or interoperability failure. Broader protocol changes remain separate and require consumer-specific validation.
The existing public API remains available. Duplicate singleton handling,
TokenElementprecedence, extension placement, and the broad 6.8 properties that are outside the validated WCF scenarios remain unchanged.The existing
WriteRequestoverload preserves the 6.8ActAsbehaviour. Callers must use the new overload to include it. Other broader serializer-completeness work remains separate.The intentional behaviour changes are limited to states that previously appeared to serialise successfully while producing unusable empty content, malformed input that cannot safely make progress, wrong-namespace content that was incorrectly classified as typed content, and messages exceeding the new resource limits.
Validation
net462net472net6.0net8.0net9.0net10.0System.ServiceModel.Federationunit testsMicrosoft.IdentityModelpackages resolved to the same validation versionThe WCF integration matrix covers WS-Trust February 2005 and WS-Trust 1.3, Text and MTOM encodings, and secure-conversation enabled and disabled.
Closes #3463.