Skip to content

Reinstate Microsoft.IdentityModel.Protocols.WsTrust as a supported 8.x package - #3547

Merged
Ignacio Inglese (iNinja) merged 19 commits into
dev8xfrom
iinglese/wstrust-forward-port
Aug 25, 2026
Merged

Ignacio Inglese (iNinja) merged 19 commits into
dev8xfrom
iinglese/wstrust-forward-port

Conversation

@iNinja

@iNinja Ignacio Inglese (iNinja) commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Reinstates Microsoft.IdentityModel.Protocols.WsTrust as a supported package in the Wilson 8.x line. The package was deprecated in 6.x, while System.ServiceModel.Federation still depends on it and has no replacement path. See #3463.

This forward-port preserves the 6.8 public surface and the behaviour required by WCF, adds current target frameworks and build integration, and addresses the parser, serializer, and resource-handling defects found during review.

Review guide

The implementation evolved through review. Please assess the final diff rather than relying on intermediate commit states.

Suggested review order:

  1. Forward-port, build, and API surface
    • Package and test project integration
    • Target frameworks
    • Public and internal API baselines
  2. AOT and compatibility corrections
    • SAML source preservation without reflection
    • WS-Trust constants and key-generation corrections
    • Existing 6.8 compatibility boundaries
  3. Parser and container boundaries
    • Reader progress
    • Empty elements
    • Unknown and extension content
    • Request and response attributes
  4. Token, reference, and extension handling
    • OnBehalfOf, ProofEncryption, UseKey, and requested tokens
    • XML Encryption proof-token round-tripping
    • Opt-in ActAs
  5. XML resource limits
    • Parse-scoped cumulative budgets
    • Bounded streaming before DOM materialisation
    • Skipped and unknown subtree handling
  6. Regression and interoperability coverage
    • Six target frameworks
    • WCF unit tests
    • Live independent STS scenarios

Forward-port

The WS-Trust source was ported from the original 6.8 codebase to dev8x.

Area Change
Target frameworks net462, net472, netstandard2.0, net6.0, net8.0, net9.0, net10.0
Build integration Added the package and test projects to the solution and package build
Cryptography Replaced obsolete RNGCryptoServiceProvider usage
API tracking Added public and internal API baselines
AOT and trimming Removed reflection used to access captured SAML XML and enabled direct internal access from Microsoft.IdentityModel.Tokens.Saml
XML handling Disabled external XML resolution and bounded buffered XML processing

Parser and serializer corrections

The updated serializer guarantees progress when reading unknown or empty elements and keeps each reader within its own wrapper. This covers unknown proof-token content, endpoint-reference extensions, duplicate AppliesTo local names, non-empty request extensions, empty context items, empty request and response containers, and reference wrappers.

Request and response extension attributes now preserve their names, namespaces, and values without duplicating typed Context or namespace declarations. Response context and open content round-trip through the public model.

Typed WS-* elements are recognised by exact QName. Wrong-namespace lookalikes remain non-fatal and are captured as extensions or skipped according to the containing element.

Token, security-token-reference, and preserved raw XML forms now share the same read and write paths for OnBehalfOf, ProofEncryption, UseKey, and RequestedSecurityToken. Existing TokenElement precedence and empty ProofEncryption read behaviour are preserved. Static UseKey and ProofEncryption APIs also accept explicit token-handler collections.

An additive WriteRequest overload can opt in to serialising the existing ActAs property. The existing overload remains unchanged and continues to omit ActAs for compatibility. The opt-in path writes the WS-Trust 1.4 200802 extension inside the selected core request namespace, preserves SAML source XML, supports security-token references and custom handlers, and writes ActAs before AdditionalContext.

Parsed XML Encryption EncryptedKey content can be retained and round-tripped. A manually constructed empty EncryptedKey, protected entropy, or another in-scope token state without a serialisable representation fails before any parent XML is written rather than producing an empty wrapper.

Empty BinarySecret elements retain their Type with an empty data array. Additional XML attributes and SecurityTokenReference.Usage now round-trip.

XML resource limits

Buffered and streamed XML processing now uses a shared parse-scoped budget. Limits are applied before internal buffering and cover depth, buffered bytes, text and Base64 content, element counts, attribute counts, names, and cumulative extension content.

Library-owned XML copying reads text and attribute values in chunks before materialising DOM content. Unknown, skipped, endpoint-reference, and token subtrees all use this bounded path. Quota failures use IDX15026.

The current internal defaults allow up to 4 MB of buffered or textual XML content and 4,096 elements or attributes within one parse.

Compatibility

This is a compatibility-first forward-port of a legacy protocol implementation. Where schema purity and established 6.8 wire behaviour differ, this PR preserves the deployed behaviour unless a change is required to address a concrete safety, correctness, or interoperability failure. Broader protocol changes remain separate and require consumer-specific validation.

The existing public API remains available. Duplicate singleton handling, TokenElement precedence, extension placement, and the broad 6.8 properties that are outside the validated WCF scenarios remain unchanged.

The existing WriteRequest overload preserves the 6.8 ActAs behaviour. Callers must use the new overload to include it. Other broader serializer-completeness work remains separate.

The intentional behaviour changes are limited to states that previously appeared to serialise successfully while producing unusable empty content, malformed input that cannot safely make progress, wrong-namespace content that was incorrectly classified as typed content, and messages exceeding the new resource limits.

Validation

Check Result
WS-Trust tests on net462 183 passed
WS-Trust tests on net472 183 passed
WS-Trust tests on net6.0 183 passed
WS-Trust tests on net8.0 183 passed
WS-Trust tests on net9.0 183 passed
WS-Trust tests on net10.0 183 passed
Total WS-Trust test executions 1,098 passed, 0 failed, 0 skipped
System.ServiceModel.Federation unit tests 3 passed, 0 failed
WCF federation integration tests against the independent net471 STS 10 passed, 0 failed, 0 skipped
Package dependency alignment All required Microsoft.IdentityModel packages resolved to the same validation version

The WCF integration matrix covers WS-Trust February 2005 and WS-Trust 1.3, Text and MTOM encodings, and secure-conversation enabled and disabled.

Closes #3463.

Ignacio Inglese (iNinja) and others added 2 commits July 15, 2026 14:25
…trust to dev8x

Port the WS-Trust implementation from the origin/wstrust feature branch
(based on 6.x) to the current dev8x branch (8.x). This package provides
the active WS-Trust SOAP profile needed by System.ServiceModel.Federation
(WCF), which cannot be replaced by WsFederation (passive/browser SSO).

Addresses: #3463

Changes from the original branch code:
- Modernized csproj: removed FxCopAnalyzers, PackageReference -> ProjectReference,
  added PublicApiAnalyzers/InternalApiAnalyzers support, trimming annotations
- Updated file headers to match current .editorconfig conventions
- Replaced obsolete RNGCryptoServiceProvider with RandomNumberGenerator.Create()
- Added DynamicallyAccessedMembers annotations for AOT/trimming compatibility
- Added using Microsoft.IdentityModel.Xml to test files for XmlReadException
- Fixed CLSCompliant attribute in test AssemblyInfo (true -> false)
- Generated PublicAPI.Unshipped.txt (588 entries) and InternalAPI.Unshipped.txt

Test results: 117 tests pass across net8.0, net9.0, and net10.0

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
AOT compatibility:
- Replace Type.InvokeMember reflection in WsTrustSerializer.TryWriteSourceData
  with direct access to the internal XmlTokenStream property
- Add InternalsVisibleTo from Tokens.Saml to Protocols.WsTrust
- Zero trimming/AOT warnings

Security hardening:
- Set XmlResolver = null on all XmlDocument instances (XXE defence)
- IDX15101 error uses reader.LocalName instead of ReadOuterXml (prevents
  token content leakage in exception messages)
- Add DepthLimitingXmlReader (MaxDepth=32) to ReadUnknownElement and
  ReadEndpointReference (XML nesting DoS defence)
- Apply BoundedXmlDictionaryReaderQuotas in ReadAsXmlElement and
  CreateXmlElement
- Replace XmlTextReader with XmlDictionaryReader.CreateTextReader in
  WsSecuritySerializer.CreateXmlElement
- Fix ReadBinarySecrect to read attributes before empty-element check;
  return null for empty elements to avoid NullReferenceException on .Data
- Add missing throw to null guards in Entropy static helpers and
  Psha1KeyGenerator.FillRandomBytes
- Fix double-wrapped FormatInvariant in Psha1KeyGenerator entropy size
  checks, restoring ArgumentException.ParamName

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR reinstates Microsoft.IdentityModel.Protocols.WsTrust as a supported Wilson 8.x package by forward-porting the WS-Trust implementation and adding modern TFMs, build integration, and unit tests so downstream consumers (notably WCF System.ServiceModel.Federation) can continue to use WS-Trust without a migration path.

Changes:

  • Adds the Microsoft.IdentityModel.Protocols.WsTrust package project (plus supporting WS-* protocol/object-model types) and integrates it into the solution/build.
  • Adds a new Microsoft.IdentityModel.Protocols.WsTrust.Tests test project with coverage for core serializer/object-model functionality.
  • Adds an InternalsVisibleTo bridge from Microsoft.IdentityModel.Tokens.Saml to the new WsTrust assembly to enable trimming/AOT-safe internal access paths.

Reviewed changes

Copilot reviewed 97 out of 99 changed files in this pull request and generated 14 comments.

Show a summary per file
File Description
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/WsTrustTheoryData.cs Adds shared test data container for WS-Trust tests.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/WsDefaults.cs Adds common WS-* default objects/values for tests.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/UseKeyTests.cs Adds tests for reading/writing <wst:UseKey>.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/RequestSecurityTokenResponseTests.cs Adds tests for reading/writing WS-Trust responses and token validation path.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/RequestedProofTokenTests.cs Adds tests for <wst:RequestedProofToken> read/write.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/Properties/AssemblyInfo.cs Test assembly metadata (CLS compliance, ComVisible).
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/Microsoft.IdentityModel.Protocols.WsTrust.Tests.csproj Introduces WS-Trust test project and references.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/EntropyTests.cs Adds tests for <wst:Entropy> read/write.
test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/DerivedKeyTests.cs Adds tests for PSHA1 combined/derived key generation behavior.
src/Microsoft.IdentityModel.Tokens.Saml/Properties/AssemblyInfo.cs Grants WsTrust assembly internal access for trimming/AOT-safe paths.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionElements.cs Adds XML Encryption element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionDataTypes.cs Adds XML Encryption datatype constants container.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionConstants.cs Adds XML Encryption namespace/prefix constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/XmlEncryptionAttributes.cs Adds XML Encryption attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/EncryptedKey.cs Adds placeholder model for encrypted key representation.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlEnc/EncryptedData.cs Adds placeholder model for encrypted data representation.
src/Microsoft.IdentityModel.Protocols.WsTrust/XmlAttributeHolder.cs Adds internal attribute buffering utility for WS-* readers.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityElements.cs Adds WS-Utility element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityConstants.cs Adds WS-Utility namespace/prefix constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsUtility/WsUtilityAttributes.cs Adds WS-Utility attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustVersion.cs Adds WS-Trust version discriminator types.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustResponse.cs Adds WS-Trust response model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustRequest.cs Adds WS-Trust request model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustKeyTypes.cs Adds WS-Trust KeyType URI constants by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustFaultCodes.cs Adds WS-Trust fault-code constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustElements.cs Adds WS-Trust element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustConstants.cs Adds WS-Trust namespace/prefix/constants container by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustBinarySecrectTypes.cs Adds WS-Trust BinarySecret type URI constants by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustAttributes.cs Adds WS-Trust attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustActions.cs Adds WS-Trust Action URI constants by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityVersion.cs Adds WS-Security version discriminator types.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecuritySerializer.cs Adds WS-Security read/write helpers for key identifiers and STRs.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityKeyTypes.cs Adds WS-Security key type URI constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityEncodingTypes.cs Adds WS-Security encoding-type URI constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityElements.cs Adds WS-Security element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityConstants.cs Adds WS-Security namespace/prefix/constants container.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityAttributes.cs Adds WS-Security attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/SecurityTokenReference.cs Adds WS-Security SecurityTokenReference model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/KeyIdentifier.cs Adds WS-Security KeyIdentifier model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyVersion.cs Adds WS-Policy version discriminator types.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicySerializer.cs Adds WS-Policy read/write helpers (AppliesTo/PolicyReference).
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyElements.cs Adds WS-Policy element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyConstants.cs Adds WS-Policy namespace/prefix constants container by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/WsPolicyAttributes.cs Adds WS-Policy attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/PolicyReference.cs Adds WS-Policy PolicyReference model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsPolicy/AppliesTo.cs Adds WS-Policy AppliesTo model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedVersion.cs Adds WS-Federation version discriminator types.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedSerializer.cs Adds WS-Federation read/write helpers for claims/additional context.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedElements.cs Adds WS-Federation element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedConstants.cs Adds WS-Federation namespace/prefix constants container.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/WsFedAttributes.cs Adds WS-Federation attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/ContextItem.cs Adds WS-Federation ContextItem model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/ClaimType.cs Adds WS-Federation ClaimType model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsFed/AdditionalContext.cs Adds WS-Federation AdditionalContext model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingSerializer.cs Adds WS-Addressing read/write for endpoint references with depth limiting.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingElements.cs Adds WS-Addressing element-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingConstants.cs Adds WS-Addressing namespace/prefix constants container by version.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddressingAttributes.cs Adds WS-Addressing attribute-name constants.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/WsAddresingVersion.cs Adds WS-Addressing version discriminator types.
src/Microsoft.IdentityModel.Protocols.WsTrust/WsAddressing/EndpointReference.cs Adds WS-Addressing EndpointReference model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/UseKey.cs Adds WS-Trust UseKey model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/SecurityTokenElement.cs Adds wrapper model for token/token-reference serialization.
src/Microsoft.IdentityModel.Protocols.WsTrust/RequestSecurityTokenResponse.cs Adds WS-Trust RSTR model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/RequestedSecurityToken.cs Adds WS-Trust requested-token model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/RequestedProofToken.cs Adds WS-Trust proof-token model type.
src/Microsoft.IdentityModel.Protocols.WsTrust/Renewing.cs Adds WS-Trust renewing preference model.
src/Microsoft.IdentityModel.Protocols.WsTrust/PublicAPI.Shipped.txt Adds/updates shipped public API declarations for the package.
src/Microsoft.IdentityModel.Protocols.WsTrust/PshaDerivedKeyGenerator.cs Adds PSHA-based derived key generator implementation.
src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs Adds PSHA1 key generation utilities used by WS-Trust.
src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsUtils.cs Adds WS-* XML utilities including bounded quotas and depth limiting reader.
src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsSerializationContext.cs Adds per-WS-Trust-version protocol constants binding context.
src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsConstantsBase.cs Adds base type for WS-* constants (Namespace/Prefix).
src/Microsoft.IdentityModel.Protocols.WsTrust/ProtectedKey.cs Adds protected-key model for entropy handling.
src/Microsoft.IdentityModel.Protocols.WsTrust/Properties/AssemblyInfo.cs Adds assembly metadata and InternalsVisibleTo for tests.
src/Microsoft.IdentityModel.Protocols.WsTrust/Participants.cs Adds WS-Trust participants model.
src/Microsoft.IdentityModel.Protocols.WsTrust/Microsoft.IdentityModel.Protocols.WsTrust.csproj Introduces the new supported WS-Trust package project and references.
src/Microsoft.IdentityModel.Protocols.WsTrust/LogMessages.cs Adds WS-Trust log message IDs used for XML/serializer diagnostics.
src/Microsoft.IdentityModel.Protocols.WsTrust/Lifetime.cs Adds WS-Trust lifetime model with UTC normalization and warnings.
src/Microsoft.IdentityModel.Protocols.WsTrust/IXmlOpenItem.cs Adds extensibility interface for additional XML items.
src/Microsoft.IdentityModel.Protocols.WsTrust/InternalAPI.Shipped.txt Adds shipped internal API declarations (currently empty placeholder).
src/Microsoft.IdentityModel.Protocols.WsTrust/GlobalSuppressions.cs Adds analyzers suppressions for the new package surface.
src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustWriteException.cs Adds WS-Trust write exception type.
src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustReadException.cs Adds WS-Trust read exception type.
src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/WsTrustException.cs Adds base WS-Trust exception type.
src/Microsoft.IdentityModel.Protocols.WsTrust/Exceptions/ExceptionLogger.cs Adds helper for WS-Trust exception logging/wrapping.
src/Microsoft.IdentityModel.Protocols.WsTrust/Entropy.cs Adds entropy model type for key material/protected key.
src/Microsoft.IdentityModel.Protocols.WsTrust/Claims.cs Adds WS-Trust claims request model.
src/Microsoft.IdentityModel.Protocols.WsTrust/BinarySecret.cs Adds binary secret model for entropy material.
src/Microsoft.IdentityModel.Protocols.WsTrust/BinaryExchange.cs Adds binary exchange model for WS-Trust exchanges.
.gitignore Ignores local NuGet folder used for local packaging.

Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustResponse.cs
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustBinarySecrectTypes.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustBinarySecrectTypes.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecurityConstants.cs Outdated
Comment thread test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/WsDefaults.cs Outdated
Comment thread test/Microsoft.IdentityModel.Protocols.WsTrust.Tests/EntropyTests.cs Outdated
Ignacio Inglese (iNinja) and others added 2 commits July 15, 2026 17:11
Bugs:
- WsTrustResponse: add missing throw to null guard (null was silently
  accepted into RequestSecurityTokenResponseCollection)
- WsTrustBinarySecrectTypes: fix WS-Trust 1.4 AsymmetricKey URI
  (was Bearer URI; correct value is 200802/AsymmetricKey)
- Psha1KeyGenerator.GenerateSymmetricKey: fix swapped issuer/requestor
  entropy in ComputeCombinedKey call
- WsSecuritySerializer: read wsu:Id using WS-Utility namespace instead
  of WS-Security namespace
- WsSecuritySerializer: write Id as wsu:Id with correct namespace/prefix
- WsFedSerializer: fix error message for missing ClaimType Uri attribute
  (was referencing ContextItem/Name)

Minor:
- WsSecurityConstants: cache WsSecurity10/WsSecurity11 as static fields
  instead of allocating on each property access
- Psha1KeyGenerator: align XML doc param order with method signature

Cleanup:
- Remove trailing semicolon in WsTrustBinarySecrectTypes
- Fix test method name misspelling (ReadRequestSeurityTokenResponse)
- Fix pragma comment typo in WsDefaults (nEndoot)
- Remove commented-out dead assertion in EntropyTests

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
The solution file was opened in Visual Studio which regenerated all
platform configuration entries adding Debug|x64, Debug|x86, Release|x64
and Release|x86 for every project. Restore to the original Any CPU-only
format and retain only the two new WsTrust project entries.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee

@adcosta118 André Costa (adcosta118) left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review of the post-port improvement commits (69ec2ac, 7378709, 96d8e84); the forward-port commit 89aa624 was excluded per request. Findings are inline. 🤖 AI-generated — please verify.

Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustBinarySecrectTypes.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustSerializer.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustSerializer.cs
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsUtils.cs
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsUtils.cs
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Protocols/WsUtils.cs
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsSecurity/WsSecuritySerializer.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/WsTrustSerializer.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs Outdated
Comment thread src/Microsoft.IdentityModel.Protocols.WsTrust/Psha1KeyGenerator.cs
Ignacio Inglese (iNinja) and others added 6 commits July 17, 2026 11:48
BinarySecret URI fix:
- WsTrust14BinarySecretTypes: update Nonce and SymmetricKey to 200802
  namespace (AsymmetricKey was already fixed; Actions and KeyTypes use
  200512 intentionally per the WS-Trust 1.4 spec WSDL)

ReadBinarySecrect empty element:
- Return BinarySecret with EncodingType set instead of null for empty
  elements, preserving the Type attribute per spec (BinarySecret content
  is optional, Type attribute is OPTIONAL but meaningful)

BoundedReaderQuotas consistency:
- WsSecuritySerializer.CreateXmlElement: use WsUtils.BoundedReaderQuotas
  instead of XmlDictionaryReaderQuotas.Max

GenerateSymmetricKey naming:
- Rename senderEntropy/receiverEntropy to requestorEntropy/issuerEntropy
  to match ComputeCombinedKey parameter names and eliminate ambiguity

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
CredScan's CodeConnString searcher flags the base64 PSHA1 key derivation
reference vectors in ComputedKeyReferences.cs as storage credentials
(5 matches). These are deterministic test vectors for verifying the
PSHA1 combined-key algorithm, not secrets.

The existing 'References.cs' entry does not cover this file as CredScan
matches on exact filename, so an explicit entry is required.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
An earlier change moved the WsTrust14BinarySecretTypes constants to the
http://docs.oasis-open.org/ws-sx/ws-trust/200802 namespace. That was wrong
and this reverts it.

WS-Trust 1.4 is an addendum to 1.3, not a standalone schema. The 1.4 XSD
declares targetNamespace 200802 but binds xmlns:wst to 200512, and it only
defines the 1.4 additions (InteractiveChallenge, TextChallenge,
ChoiceChallenge, ContextData). It never redefines BinarySecretTypeEnum, so
the BinarySecret @type URIs stay at 200512. The same reasoning applies to
WsTrust14Actions and WsTrust14KeyTypes, which were already correct.

The one genuine bug from 6.8.0 is retained: WsTrust14BinarySecretTypes
.AsymmetricKey pointed at the 200512 Bearer KeyType URI instead of
AsymmetricKey.

Adds WsTrustConstantsTests to pin the expected URIs so these values are not
"corrected" again. Verified end to end against a self hosted WCF STS: all 10
System.ServiceModel.Federation federation scenario tests pass over
wstrust13 and wstrustFeb2005, Text and Mtom, with and without secure
conversation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Ensure unknown and empty extension elements advance their outer readers,
reset per-element AppliesTo dispatch state, and preserve request attribute
values without duplicating Context or namespace declarations.

Keep accepted empty request and response models within their own XML
boundaries so they do not inspect or consume following siblings.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Capture and round-trip parsed XML Encryption EncryptedKey elements in
RequestedProofToken. Reject manually constructed empty EncryptedKey values
and protected entropy before mutating the XML writer instead of emitting
misleading empty wrappers.

Add regression tests for parsed encrypted-key round-tripping and atomic
unsupported-state failures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Share token, security-token-reference, and preserved raw XML handling across
OnBehalfOf, ProofEncryption, UseKey, and RequestedSecurityToken. Use capable
token handlers when source XML is unavailable and validate representability
before writing wrappers.

Preserve existing empty ProofEncryption skip behavior and TokenElement
precedence. Add round-trip coverage for references, SAML tokens, and raw
EndpointReference content.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Preserve response Context, custom attributes, and unknown elements. Add a
typed XML attribute collection for BinarySecret, retain empty BinarySecret
Type values with safe data, and serialize SecurityTokenReference Usage.

Recognize typed WS-* children by exact QName while skipping or capturing
wrong-namespace lookalikes, including lookalikes that precede valid
reference children.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Apply parse-scoped cumulative budgets for elements, attributes, characters,
and buffered bytes. Stream string, Base64, and attribute values through the
budget and bound every XML materialization before allocating its DOM.

Use finite dictionary-reader quotas and expose IDX15026 directly for quota
failures. Add coverage for quota boundaries across extensions, known strings,
decoded binary secrets, sibling collections, attributes, and
comment-interleaved text.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Apply the shared parse budget to skipped subtrees and reference wrappers,
preflight nested request and response states before writing parent elements,
and validate EndpointReference Address by exact QName.

Add static UseKey and ProofEncryption overloads for custom token handlers,
with coverage for custom handlers, top-level writer atomicity, bounded skips,
reference child quotas, and wrong-namespace Address handling.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Replace eager subtree and DOM copying with a shared bounded streaming copier
that reads text and attribute values in chunks. Route unknown, skipped,
endpoint-reference, and token XML through the same path before constructing
an XmlDocument.

Add guard-reader, attribute-boundary, chunk-boundary, and special-node tests
for the library-owned buffering paths.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
Add a WriteRequest overload that emits the existing ActAs property in the
WS-Trust 1.4 extension namespace when explicitly requested. Keep the
existing overload and disabled path byte-for-byte compatible.

Reuse source-preserving token, SecurityTokenReference, and custom-handler
serialization with preflight validation before writing the request root.
Add coverage for namespace, ordering, SAML 1.1 and 2.0, signatures, custom
handlers, coexistence, and atomic unsupported-state failure.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a191b9da-fe1b-4bf7-89a2-be044b10e0ee
@iNinja
Ignacio Inglese (iNinja) merged commit 5a619db into dev8x Aug 25, 2026
2 checks passed
This was referenced Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants