Backport SHR p-claim percent-encoding hex case handling to dev8x - #3578
Closed
debchoudhury-id4s wants to merge 1 commit into
Closed
debchoudhury-id4s wants to merge 1 commit into
debchoudhury-id4s wants to merge 1 commit into
Conversation
) * Handle SHR p-claim percent-encoding hex case Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> (cherry picked from commit 58d6002)
Contributor
There was a problem hiding this comment.
Pull request overview
Backport of SHR p-claim validation behavior to the dev8x line so that percent-encoded triplets compare hex letters case-insensitively (per RFC 3986), while preserving the existing 8.x default behavior for literal path casing via UseCaseSensitivePClaimComparison and keeping p-claim creation output unchanged.
Changes:
- Updated
SignedHttpRequestHandler.ValidatePClaimto avoid allocations via span-based trimming/comparison and added%XX-aware ordinal comparison logic for hex-letter casing. - Expanded validation test coverage with a comparison matrix and exception-message casing checks.
- Added creation tests to ensure percent-encoding hex casing and double-encoding are preserved in output; documented the change in the changelog.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| test/Microsoft.IdentityModel.Protocols.SignedHttpRequest.Tests/SignedHttpRequestValidationTests.cs | Adds targeted tests covering hex-case equivalence in %XX triplets, switch behavior, and exception-message casing. |
| test/Microsoft.IdentityModel.Protocols.SignedHttpRequest.Tests/SignedHttpRequestCreationTests.cs | Adds tests verifying p claim creation preserves percent-encoding casing (lower/upper) and double-encoding. |
| src/Microsoft.IdentityModel.Protocols.SignedHttpRequest/SignedHttpRequestHandler.cs | Implements allocation-free trimming/comparison and %XX-aware equality for ordinal comparisons. |
| CHANGELOG.md | Notes the backported bug fix in the release notes. |
RojaEnnam
approved these changes
Jul 30, 2026
Contributor
Author
|
Superseded by #3579, which uses a branch directly in the AzureAD repository and includes the dev8x conflict resolution. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Backports #3561 to the dev8x branch.
Testing