Skip to content

Backport SHR p-claim percent-encoding hex case handling to dev8x - #3579

Merged
debchoudhury-id4s merged 1 commit into
dev8xfrom
debchoudhury/shr-p-claim-percent-encoding-backport
Jul 31, 2026
Merged

debchoudhury-id4s merged 1 commit into
dev8xfrom
debchoudhury/shr-p-claim-percent-encoding-backport

Conversation

@debchoudhury-id4s

Copy link
Copy Markdown
Contributor

Summary

Backports #3561 to the dev8x branch.

  • treats hexadecimal letters inside valid percent-encoded triplets as case-insensitive during SHR p claim validation
  • preserves the 8.x default for literal path casing through UseCaseSensitivePClaimComparison
  • keeps encoded characters distinct from literal delimiters and preserves p claim creation output
  • includes the corresponding validation and creation tests

Replaces the fork-based PR #3578.

Testing

  • Targeted ValidatePClaim and CreatePClaim tests pass on .NET 8 and 10 (66 tests per target)
  • .NET 6 and 9 require CI because those runtimes are not installed locally
  • .NET Framework targets require an environment configured for delay-signed assembly verification

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Backports the Signed HTTP Request (SHR) p claim validation fix to the dev8x line so that percent-encoded triplets compare equivalently regardless of hex-letter casing (e.g., %2F == %2f) while preserving the existing UseCaseSensitivePClaimComparison behavior for literal path casing and keeping creation output unchanged.

Changes:

  • Updates SignedHttpRequestHandler.ValidatePClaim to perform an additional percent-triplet-aware comparison when ordinal comparison fails.
  • Expands SHR p claim validation and creation test coverage for percent-encoding hex-case scenarios and delimiter-vs-encoded character distinctions.
  • Adds a changelog entry describing the behavior change.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
src/Microsoft.IdentityModel.Protocols.SignedHttpRequest/SignedHttpRequestHandler.cs Implements percent-triplet-aware equality for p claim validation (case-insensitive hex letters only within valid %XX triplets).
test/Microsoft.IdentityModel.Protocols.SignedHttpRequest.Tests/SignedHttpRequestValidationTests.cs Adds comparison-matrix coverage and exception-message casing preservation tests for ValidatePClaim.
test/Microsoft.IdentityModel.Protocols.SignedHttpRequest.Tests/SignedHttpRequestCreationTests.cs Adds tests ensuring p claim creation preserves percent-encoding hex casing and double-encoding.
CHANGELOG.md Documents the bug fix in the 8.x changelog.

Comment thread CHANGELOG.md
@pmaytak
Peter (pmaytak) requested a review from a team July 31, 2026 04:04
@debchoudhury-id4s
debchoudhury-id4s merged commit bbccd7c into dev8x Jul 31, 2026
3 checks passed
This was referenced Sep 21, 2026
This was referenced Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants