Skip to content

Log IDX10650 decryption-tag failures below Error during multi-key decryption - #3582

Merged
RojaEnnam merged 3 commits into
dev8xfrom
roennam/idx10650-log-severity-dev8x
Aug 28, 2026
Merged

RojaEnnam merged 3 commits into
dev8xfrom
roennam/idx10650-log-severity-dev8x

Conversation

@RojaEnnam

Copy link
Copy Markdown
Contributor

A per-key JWE authentication-tag failure (IDX10650) is expected noise while JsonWebTokenHandler probes multiple candidate decryption keys (try-all when it cannot resolve one by kid/x5t). Logging each attempt at Error produced many Error-level logs during otherwise-successful token validation, which broke partner alerting and could not be filtered.

Log the per-key failure at Informational instead. It is suppressed by default (default LogLevel is Warning) and remains available for diagnostics. The terminal all-keys-failed case is still reported at Error via IDX10603/IDX10609, which aggregates each attempted key's exception detail, so nothing is lost.

Adds a regression test asserting IDX10650 is not logged at Error but is logged at Informational.

@RojaEnnam
RojaEnnam requested a review from a team as a code owner August 3, 2026 19:49
@pmaytak
Peter (pmaytak) requested review from a team and a lite review from Copilot August 4, 2026 16:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adjusts IdentityModel’s decryption logging to reduce noisy Error logs from expected per-key JWE authentication-tag failures during multi-key probing, while keeping terminal decryption failures reported at Error for diagnostics and alerting.

Changes:

  • Log IDX10650 (per-key auth-tag verification failure) at Informational instead of Error in AuthenticatedEncryptionProvider.
  • Ensure terminal experimental decryption failures (e.g., IDX10603 / IDX10609) are explicitly logged at Error when returning ValidationError results.
  • Add regression tests asserting IDX10650 is not logged at Error, and that aggregate failures are logged at Error in the experimental result-based APIs.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
test/Microsoft.IdentityModel.Tokens.Tests/AuthenticatedEncryptionProviderTests.cs Adds regression coverage for IDX10650 not being emitted at Error during auth-tag failures.
test/Microsoft.IdentityModel.JsonWebTokens.Tests/JwtTokenUtilitiesTests.cs Adds tests asserting aggregate decryption failures are logged at Error for experimental result-based decryption paths.
src/Microsoft.IdentityModel.Tokens/Encryption/AuthenticatedEncryptionProvider.cs Downgrades IDX10650 logging to Informational for expected per-key failures during probing.
src/Microsoft.IdentityModel.JsonWebTokens/Experimental/JwtTokenUtilities.DecryptTokenResult.cs Logs terminal decryption failures at Error before returning ValidationError.
src/Microsoft.IdentityModel.JsonWebTokens/Experimental/JsonWebTokenHandler.DecryptToken.cs Logs the “no keys” terminal decryption failure (IDX10609) at Error before returning ValidationError.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

RojaEnnam and others added 3 commits August 28, 2026 13:55
…ryption

A per-key JWE authentication-tag failure (IDX10650) is expected noise while
JsonWebTokenHandler probes multiple candidate decryption keys (try-all when it
cannot resolve one by kid/x5t). Logging each attempt at Error produced many
Error-level logs during otherwise-successful token validation, which broke
partner alerting and could not be filtered.

Log the per-key failure at Informational instead. It is suppressed by default
(default LogLevel is Warning) and remains available for diagnostics. The
terminal all-keys-failed case is still reported at Error via IDX10603/IDX10609,
which aggregates each attempted key's exception detail, so nothing is lost.

Adds a regression test asserting IDX10650 is not logged at Error but is logged
at Informational.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e44607d1-865c-48e7-ae30-00c20c10cf9d
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c2f4dfa6-00c6-4841-827a-d25b5fe0b707
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 6bff5eb6-d9ec-4862-91a4-e02db1e0d08d
@RojaEnnam
RojaEnnam force-pushed the roennam/idx10650-log-severity-dev8x branch from 8d81843 to 05109b4 Compare August 28, 2026 20:55
@RojaEnnam
RojaEnnam merged commit 155e9cb into dev8x Aug 28, 2026
2 checks passed
This was referenced Sep 21, 2026
This was referenced Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Reduce IDX10650 log severity during successful multi-key JWE decryption

5 participants