Log IDX10650 decryption-tag failures below Error during multi-key decryption - #3582
Merged
Merged
Conversation
dlingam-msft
reviewed
Aug 3, 2026
Contributor
There was a problem hiding this comment.
Pull request overview
Adjusts IdentityModel’s decryption logging to reduce noisy Error logs from expected per-key JWE authentication-tag failures during multi-key probing, while keeping terminal decryption failures reported at Error for diagnostics and alerting.
Changes:
- Log
IDX10650(per-key auth-tag verification failure) at Informational instead of Error inAuthenticatedEncryptionProvider. - Ensure terminal experimental decryption failures (e.g.,
IDX10603/IDX10609) are explicitly logged at Error when returningValidationErrorresults. - Add regression tests asserting
IDX10650is not logged at Error, and that aggregate failures are logged at Error in the experimental result-based APIs.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| test/Microsoft.IdentityModel.Tokens.Tests/AuthenticatedEncryptionProviderTests.cs | Adds regression coverage for IDX10650 not being emitted at Error during auth-tag failures. |
| test/Microsoft.IdentityModel.JsonWebTokens.Tests/JwtTokenUtilitiesTests.cs | Adds tests asserting aggregate decryption failures are logged at Error for experimental result-based decryption paths. |
| src/Microsoft.IdentityModel.Tokens/Encryption/AuthenticatedEncryptionProvider.cs | Downgrades IDX10650 logging to Informational for expected per-key failures during probing. |
| src/Microsoft.IdentityModel.JsonWebTokens/Experimental/JwtTokenUtilities.DecryptTokenResult.cs | Logs terminal decryption failures at Error before returning ValidationError. |
| src/Microsoft.IdentityModel.JsonWebTokens/Experimental/JsonWebTokenHandler.DecryptToken.cs | Logs the “no keys” terminal decryption failure (IDX10609) at Error before returning ValidationError. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Peter (pmaytak)
approved these changes
Aug 10, 2026
…ryption A per-key JWE authentication-tag failure (IDX10650) is expected noise while JsonWebTokenHandler probes multiple candidate decryption keys (try-all when it cannot resolve one by kid/x5t). Logging each attempt at Error produced many Error-level logs during otherwise-successful token validation, which broke partner alerting and could not be filtered. Log the per-key failure at Informational instead. It is suppressed by default (default LogLevel is Warning) and remains available for diagnostics. The terminal all-keys-failed case is still reported at Error via IDX10603/IDX10609, which aggregates each attempted key's exception detail, so nothing is lost. Adds a regression test asserting IDX10650 is not logged at Error but is logged at Informational. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e44607d1-865c-48e7-ae30-00c20c10cf9d
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: c2f4dfa6-00c6-4841-827a-d25b5fe0b707
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 6bff5eb6-d9ec-4862-91a4-e02db1e0d08d
RojaEnnam
force-pushed
the
roennam/idx10650-log-severity-dev8x
branch
from
August 28, 2026 20:55
8d81843 to
05109b4
Compare
Westin Musser (westin-m)
approved these changes
Aug 28, 2026
This was referenced Sep 21, 2026
This was referenced Sep 28, 2026
Open
Open
build(deps): Bump the minor-and-patch group with 2 updates
MaximeMichaud/expressiondansebeauport#302
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A per-key JWE authentication-tag failure (IDX10650) is expected noise while JsonWebTokenHandler probes multiple candidate decryption keys (try-all when it cannot resolve one by kid/x5t). Logging each attempt at Error produced many Error-level logs during otherwise-successful token validation, which broke partner alerting and could not be filtered.
Log the per-key failure at Informational instead. It is suppressed by default (default LogLevel is Warning) and remains available for diagnostics. The terminal all-keys-failed case is still reported at Error via IDX10603/IDX10609, which aggregates each attempted key's exception detail, so nothing is lost.
Adds a regression test asserting IDX10650 is not logged at Error but is logged at Informational.