Skip to content

Register IAuthorizationHeaderProvider2 in DI#3927

Merged
neha-bhargava merged 3 commits into
masterfrom
nebharg/register-iauthorizationheaderprovider2
Jul 7, 2026
Merged

Register IAuthorizationHeaderProvider2 in DI#3927
neha-bhargava merged 3 commits into
masterfrom
nebharg/register-iauthorizationheaderprovider2

Conversation

@neha-bhargava

Copy link
Copy Markdown
Contributor

DefaultAuthorizationHeaderProvider implements both IAuthorizationHeaderProvider and IAuthorizationHeaderProvider2, but AddTokenAcquisition only registered v1. So resolving IAuthorizationHeaderProvider2 directly returned nothing - our own consumers (DownstreamApi, MicrosoftIdentityMessageHandler) only worked because they resolve v1 and cast.

This registers v2 pointing at the same instance, using the same pattern we already use to expose ITokenAcquisitionInternal / IConfidentialClientApplicationProvider off ITokenAcquisition:

  • Added in both the singleton and scoped branches.
  • Captured + removed in the lifetime-mismatch re-registration so it doesn't leak a stale descriptor.

Tests: updated the two service-collection assertions, and added a Registers + a Resolves-to-same-instance test.

DefaultAuthorizationHeaderProvider implements both IAuthorizationHeaderProvider and
IAuthorizationHeaderProvider2, but only v1 was registered - so resolving v2 directly
returned nothing (internal callers only worked because they cast). Register v2 as the
same instance (mirroring how ITokenAcquisitionInternal is exposed off ITokenAcquisition)
in both the singleton and scoped paths, and remove it on the lifetime-mismatch re-registration.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@bgavrilMS
bgavrilMS force-pushed the nebharg/register-iauthorizationheaderprovider2 branch from 62f62ca to e31076a Compare July 7, 2026 11:20
neha-bhargava and others added 2 commits July 7, 2026 09:51
* Register IAuthorizationHeaderProvider2 in DI

DefaultAuthorizationHeaderProvider implements both IAuthorizationHeaderProvider and
IAuthorizationHeaderProvider2, but only v1 was registered - so resolving v2 directly
returned nothing (internal callers only worked because they cast). Register v2 as the
same instance (mirroring how ITokenAcquisitionInternal is exposed off ITokenAcquisition)
in both the singleton and scoped paths, and remove it on the lifetime-mismatch re-registration.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Add GetAuthorizationHeaderProvider2() to OWIN controllers

OWIN controllers already get a one-liner for the v1 IAuthorizationHeaderProvider;
this adds the same convenience for IAuthorizationHeaderProvider2 on both ApiController
and ControllerBase, resolving it from the OWIN TokenAcquirerFactory service provider.

Depends on IAuthorizationHeaderProvider2 being registered in DI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@neha-bhargava
neha-bhargava merged commit 922beec into master Jul 7, 2026
5 checks passed
@neha-bhargava
neha-bhargava deleted the nebharg/register-iauthorizationheaderprovider2 branch July 7, 2026 20:25
neha-bhargava added a commit that referenced this pull request Jul 10, 2026
Add the 4.13.0 changelog section (OWIN GetAuthorizationHeaderProvider2 #3928, IAuthorizationHeaderProvider2 DI registration #3927, MSAL 4.86.0 bump #3931), move the OWIN unshipped public API entries to shipped, and bump the dev version to 4.13.1.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Jul 10, 2026
This was referenced Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants