Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi#3942
Merged
Merged
Conversation
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
2 times, most recently
from
July 13, 2026 22:07
937c07e to
3150be1
Compare
bgavrilMS
reviewed
Jul 13, 2026
bgavrilMS
approved these changes
Jul 13, 2026
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
from
July 13, 2026 22:46
3150be1 to
fc2f715
Compare
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
from
July 14, 2026 04:40
fc2f715 to
d39f979
Compare
neha-bhargava
changed the base branch from
master
to
nebharg/fix-customizehttprequestmessage-regression
July 14, 2026 04:40
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
from
July 14, 2026 05:02
d39f979 to
83999d9
Compare
bgavrilMS
reviewed
Jul 14, 2026
bgavrilMS
previously approved these changes
Jul 14, 2026
Base automatically changed from
nebharg/fix-customizehttprequestmessage-regression
to
master
July 14, 2026 10:36
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
3 times, most recently
from
July 14, 2026 17:18
19da5e1 to
022f5fc
Compare
bgavrilMS
approved these changes
Jul 14, 2026
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
from
July 14, 2026 17:57
022f5fc to
96929f4
Compare
…ownstreamApi Honor the new AuthorizationHeaderProviderOptions hooks from Microsoft.Identity.Abstractions 12.5.0: - OnBeforeAuthHeaderCreation runs before the authorization header is created and signed, so callers can shape the request that request-binding protocols (SignedHttpRequest q/h/b) sign, ensuring the signature covers the finalized request. - OnAfterAuthHeaderCreation runs after the header is attached. The pre-existing CustomizeHttpRequestMessage is still invoked at the same point for backwards compatibility. Both hooks are propagated through MicrosoftIdentityMessageHandler. Also declare IAuthorizationHeaderProvider2 only on the Base/Default header providers (it already extends IAuthorizationHeaderProvider), and type the Base provider's delegate field as IAuthorizationHeaderProvider2 to avoid upcasting at the metadata delegation sites. Stacked on the regression fix (#3943). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
neha-bhargava
force-pushed
the
nebharg/fix-customizerequest-header-ordering
branch
from
July 14, 2026 22:35
96929f4 to
0517cbb
Compare
gladjohn
approved these changes
Jul 14, 2026
trwalke
approved these changes
Jul 14, 2026
This was referenced Jul 17, 2026
Merged
This was referenced Jul 19, 2026
Closed
Open
Merged
github-actions Bot
pushed a commit
to EelcoLos/nx-tinkering
that referenced
this pull request
Jul 21, 2026
Pinned [Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web) at 4.13.2. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Identity.Web's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._ ## 4.13.2 ## What's Changed * Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @iNinja in AzureAD/microsoft-identity-web#3915 * Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @iarekk in AzureAD/microsoft-identity-web#3935 * Post-release 4.13.0: changelog and public API shipped move by @neha-bhargava in AzureAD/microsoft-identity-web#3937 * Remove redundant 'Run unit tests' GitHub Action by @iarekk in AzureAD/microsoft-identity-web#3939 * Apply consistent redirect-URI validation on AccountController.SignIn by @iNinja in AzureAD/microsoft-identity-web#3940 * Fix duplicate logging of MsalUiRequiredException (in-repo copy of #3910) by @iarekk in AzureAD/microsoft-identity-web#3941 * Use MSAL's recent UserFIC API for agentic flows by @Avery-Dunn in AzureAD/microsoft-identity-web#3842 * Restore CustomizeHttpRequestMessage to run after the authorization header by @neha-bhargava in AzureAD/microsoft-identity-web#3943 * Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @dependabot[bot] in AzureAD/microsoft-identity-web#3909 * Revert #3909: keep OWIN Saml/WsFederation on 5.7.0 by @iarekk in AzureAD/microsoft-identity-web#3944 * Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @neha-bhargava in AzureAD/microsoft-identity-web#3947 * Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @neha-bhargava in AzureAD/microsoft-identity-web#3942 * Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @trwalke in AzureAD/microsoft-identity-web#3950 * Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3949 * Improve IDW10109 error handling for credential loading failures by @Avery-Dunn in AzureAD/microsoft-identity-web#3946 * Bump MSAL dependencies to 4.86.1 in central props by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3953 * Bump the notsecurity group with 3 updates by @dependabot[bot] in AzureAD/microsoft-identity-web#3954 **Full Changelog**: AzureAD/microsoft-identity-web@4.13.0...4.13.2 Commits viewable in [compare view](AzureAD/microsoft-identity-web@4.13.0...4.13.2). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 21, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Targets 4.13.2. Builds on the regression fix from #3943 (already merged).
What
Adds explicit request-customization hooks to
DownstreamApi, consuming the newAuthorizationHeaderProviderOptionsmembers fromMicrosoft.Identity.Abstractions12.5.0 (AzureAD/microsoft-identity-abstractions-for-dotnet#262):OnBeforeAuthHeaderCreation— runs before the header is created/signed. Use it to shape the request that a request-binding protocol signs (SignedHttpRequestq/h/b), so the signature covers the finalized request.OnAfterAuthHeaderCreation— runs after the header is attached. The pre-existingCustomizeHttpRequestMessageis still invoked at the same point for backwards compatibility (both run; distinct hooks).Both hooks are propagated through
MicrosoftIdentityMessageHandler.Also
BaseAuthorizationHeaderProviderandDefaultAuthorizationHeaderProviderdeclareIAuthorizationHeaderProvider2only (it already extendsIAuthorizationHeaderProvider), and the Base provider's delegate field is typedIAuthorizationHeaderProvider2to avoid upcasting.Tests
OnBeforeAuthHeaderCreation(asserting it reaches the provider before signing).OnBeforesees no header (runs before);OnAfterandCustomizeHttpRequestMessageboth observe it.with SHR/without SHRtests asserting theAuthorizationheader is created and attached in both cases.Depends on
AzureAD/microsoft-identity-abstractions-for-dotnet#262 (Abstractions 12.5.0) — the Abstractions package floor bump is pending its release.