Skip to content

Revert #3909: keep OWIN Saml/WsFederation on 5.7.0#3944

Merged
iarekk merged 1 commit into
masterfrom
iarekk/revert-3909-saml-owin
Jul 14, 2026
Merged

Revert #3909: keep OWIN Saml/WsFederation on 5.7.0#3944
iarekk merged 1 commit into
masterfrom
iarekk/revert-3909-saml-owin

Conversation

@iarekk

@iarekk iarekk commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Reverts #3909.

That PR (Dependabot) bumped the default IdentityModelV5Version in Microsoft.Identity.Web.OWIN.csproj from 5.7.0 → 8.19.1. This property deliberately pins Microsoft.IdentityModel.Tokens.Saml and Microsoft.IdentityModel.Protocols.WsFederation to the 5.x line for the net472 OWIN package (an 8.x bump was attempted and explicitly reverted in #3900).

Problems with the bump:

  • Only the default branch was changed; the CI path (TF_BUILD=true) still resolves 5.7.1, so local builds (now 8.19.1) diverge from official builds.
  • The MSB3277 warning suppression is still keyed to '5.7.1', so it no longer matches the default value.

Reverting to 5.7.0 until the intent/impact is clarified.

Reverts the default IdentityModelV5Version bump from 8.19.1 back to 5.7.0.
This property deliberately pins Microsoft.IdentityModel.Tokens.Saml and
Microsoft.IdentityModel.Protocols.WsFederation to the 5.x line for the
net472 OWIN package. The bump only touched the default branch (CI/TF_BUILD
stays 5.7.1) and left the MSB3277 suppression keyed to 5.7.1, causing a
local-vs-CI version divergence. Reverting until the intent is clarified.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 742e5e40-2da7-4d10-af81-d038b3802ce4
@iarekk
iarekk requested a review from a team as a code owner July 14, 2026 14:20
@iarekk
iarekk merged commit c92b806 into master Jul 14, 2026
8 checks passed
@iarekk
iarekk deleted the iarekk/revert-3909-saml-owin branch July 14, 2026 16:33
This was referenced Jul 17, 2026
This was referenced Jul 19, 2026
github-actions Bot pushed a commit to EelcoLos/nx-tinkering that referenced this pull request Jul 21, 2026
Pinned
[Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web)
at 4.13.2.

<details>
<summary>Release notes</summary>

_Sourced from [Microsoft.Identity.Web's
releases](https://github.com/AzureAD/microsoft-identity-web/releases)._

## 4.13.2

## What's Changed
* Apply reserved-header handling on the request-clone path and cover all
X-MS-TOKEN- headers by @​iNinja in
AzureAD/microsoft-identity-web#3915
* Restore independent PR pipeline + pool-aware MI identity + net462/472
unit tests by @​iarekk in
AzureAD/microsoft-identity-web#3935
* Post-release 4.13.0: changelog and public API shipped move by
@​neha-bhargava in
AzureAD/microsoft-identity-web#3937
* Remove redundant 'Run unit tests' GitHub Action by @​iarekk in
AzureAD/microsoft-identity-web#3939
* Apply consistent redirect-URI validation on AccountController.SignIn
by @​iNinja in
AzureAD/microsoft-identity-web#3940
* Fix duplicate logging of MsalUiRequiredException (in-repo copy of
#​3910) by @​iarekk in
AzureAD/microsoft-identity-web#3941
* Use MSAL's recent UserFIC API for agentic flows by @​Avery-Dunn in
AzureAD/microsoft-identity-web#3842
* Restore CustomizeHttpRequestMessage to run after the authorization
header by @​neha-bhargava in
AzureAD/microsoft-identity-web#3943
* Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by
@​dependabot[bot] in
AzureAD/microsoft-identity-web#3909
* Revert #​3909: keep OWIN Saml/WsFederation on 5.7.0 by @​iarekk in
AzureAD/microsoft-identity-web#3944
* Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by
@​neha-bhargava in
AzureAD/microsoft-identity-web#3947
* Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to
DownstreamApi by @​neha-bhargava in
AzureAD/microsoft-identity-web#3942
* Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj…
by @​trwalke in
AzureAD/microsoft-identity-web#3950
* Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by
@​gladjohn with @​Copilot in
AzureAD/microsoft-identity-web#3949
* Improve IDW10109 error handling for credential loading failures by
@​Avery-Dunn in
AzureAD/microsoft-identity-web#3946
* Bump MSAL dependencies to 4.86.1 in central props by @​gladjohn with
@​Copilot in AzureAD/microsoft-identity-web#3953
* Bump the notsecurity group with 3 updates by @​dependabot[bot] in
AzureAD/microsoft-identity-web#3954


**Full Changelog**:
AzureAD/microsoft-identity-web@4.13.0...4.13.2

Commits viewable in [compare
view](AzureAD/microsoft-identity-web@4.13.0...4.13.2).
</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants