Meaningless error when using both Microsoft.AspNetCore.Authentication.OpenIdConnect 8.0.4 and System.IdentityModel.Tokens.Jwt 7.5.0 or higher #55194
Labels
area-security
Needs: Attention 👋
This issue needs the attention of a contributor, typically because the OP has provided an update.
Needs: Repro
Indicates that the team needs a repro project to continue the investigation on this issue
Is there an existing issue for this?
Describe the bug
When using the Microsoft.AspNetCore.Authentication.OpenIdConnect package version 8.04 and the System.IdentityModel.Tokens.Jwt package version 7.5.0 or higher, a meaningless error arises not pointing in the direction of the cause.
All works well when the System.IdentityModel.Tokens.Jwt package is deleted and the Microsoft.AspNetCore.Authentication.OpenIdConnect package uses its default 7.1.2 version.
Expected Behavior
A working login procedure with up to date System.IdentityModel.Tokens.Jwt package. Please add support for this package in the latest Microsoft.AspNetCore.Authentication.OpenIdConnect package.
Steps To Reproduce
Install both packages and perform an open id connect login procedure with only a Authority set, so the Open ID connect middleware will figure out it's configuration from the .well-known/openid-configuration endpoint.
See https://github.com/POORT8/AspNetCore.Repro.55194 for a minimal reproduction repo.
Exceptions (if any)
No response
.NET Version
.NET 8
Anything else?
No response
The text was updated successfully, but these errors were encountered: