Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] When will Proof of Possession be released? #4665

Closed
sameerkapps opened this issue Mar 15, 2024 · 2 comments
Closed

[Bug] When will Proof of Possession be released? #4665

sameerkapps opened this issue Mar 15, 2024 · 2 comments

Comments

@sameerkapps
Copy link
Contributor

Library version used

4.54.0

.NET version

N/A

Scenario

ConfidentialClient - service to service (AcquireTokenForClient)

Is this a new or an existing app?

None

Issue description and reproduction steps

Doc says that Pop token is experimental for confidential clients. Is the doc correct? If so, is when do you plan to remove it as experimental feature?

Relevant code snippets

No response

Expected behavior

No response

Identity provider

Microsoft Entra ID (Work and School accounts and Personal Microsoft accounts)

Regression

No response

Solution and workarounds

No response

@sameerkapps sameerkapps added needs attention Delete label after triage untriaged Do not delete. Needed for Automation labels Mar 15, 2024
@bgavrilMS
Copy link
Member

bgavrilMS commented Mar 19, 2024

Hi @sameerkapps - long time :)

We are looking into a different approach for POP for confidential client, based on MTLS, because it's faster.

I think the version of POP that is already out there as experimental is ok from security perspective and we will keep it (maybe we'll rename the API at some point).

Note that we don't have token validators for POP tokens, so if you need to protect your own web api, you'll have to customize token validation to handle these tokens. Microsoft APIs are adopting this.

@gladjohn gladjohn added question answered and removed needs attention Delete label after triage untriaged Do not delete. Needed for Automation labels Mar 19, 2024
@sameerkapps
Copy link
Contributor Author

Thanks. We cannot use experimental api in the production code. So we will use the non-pop token. But still using the product. 😀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants