From 1836f5163059c385f0f40da391e2749df7daa1c2 Mon Sep 17 00:00:00 2001 From: Youssef Fahmy Date: Fri, 25 Sep 2026 11:02:21 +0200 Subject: [PATCH 1/2] Update comments in `/refresh` implementation --- .../Core/src/IdentityApiEndpointRouteBuilderExtensions.cs | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs b/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs index b091a69f598e..7101a3865b23 100644 --- a/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs +++ b/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs @@ -181,6 +181,9 @@ public static IEndpointConventionBuilder MapIdentityApi(this IEndpointRou var refreshTicket = refreshTokenProtector.Unprotect(refreshRequest.RefreshToken); // Reject the /refresh attempt with a 401 if the token expired or the security stamp validation fails + // By-design: we don't check whether or not the account is locked out. Locking out is a + // password bruteforce protection and so is irrelevant to check here. + // Refreshing the token doesn't force a sign-in. if (refreshTicket?.Properties?.ExpiresUtc is not { } expiresUtc || timeProvider.GetUtcNow() >= expiresUtc || await signInManager.ValidateSecurityStampAsync(refreshTicket.Principal) is not TUser user) From 5d1464670fe8c53019856b2c0c12cc614a42e9c7 Mon Sep 17 00:00:00 2001 From: Youssef Fahmy Date: Fri, 25 Sep 2026 11:08:39 +0200 Subject: [PATCH 2/2] Apply Copilot suggestion Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .../Core/src/IdentityApiEndpointRouteBuilderExtensions.cs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs b/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs index 7101a3865b23..5a1b335110da 100644 --- a/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs +++ b/src/Identity/Core/src/IdentityApiEndpointRouteBuilderExtensions.cs @@ -181,8 +181,8 @@ public static IEndpointConventionBuilder MapIdentityApi(this IEndpointRou var refreshTicket = refreshTokenProtector.Unprotect(refreshRequest.RefreshToken); // Reject the /refresh attempt with a 401 if the token expired or the security stamp validation fails - // By-design: we don't check whether or not the account is locked out. Locking out is a - // password bruteforce protection and so is irrelevant to check here. + // By design: we don't check whether the account is locked out. Locking out is + // password brute-force protection and is therefore irrelevant to check here. // Refreshing the token doesn't force a sign-in. if (refreshTicket?.Properties?.ExpiresUtc is not { } expiresUtc || timeProvider.GetUtcNow() >= expiresUtc ||