Skip to content

Update preview samples to IdentityServer 8.1.0-preview.4 and show multiple storage instances - #384

Open
Erwinvandervalk wants to merge 3 commits into
mainfrom
ev/8-1-preview-4-sample-updates
Open

Erwinvandervalk wants to merge 3 commits into
mainfrom
ev/8-1-preview-4-sample-updates

Conversation

@Erwinvandervalk

@Erwinvandervalk Erwinvandervalk commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Updates the preview samples to the newly released packages and adds a demo of multiple storage instances.

Package updates

Sample Changes
IdentityServer/v8/Storage Duende.IdentityServer 8.1.0-preview.4, Duende.Storage.Sqlite 2.0.0-preview.3
IdentityServer/v8/UserManagement/AccountLockout Duende.IdentityServer 8.1.0-preview.4, Duende.Storage.Sqlite 2.0.0-preview.3, Duende.UserManagement.IdentityServer8 2.0.0-preview.3
IdentityServer/v8/Spaces The same as AccountLockout, plus Duende.Storage 2.0.0-preview.3 and Duende.Spaces 1.0.0-preview.3

API migrations

  • AddSqliteInMemoryStore(...) is replaced by AddSqliteInMemory(...) / AddSqlite(...).
  • AddStorage(...) now only registers a database. The Storage and Spaces samples call AddConfigurationStorage() and AddOperationalStorage() to keep IdentityServer data in it.
  • User Management no longer has its own AddSqliteStore(...). AccountLockout registers the database with AddStorage(...) on the IdentityServer builder; the database file stays in the same place.
  • AccountLockout calls AddDynamicSchemas() because its schema bootstrapper uses ISchemaAdmin.
  • IDatabaseSchema is replaced by IStorageInstanceSchema.
  • SchemaId.IdentityProvider("oidc") is replaced by SchemaId.OidcIdentityProvider.
  • User Management now requires passwords of at least 15 characters, so the Spaces demo password is now Pa$$Word123456789 (seed data, development settings, README and Playwright tests).
  • Spaces now uses the built-in schemas instead of copies: DefaultOidcProviderSchema for the OIDC identity provider, and BuiltInSchemas.UserProfile.Extend(DemoUserAttributes.UserName) for user profiles (email, name, given_name and family_name are built in). The built-in email is required and unique, so seeded users get <username>@example.com, and external users without an email claim get a per-user placeholder instead of the shared test@test.nl.

Multiple storage instances

The Storage sample now keeps IdentityServer configuration data and operational data in two separate named storage instances, and migrates each one separately:

.AddStorage(SampleStorage.Configuration, s => s.AddSqliteInMemory("IdentityServerStorageSample-Configuration"))
.AddStorage(SampleStorage.Operational,   s => s.AddSqliteInMemory("IdentityServerStorageSample-Operational"))
.AddConfigurationStorage(SampleStorage.Configuration)
.AddOperationalStorage(SampleStorage.Operational)

The home page shows which instance holds which data, and the README has a new "Multiple storage instances" section.

Verification

  • Storage: builds with no warnings. The client credentials token request succeeds with region eu-west and fails with us-east. Signing in as alice with authorization code + PKCE creates a server-side session, which /sample/sessions lists; /sample/clients returns the stored clients.
  • AccountLockout: the app starts, migrates, creates its schema and seed users, and the home page returns 200.
  • Spaces: the app starts and seeds its data. The Playwright suite passes 5/5 (run with dotnet run, because dotnet test doesn't support Microsoft.Testing.Platform on the .NET 10 SDK).

…agement 2.0.0-preview.3

Migrate Storage, AccountLockout and Spaces to the new storage registration APIs (AddStorage + AddConfigurationStorage/AddOperationalStorage, IStorageInstanceSchema, SchemaId.OidcIdentityProvider). Lengthen the Spaces demo password to meet the new 15-character minimum.
Store configuration and operational data in separate named storage instances and migrate each one separately.
… sample

Replace the copied OIDC provider schema with DefaultOidcProviderSchema, and extend BuiltInSchemas.UserProfile with the username attribute instead of redefining email. The built-in email is required and unique, so seeded users get an email and external users without one get a per-user placeholder.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant