Repository navigation
[11.0 P6] Blazor Preview 6 coverage #37322
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 19 commits
3385a02
ad5066e
06572b4
0709fa6
3f0aa0d
9da4ca3
87a326a
5716816
f5aec5b
6c107c8
559bda5
fc74348
813cd55
8515716
ade5f55
ff16f4f
8181f9a
e93e34e
2871d6f
cd5340e
0b22693
e15f308
f8d9161
6056a9e
71c2b83
c6bd135
2b72e4a
0cb5bb0
64b7044
a48d605
7c5615b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -289,8 +289,29 @@ There's no need to call <xref:Microsoft.AspNetCore.Components.ComponentBase.Stat | |
|
|
||
| Antiforgery services are automatically added to Blazor apps when <xref:Microsoft.Extensions.DependencyInjection.RazorComponentsServiceCollectionExtensions.AddRazorComponents%2A> is called in the `Program` file. | ||
|
|
||
| :::moniker-end | ||
|
|
||
| :::moniker range=">= aspnetcore-11.0" | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Not sure what kind of info we need to put here, but maybe extend a bit with usage? :::moniker range=">= aspnetcore-11.0" Blazor apps are protected against Cross-Site Request Forgery (CSRF/XSRF) by two complementary mechanisms. Automatic header-based CSRF protection middleware Automatic CSRF protection middleware is enabled by default in apps built with Token-based antiforgery Token-based antiforgery services are added to the app when xref:Microsoft.Extensions.DependencyInjection.RazorComponentsServiceCollectionExtensions.AddRazorComponents%2A is called in the How the two mechanisms interact Adding token-based antiforgery doesn't replace the automatic header-based middleware. When an app calls xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A, both defense mechanisms run for a form post: the header-based CSRF protection middleware runs first and records its verdict, then Antiforgery Middleware performs token-based validation. The token-based result is authoritative and overrides the earlier header-based verdict. To explicitly add Antiforgery Middleware, call xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A after the call to xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A. If there are calls to xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A and xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseEndpoints%2A, the call to xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A must go between them. A call to xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A must be placed after calls to xref:Microsoft.AspNetCore.Builder.AuthAppBuilderExtensions.UseAuthentication%2A and xref:Microsoft.AspNetCore.Builder.AuthorizationAppBuilderExtensions.UseAuthorization%2A. Disable the automatic CSRF protection middleware To disable the automatic header-based CSRF protection middleware, set the {
"DisableCsrfProtection": true
}The setting can be supplied by any configuration source, including an environment variable ( Warning Disabling the automatic CSRF protection middleware removes the default header-based ( For more information, see xref:security/csrf-protection. Important The following guidance on the xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryToken component and the xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryStateProvider service only apply to an app that explicitly adopts token-based Antiforgery Middleware by calling xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A in its request processing pipeline. :::moniker-end |
||
|
|
||
| Automatic Cross-Site Request Forgery (CSRF) Protection Middleware is enabled by default in apps built with `WebApplication.CreateBuilder`. The middleware inspects the `Sec-Fetch-Site` and `Origin` headers on unsafe HTTP methods and records a validation verdict on the request. Blazor server-side rendering (SSR) form posts enforce that verdict and return `400 Bad Request` for cross-origin form posts that aren't trusted. | ||
|
|
||
| If the app explicitly adds Antiforgery Middleware by calling <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in its request processing pipeline in the `Program` file, <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> is called after the call to <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A>. If there are calls to <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A> and <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseEndpoints%2A>, the call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> must go between them. A call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> must be placed after calls to <xref:Microsoft.AspNetCore.Builder.AuthAppBuilderExtensions.UseAuthentication%2A> and <xref:Microsoft.AspNetCore.Builder.AuthorizationAppBuilderExtensions.UseAuthorization%2A>. | ||
|
|
||
| For more information, see <xref:security/csrf-protection>. | ||
|
|
||
| > [!IMPORTANT] | ||
| > The following guidance on the <xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryToken> component and the <xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryStateProvider> service only apply to an app that explicitly adopts token-based Antiforgery Middleware by calling <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in its request processing pipeline. | ||
|
|
||
| :::moniker-end | ||
|
|
||
| :::moniker range=">= aspnetcore-8.0 < aspnetcore-11.0" | ||
|
|
||
| The app uses Antiforgery Middleware by calling <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in its request processing pipeline in the `Program` file. <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> is called after the call to <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A>. If there are calls to <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseRouting%2A> and <xref:Microsoft.AspNetCore.Builder.EndpointRoutingApplicationBuilderExtensions.UseEndpoints%2A>, the call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> must go between them. A call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> must be placed after calls to <xref:Microsoft.AspNetCore.Builder.AuthAppBuilderExtensions.UseAuthentication%2A> and <xref:Microsoft.AspNetCore.Builder.AuthorizationAppBuilderExtensions.UseAuthorization%2A>. | ||
|
|
||
| :::moniker-end | ||
|
|
||
| :::moniker range=">= aspnetcore-8.0" | ||
|
|
||
| The <xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryToken> component renders an antiforgery token as a hidden field, and the `[RequireAntiforgeryToken]` attribute enables antiforgery protection. If an antiforgery check fails, a [`400 - Bad Request`](https://developer.mozilla.org/docs/Web/HTTP/Status/400) response is thrown and the form isn't processed. | ||
|
|
||
| For forms based on <xref:Microsoft.AspNetCore.Components.Forms.EditForm>, the <xref:Microsoft.AspNetCore.Components.Forms.AntiforgeryToken> component and `[RequireAntiforgeryToken]` attribute are automatically added to provide antiforgery protection. | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.