Skip to content

Doc: Clarify antiforgery service registration and middleware setup (#36185) - #37797

Merged
guardrex merged 3 commits into
dotnet:mainfrom
SkyDevLab:docs/36185-antiforgery-registration-clarification
Oct 9, 2026
Merged

guardrex merged 3 commits into
dotnet:mainfrom
SkyDevLab:docs/36185-antiforgery-registration-clarification

Conversation

@SkyDevLab

@SkyDevLab SkyDevLab commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #36185

Summary of Changes

  • Corrected phrasing where antiforgery was described as "middleware added to the Dependency injection container" to "services are registered in the Dependency injection container".
  • Added AddAntiforgery (xref:Microsoft.Extensions.DependencyInjection.AntiforgeryServiceCollectionExtensions.AddAntiforgery%2A) to the list of APIs that register antiforgery services in DI across the article's version monikers.
  • Clarified the note in .NET 8+ explaining that registering services (such as with AddRazorComponents or AddAntiforgery) does not automatically add the Antiforgery middleware to the pipeline, and that app.UseAntiforgery() must be called explicitly for Blazor and Minimal APIs.

Internal previews

File Preview link
aspnetcore/security/anti-request-forgery.md Learn preview

Build report

@guardrex guardrex self-assigned this Oct 8, 2026

@guardrex guardrex left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Let's start with ...

  • The merge conflict fix ... 💀 for author and ms.author in metadata.
  • The small lowercase change for Line 430.
  • The following update for Line 439, which drops out the text about antiforgery middleware pipeline call in the BWA project template for .NET 11 or later.
  • Note that the repo won't be using named anchors any longer. Link to sections using the section id value, which is derived from the section title. In this case, it will be #antiforgery-with-minimal-apis. You're welcome to 💀 named anchors everywhere you see them and update links to use the section header ids. It's not a critical change, but we'll be doing it whenever we can until all of the named anchors on the repo are gone.

Replace Lines 438 and 439 with ...

:::moniker-end

:::moniker range=">= aspnetcore-11.0"

> [!NOTE]
> Registering the services doesn't add the Antiforgery middleware to the request processing pipeline. Calling `AddRazorComponents` or `AddAntiforgery` only registers the antiforgery services in DI; it doesn't add the middleware. Blazor and Minimal APIs require an explicit call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in `Program.cs` to add the middleware to the request processing pipeline. MVC and Razor Pages validate tokens with built-in filters and don't require the middleware. For more information, see <xref:blazor/security/index#antiforgery-support> and [Antiforgery with Minimal APIs](#antiforgery-with-minimal-apis).

:::moniker-end

:::moniker range=">= aspnetcore-8.0 < aspnetcore-11.0"

> [!NOTE]
> Registering the services doesn't add the Antiforgery middleware to the request processing pipeline. Calling `AddRazorComponents` or `AddAntiforgery` only registers the antiforgery services in DI; it doesn't add the middleware. Blazor and Minimal APIs require an explicit call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in `Program.cs` to add the middleware to the request processing pipeline (present by default in the Blazor Web App project template). MVC and Razor Pages validate tokens with built-in filters and don't require the middleware. For more information, see <xref:blazor/security/index#antiforgery-support> and [Antiforgery with Minimal APIs](#antiforgery-with-minimal-apis).

:::moniker-end

:::moniker range=">= aspnetcore-8.0"

Comment thread aspnetcore/security/anti-request-forgery.md Outdated
@SkyDevLab

Copy link
Copy Markdown
Contributor Author

Thanks @guardrex! Updated to lowercase dependency injection across all occurrences.

@SkyDevLab
SkyDevLab force-pushed the docs/36185-antiforgery-registration-clarification branch from bb48743 to 67ee27c Compare October 8, 2026 17:39
@SkyDevLab

Copy link
Copy Markdown
Contributor Author

Thank you @guardrex! I have updated the branch with the requested versioning for .NET 11 and .NET 8-10, removed the named anchor in favor of #antiforgery-with-minimal-apis, and rebased onto main to clear any merge conflicts.

@guardrex

guardrex commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Thanks! I'll pick back up with reviews tomorrow morning. I'm heading OOF for the day.

@guardrex
guardrex merged commit 3bd0259 into dotnet:main Oct 9, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Clarify antiforgery service registration and middleware setup

2 participants