Repository navigation
Conversation
guardrex
requested changes
Oct 8, 2026
guardrex
left a comment
Collaborator
There was a problem hiding this comment.
Let's start with ...
- The merge conflict fix ... 💀 for
authorandms.authorin metadata. - The small lowercase change for Line 430.
- The following update for Line 439, which drops out the text about antiforgery middleware pipeline call in the BWA project template for .NET 11 or later.
- Note that the repo won't be using named anchors any longer. Link to sections using the section
idvalue, which is derived from the section title. In this case, it will be#antiforgery-with-minimal-apis. You're welcome to 💀 named anchors everywhere you see them and update links to use the section headerids. It's not a critical change, but we'll be doing it whenever we can until all of the named anchors on the repo are gone.
Replace Lines 438 and 439 with ...
:::moniker-end
:::moniker range=">= aspnetcore-11.0"
> [!NOTE]
> Registering the services doesn't add the Antiforgery middleware to the request processing pipeline. Calling `AddRazorComponents` or `AddAntiforgery` only registers the antiforgery services in DI; it doesn't add the middleware. Blazor and Minimal APIs require an explicit call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in `Program.cs` to add the middleware to the request processing pipeline. MVC and Razor Pages validate tokens with built-in filters and don't require the middleware. For more information, see <xref:blazor/security/index#antiforgery-support> and [Antiforgery with Minimal APIs](#antiforgery-with-minimal-apis).
:::moniker-end
:::moniker range=">= aspnetcore-8.0 < aspnetcore-11.0"
> [!NOTE]
> Registering the services doesn't add the Antiforgery middleware to the request processing pipeline. Calling `AddRazorComponents` or `AddAntiforgery` only registers the antiforgery services in DI; it doesn't add the middleware. Blazor and Minimal APIs require an explicit call to <xref:Microsoft.AspNetCore.Builder.AntiforgeryApplicationBuilderExtensions.UseAntiforgery%2A> in `Program.cs` to add the middleware to the request processing pipeline (present by default in the Blazor Web App project template). MVC and Razor Pages validate tokens with built-in filters and don't require the middleware. For more information, see <xref:blazor/security/index#antiforgery-support> and [Antiforgery with Minimal APIs](#antiforgery-with-minimal-apis).
:::moniker-end
:::moniker range=">= aspnetcore-8.0"
Contributor
Author
|
Thanks @guardrex! Updated to lowercase dependency injection across all occurrences. |
SkyDevLab
force-pushed
the
docs/36185-antiforgery-registration-clarification
branch
from
October 8, 2026 17:39
bb48743 to
67ee27c
Compare
Contributor
Author
|
Thank you @guardrex! I have updated the branch with the requested versioning for .NET 11 and .NET 8-10, removed the named anchor in favor of |
Collaborator
|
Thanks! I'll pick back up with reviews tomorrow morning. I'm heading OOF for the day. |
guardrex
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #36185
Summary of Changes
AddAntiforgery(xref:Microsoft.Extensions.DependencyInjection.AntiforgeryServiceCollectionExtensions.AddAntiforgery%2A) to the list of APIs that register antiforgery services in DI across the article's version monikers.AddRazorComponentsorAddAntiforgery) does not automatically add the Antiforgery middleware to the pipeline, and thatapp.UseAntiforgery()must be called explicitly for Blazor and Minimal APIs.Internal previews
Build report