Skip to content

[release/11.0-rc1] Extract IsAuthenticated helper method - #68658

Merged
wtgodbe merged 3 commits into
release/11.0-rc1from
copilot/backport-68645-to-release-110-rc1
Aug 21, 2026
Merged

[release/11.0-rc1] Extract IsAuthenticated helper method#68658
wtgodbe merged 3 commits into
release/11.0-rc1from
copilot/backport-68645-to-release-110-rc1

Conversation

Copilot AI commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Backporting #68645 to release/11.0-rc1

Youssef1313 and others added 3 commits August 20, 2026 04:17
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
@Youssef1313 Youssef1313 changed the title Backporting PR 68645 to release 11.0 rc1 [release/11.0-rc1] Extract IsAuthenticated helper method Aug 20, 2026
@Youssef1313
Youssef1313 marked this pull request as ready for review August 20, 2026 04:41
Copilot AI lite review requested due to automatic review settings August 20, 2026 04:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This backport extracts a shared SecurityHelper.IsAuthenticated(ClaimsPrincipal?) helper that matches DenyAnonymousAuthorizationRequirement’s aggregate authentication semantics (any authenticated identity, not just the primary identity), and adopts it in multiple call sites that previously checked only User.Identity.

Changes:

  • Add SecurityHelper.IsAuthenticated helper to centralize authenticated-principal semantics.
  • Update Authorization, Output Caching, and Blazor Server revalidation logic to use the helper (ensuring non-primary authenticated identities are treated as authenticated).
  • Add/extend unit tests to cover the helper and the updated Output Caching behavior.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/Shared/test/Shared.Tests/SecurityHelperTests.cs Adds unit tests for the new SecurityHelper.IsAuthenticated helper, including non-primary identity behavior.
src/Shared/SecurityHelper/SecurityHelper.cs Introduces the IsAuthenticated(ClaimsPrincipal?) helper with authorization-matching semantics.
src/Security/Authorization/Core/src/Microsoft.AspNetCore.Authorization.csproj Links the shared SecurityHelper source into the Authorization assembly.
src/Security/Authorization/Core/src/DenyAnonymousAuthorizationRequirement.cs Replaces inline principal-authenticated logic with SecurityHelper.IsAuthenticated.
src/Middleware/OutputCaching/test/OutputCachePolicyProviderTests.cs Adds tests ensuring output caching is disallowed for principals authenticated via any identity.
src/Middleware/OutputCaching/src/Policies/DefaultPolicy.cs Uses SecurityHelper.IsAuthenticated when deciding cache eligibility/storage for authenticated users.
src/Middleware/OutputCaching/src/Microsoft.AspNetCore.OutputCaching.csproj Links the shared SecurityHelper source into the OutputCaching assembly.
src/Components/Server/src/Microsoft.AspNetCore.Components.Server.csproj Links the shared SecurityHelper source into the Components Server assembly.
src/Components/Server/src/Circuits/RevalidatingServerAuthenticationStateProvider.cs Uses SecurityHelper.IsAuthenticated to determine whether to enter the revalidation loop.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@wtgodbe
wtgodbe merged commit 4c1e2ed into release/11.0-rc1 Aug 21, 2026
29 checks passed
@wtgodbe
wtgodbe deleted the copilot/backport-68645-to-release-110-rc1 branch August 21, 2026 16:04
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 11.0-rc1 milestone Aug 21, 2026
wtgodbe added a commit that referenced this pull request Aug 22, 2026
* [SignalR] Reject duplicate SignalR upload stream IDs (#68525) (#68638)

* Reject duplicate SignalR upload stream IDs



* Simplify upload stream ownership cleanup



* Avoid upload stream ownership allocations



* Simplify upload stream registration ownership



* Defer upload stream reader creation





* Dispose cancellation source after binding failure





* Reuse upload stream test helper





---------

Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2

* Honor all sign-in confirmation requirements after registration (#68631) (#68655)

Co-authored-by: Brennan <brecon@microsoft.com>

* Preserve BadHttpRequestException status codes (#68632) (#68649)

* Preserve BadHttpRequestException status codes



* Preserve exception handler 404 safeguard



---------

Co-authored-by: Stephen Halter <halter73@gmail.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

* SignInManager: return SignInResult.Failed for expired passkey session challenge (#67539) (#68654)

Co-authored-by: Grant Totinov <granttotinov604@gmail.com>

* Don't apply the CSRF verdict to remote authentication callbacks (#68669)

* Don't apply the CSRF verdict to remote authentication callbacks

A remote provider's callback (OIDC response_mode=form_post, WS-Federation)
is a cross-site form POST by protocol design, so the auto-injected CSRF
protection records an invalid IAntiforgeryValidationFeature verdict for it.
The handler then throws while reading its own callback body, before any of
its events can run, so apps have no way to opt out.

Suppress the verdict while a remote handler owns the request, and restore it
if the handler declines so the rest of the pipeline still sees it.

Fixes #68666

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd

* test both antiforgery & csrf

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd

* Use model display names in Blazor input parsing errors (#68667) (#68688)

* Use display attributes in input parsing errors

* Address test coverage feedback from review.

* Apply dedup cleanup from feedback.

Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>

* [release/11.0-rc1] Extract IsAuthenticated helper method (#68658)

* Extract IsAuthenticated helper method

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

* Reorder using

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

* Use SecurityHelper for authentication revalidation

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>

---------

Co-authored-by: Youssef1313 <youssefvictor00@gmail.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com>

* Fix  InitialItemIndex viewport underfill for small items in big container or on window resize (#67936) (#68689)

Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>

* fix nullable<union> for openapi gen (#68665)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Javier Calvarro Nelson <jacalvar@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Brennan <brecon@microsoft.com>
Co-authored-by: Stephen Halter <halter73@gmail.com>
Co-authored-by: Grant Totinov <granttotinov604@gmail.com>
Co-authored-by: Korolev Dmitry <dmkorolev@microsoft.com>
Co-authored-by: Ilona Tomkowicz <32700855+ilonatommy@users.noreply.github.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Youssef1313 <youssefvictor00@gmail.com>
Co-authored-by: Youssef1313 <31348972+Youssef1313@users.noreply.github.com>
Co-authored-by: Milos Kotlar <kotlarmilos@gmail.com>
Co-authored-by: William Godbe <wigodbe@microsoft.com>
Copilot-Session: 82e97f5a-a052-4dbe-9cf1-b62f45cf7ee2
Copilot-Session: cb987098-3301-465b-9a3d-2e63aabf43bd
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants