AntiforgeryApplicationBuilderExtensions.UseAntiforgery Method
Definition
Important
Some information relates to prerelease product that may be substantially modified before it’s released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Adds the anti-forgery middleware to the pipeline.
public static Microsoft.AspNetCore.Builder.IApplicationBuilder UseAntiforgery(this Microsoft.AspNetCore.Builder.IApplicationBuilder builder);
static member UseAntiforgery : Microsoft.AspNetCore.Builder.IApplicationBuilder -> Microsoft.AspNetCore.Builder.IApplicationBuilder
<Extension()>
Public Function UseAntiforgery (builder As IApplicationBuilder) As IApplicationBuilder
Parameters
- builder
- IApplicationBuilder
The IApplicationBuilder.
Returns
The app builder.
Remarks
The middleware validates anti-forgery tokens only for HTTP POST, PUT, and PATCH requests. Requests using other HTTP methods are skipped.
If you need validation for other HTTP methods (for example, DELETE), resolve IAntiforgery and call ValidateRequestAsync(HttpContext) or IsRequestValidAsync(HttpContext) in your handler.
When using HTTP method override middleware configured to read the method from a form field before this middleware, an incoming POST request can be overridden to another method. Anti-forgery validation still runs when the effective method is POST, PUT, or PATCH, but does not run automatically when the override changes the request to a different method outside that set (for example, DELETE).