Language

AntiforgeryApplicationBuilderExtensions.UseAntiforgery Method

Definition

Adds the anti-forgery middleware to the pipeline.

public static Microsoft.AspNetCore.Builder.IApplicationBuilder UseAntiforgery(this Microsoft.AspNetCore.Builder.IApplicationBuilder builder);
static member UseAntiforgery : Microsoft.AspNetCore.Builder.IApplicationBuilder -> Microsoft.AspNetCore.Builder.IApplicationBuilder
<Extension()>
Public Function UseAntiforgery (builder As IApplicationBuilder) As IApplicationBuilder

Parameters

Returns

The app builder.

Remarks

The middleware validates anti-forgery tokens only for HTTP POST, PUT, and PATCH requests. Requests using other HTTP methods are skipped.

If you need validation for other HTTP methods (for example, DELETE), resolve IAntiforgery and call ValidateRequestAsync(HttpContext) or IsRequestValidAsync(HttpContext) in your handler.

When using HTTP method override middleware configured to read the method from a form field before this middleware, an incoming POST request can be overridden to another method. Anti-forgery validation still runs when the effective method is POST, PUT, or PATCH, but does not run automatically when the override changes the request to a different method outside that set (for example, DELETE).

Applies to