Skip to content

Conversation

@hakenr
Copy link
Member

@hakenr hakenr commented Nov 5, 2024

The sample code only demonstrates how to render different content for authorized and unauthorized users. We shouldn't mislead users by naming the button click handler SecureMethod or suggesting it's secure in the description below the sample.

Even in server-side Blazor, the method could still be called from other places (either explicitly or through some attack technique), and it doesn't provide any security protection on its own.


Internal previews

📄 File 🔗 Preview link
aspnetcore/blazor/security/index.md aspnetcore/blazor/security/index

@hakenr hakenr requested a review from guardrex as a code owner November 5, 2024 23:46
Copy link
Collaborator

@guardrex guardrex left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Idk if this was them or 🦖 ... it's been here for several years. Thanks for the improvements. The primary updates are ...

  • We usually use contractions.
  • Location terms "preceding" and "following" are favored over "above" and "below."

@guardrex guardrex merged commit a72cd19 into dotnet:main Nov 6, 2024
3 checks passed
@hakenr hakenr deleted the patch-36 branch November 6, 2024 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants