Repository navigation
Enabling CORS in ASP.NET Core: migrate the sample here on .NET 10, with tests - #2282
Open
vladimir-pecanac-main wants to merge 1 commit into
Conversation
… on .NET 10 Moves the sample from the standalone cors-aspnetcore-example repository into aspnetcore-webapi/EnablingCorsInAspNetCore as one solution with Api, Client and Tests projects, all on net10.0. - UseCors now runs before UseAuthentication and UseAuthorization - Swashbuckle removed; Microsoft.AspNetCore.OpenApi 10.0.12 with AddOpenApi and MapOpenApi; WithOpenApi removed (ASPDEPR002) - one WeatherForecast record shared by the controller and the minimal API endpoint (the duplicate class is gone) - client reduced to the FetchData page, its layout and Program.cs; PreferExactMatches removed (obsolete, no effect); nullable forecasts field - launchSettings dotnetRunMessages is a boolean (a string makes the .NET 10 SDK skip the profile) - new xunit integration tests for the allowed origin, a refused origin, the preflight and the exposed X-Pagination header
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Sample for the article "Enabling CORS in ASP.NET Core Web API" (https://code-maze.com/enabling-cors-in-asp-net-core/). The code moves here from the standalone cors-aspnetcore-example repository. Only the new folder
aspnetcore-webapi/EnablingCorsInAspNetCoreis added; nothing else in the repository changes.Changes
EnablingCorsInAspNetCore.sln, with three projects side by side:Api(was CorsServerApp),Client(was CorsClientApp) andTests(new). Same shape asaspnetcore-webapi/FixCorsProtocolErrorWithAnyOriginAndAllowCredentials.app.UseCors()now runs beforeapp.UseAuthentication()andapp.UseAuthorization(). With authorization first, a request it refuses returns 401 withoutAccess-Control-Allow-Origin, so the browser reports a CORS error instead of the real status.AddOpenApi()andMapOpenApi(), and.WithOpenApi()is gone from the minimal endpoint (deprecated on .NET 10, ASPDEPR002).AddEndpointsApiExplorer()went with Swashbuckle.WeatherForecastrecord serves both the controller and the minimal API endpoint. The oldWeatherForecastclass, a second type with the same name, is deleted.GlobalUsings.csfiles are replaced by explicitusingdirectives in the files that need them (Microsoft.Net.Http.Headersin Program.cs,Microsoft.AspNetCore.Corsin the controller,Microsoft.AspNetCore.Components.WebAssembly.Hostingin the client's Program.cs).PreferExactMatchesis removed from the router (obsolete on .NET 10, CS0618, no effect), theforecastsfield is nullable, and the bootstrap and open-iconic assets are gone."dotnetRunMessages"in both launchSettings.json files is now the booleantrue. The old string value makes the .NET 10 SDK skip the whole launch profile, so the API started on http://localhost:5000 in Production instead of https://localhost:5001.Access-Control-Allow-Originon the controller action and the minimal endpoint, a refused origin gets no CORS header, the preflight answers 204 withAccess-Control-Allow-Methods: GET, and the second policy exposesX-Pagination.Package versions, re-queried on NuGet on 2026-10-11 (newest listed stable of each id): Microsoft.AspNetCore.OpenApi 10.0.12, Microsoft.AspNetCore.Components.WebAssembly 10.0.12, Microsoft.AspNetCore.Components.WebAssembly.DevServer 10.0.12, Microsoft.AspNetCore.Mvc.Testing 10.0.12, Microsoft.NET.Test.Sdk 18.10.1, xunit 2.9.3, xunit.runner.visualstudio 4.0.1, coverlet.collector 10.1.0.
Local run (SDK 10.0.302, runtime 10.0.10, Windows 10.0.19045):
dotnet build -c Release0 warnings, 0 errors;dotnet test7 passed, 0 failed;dotnet list package --vulnerable --include-transitivereports no vulnerable packages in any project.dotnet runon the Api answered anOrigin: https://localhost:5011request withAccess-Control-Allow-Origin: https://localhost:5011and a refused origin with no CORS header.