Skip to content

Enabling CORS in ASP.NET Core: migrate the sample here on .NET 10, with tests - #2282

Open
vladimir-pecanac-main wants to merge 1 commit into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/3565-enabling-cors-in-asp-net-core
Open

vladimir-pecanac-main wants to merge 1 commit into
CodeMazeBlog:mainfrom
vladimir-pecanac-main:seo/3565-enabling-cors-in-asp-net-core

Conversation

@vladimir-pecanac-main

Copy link
Copy Markdown
Collaborator

Sample for the article "Enabling CORS in ASP.NET Core Web API" (https://code-maze.com/enabling-cors-in-asp-net-core/). The code moves here from the standalone cors-aspnetcore-example repository. Only the new folder aspnetcore-webapi/EnablingCorsInAspNetCore is added; nothing else in the repository changes.

Changes

  • One solution, EnablingCorsInAspNetCore.sln, with three projects side by side: Api (was CorsServerApp), Client (was CorsClientApp) and Tests (new). Same shape as aspnetcore-webapi/FixCorsProtocolErrorWithAnyOriginAndAllowCredentials.
  • Every project targets net10.0 (was net8.0).
  • app.UseCors() now runs before app.UseAuthentication() and app.UseAuthorization(). With authorization first, a request it refuses returns 401 without Access-Control-Allow-Origin, so the browser reports a CORS error instead of the real status.
  • Swashbuckle.AspNetCore and the Swagger calls are removed. Microsoft.AspNetCore.OpenApi moves to 10.0.12 with AddOpenApi() and MapOpenApi(), and .WithOpenApi() is gone from the minimal endpoint (deprecated on .NET 10, ASPDEPR002). AddEndpointsApiExplorer() went with Swashbuckle.
  • One WeatherForecast record serves both the controller and the minimal API endpoint. The old WeatherForecast class, a second type with the same name, is deleted.
  • The GlobalUsings.cs files are replaced by explicit using directives in the files that need them (Microsoft.Net.Http.Headers in Program.cs, Microsoft.AspNetCore.Cors in the controller, Microsoft.AspNetCore.Components.WebAssembly.Hosting in the client's Program.cs).
  • The client keeps only what the article shows: the FetchData page, a minimal layout and Program.cs. PreferExactMatches is removed from the router (obsolete on .NET 10, CS0618, no effect), the forecasts field is nullable, and the bootstrap and open-iconic assets are gone.
  • "dotnetRunMessages" in both launchSettings.json files is now the boolean true. The old string value makes the .NET 10 SDK skip the whole launch profile, so the API started on http://localhost:5000 in Production instead of https://localhost:5001.
  • New xunit integration tests (WebApplicationFactory): an allowed origin gets Access-Control-Allow-Origin on the controller action and the minimal endpoint, a refused origin gets no CORS header, the preflight answers 204 with Access-Control-Allow-Methods: GET, and the second policy exposes X-Pagination.

Package versions, re-queried on NuGet on 2026-10-11 (newest listed stable of each id): Microsoft.AspNetCore.OpenApi 10.0.12, Microsoft.AspNetCore.Components.WebAssembly 10.0.12, Microsoft.AspNetCore.Components.WebAssembly.DevServer 10.0.12, Microsoft.AspNetCore.Mvc.Testing 10.0.12, Microsoft.NET.Test.Sdk 18.10.1, xunit 2.9.3, xunit.runner.visualstudio 4.0.1, coverlet.collector 10.1.0.

Local run (SDK 10.0.302, runtime 10.0.10, Windows 10.0.19045): dotnet build -c Release 0 warnings, 0 errors; dotnet test 7 passed, 0 failed; dotnet list package --vulnerable --include-transitive reports no vulnerable packages in any project. dotnet run on the Api answered an Origin: https://localhost:5011 request with Access-Control-Allow-Origin: https://localhost:5011 and a refused origin with no CORS header.

… on .NET 10

Moves the sample from the standalone cors-aspnetcore-example repository into
aspnetcore-webapi/EnablingCorsInAspNetCore as one solution with Api, Client
and Tests projects, all on net10.0.

- UseCors now runs before UseAuthentication and UseAuthorization
- Swashbuckle removed; Microsoft.AspNetCore.OpenApi 10.0.12 with AddOpenApi
  and MapOpenApi; WithOpenApi removed (ASPDEPR002)
- one WeatherForecast record shared by the controller and the minimal API
  endpoint (the duplicate class is gone)
- client reduced to the FetchData page, its layout and Program.cs;
  PreferExactMatches removed (obsolete, no effect); nullable forecasts field
- launchSettings dotnetRunMessages is a boolean (a string makes the .NET 10
  SDK skip the profile)
- new xunit integration tests for the allowed origin, a refused origin,
  the preflight and the exposed X-Pagination header
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant