Update HTTP endpoint authorization handler
The default authorization handler for HTTP endpoints is now the AuthenticationBasedHttpEndpointAuthorizationHandler instead of the AllowAnonymousHttpEndpointAuthorizationHandler. The configuration was updated in HttpFeature.cs and the override in Program.cs was removed. This provides more security to HTTP endpoints by requiring authentication.
This commit is contained in:
parent
fac292a9e3
commit
2a5cf04207
|
|
@ -175,7 +175,6 @@ services
|
|||
.UseHttp(http =>
|
||||
{
|
||||
http.ConfigureHttpOptions = options => configuration.GetSection("Http").Bind(options);
|
||||
http.HttpEndpointAuthorizationHandler = sp => sp.GetRequiredService<AllowAnonymousHttpEndpointAuthorizationHandler>();
|
||||
})
|
||||
.UseEmail(email => email.ConfigureOptions = options => configuration.GetSection("Smtp").Bind(options))
|
||||
.UseAlterations(alterations =>
|
||||
|
|
|
|||
|
|
@ -53,7 +53,7 @@ public class HttpFeature : FeatureBase
|
|||
/// <summary>
|
||||
/// A delegate that is invoked when authorizing an inbound HTTP request.
|
||||
/// </summary>
|
||||
public Func<IServiceProvider, IHttpEndpointAuthorizationHandler> HttpEndpointAuthorizationHandler { get; set; } = sp => sp.GetRequiredService<AllowAnonymousHttpEndpointAuthorizationHandler>();
|
||||
public Func<IServiceProvider, IHttpEndpointAuthorizationHandler> HttpEndpointAuthorizationHandler { get; set; } = sp => sp.GetRequiredService<AuthenticationBasedHttpEndpointAuthorizationHandler>();
|
||||
|
||||
/// <summary>
|
||||
/// A delegate that is invoked when an HTTP workflow faults.
|
||||
|
|
|
|||
Loading…
Reference in a new issue