dotnet / dotnet/AspNetCore.Docs

Needs more details.

Open
#33,353 2 comments 0 reactions 0 assignees View on GitHub
aspnet-core/svc re-Aditya security/subsvc Source - Docs.ms
Dominant language
C#
Stars
13.1k
Forks
24.6k
Avg merge
1d 3h
Merged PRs (30d)
97

Description

### Description

The example in this article creates confusion because of mixing custom policy provider and `IAuthrizationRequirementData`.
There's no explanation of how framework actually behaves.

It's not needed to inherit from `Authorize` attribute.
If attribute implements `IAuthrizationRequirementData`, either _active_ policy will be extended with the requirements `IAuthrizationRequirementData` yields, or new policy will be created dynamically.

See this example: https://github.com/voroninp/AuthorizationRequirementDataTest

### Page URL

https://learn.microsoft.com/en-us/aspnet/core/security/authorization/iard?view=aspnetcore-8.0

### Content source URL

https://github.com/dotnet/AspNetCore.Docs/blob/main/aspnetcore/security/authorization/iard.md

### Document ID

f6195feb-aade-5e5a-dc6d-6a6b9bb6038e

### Article author

@Rick-Anderson

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.