Skip to content

Align passkey guidance with the .NET 11 Blazor template - #37559

Merged
rolandVi merged 4 commits into
dotnet:mainfrom
rolandVi:fix-passkey-docs-template-drift-clean
Sep 1, 2026
Merged

rolandVi merged 4 commits into
dotnet:mainfrom
rolandVi:fix-passkey-docs-template-drift-clean

Conversation

@rolandVi

@rolandVi rolandVi commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Documents dotnet/aspnetcore#65343, dotnet/aspnetcore#65752, dotnet/aspnetcore#67539 and dotnet/aspnetcore#67589.

The passkey articles had drifted from the Blazor Web App template, so a .NET 11 reader following them copies the .NET 10 flow.

Versioned JavaScript

The .NET 10 samples stay as they are. The .NET 11 versions drop the headers argument, which the template stopped sending in dotnet/aspnetcore#67589 when it moved to the fetch-metadata CSRF middleware. Those endpoints are still validated, just by the middleware instead of a token header, so nothing loses protection here.

The rest

Two things I left out on purpose: the creation options URL moving to /Account/Manage/, and PasskeyOperation gaining Reauthenticate. Both are .NET 12 only, and there's no aspnetcore-12.0 moniker yet, so gated content would render for nobody.

One fix outside the drift: the "locate the Blazor script tag" snippet was missing @Assets[...], which is wrong in every version.

Checked every sample against release/10.0, release/11.0 and main.


Internal previews

File Preview link
aspnetcore/security/authentication/passkeys/blazor.md Learn preview
aspnetcore/security/authentication/passkeys/index.md Learn preview

Build report

@guardrex
guardrex self-requested a review August 31, 2026 15:58
@guardrex guardrex self-assigned this Aug 31, 2026
@guardrex

Copy link
Copy Markdown
Collaborator

Thanks, @rolandVi ... Let me try and get back to you tomorrow (Tuesday). I'm ⛏️😅 at the moment on a doc overhaul.

@guardrex

guardrex commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

Fixes #37564

@rolandVi
rolandVi requested a review from rokonec September 1, 2026 09:38

@guardrex guardrex left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for taking care of these updates, @rolandVi! I'm slammed with main doc set overhauls, and you saved me a lot of time submitting this PR.

  • There are two NITs inline ... adding a line to get the spacing right in the rendered list and a comma splice.
  • For each >=11.0/<11.0 versioned block pair, rotate the >=11.0 blocks to the top of those pairs ... place the >=11.0 content first.
  • Finally, run Copilot (Lite) on the PR to see if it turns up anything interesting to adjust.

Comment thread aspnetcore/security/authentication/passkeys/index.md Outdated
Comment thread aspnetcore/security/authentication/passkeys/blazor.md
Co-authored-by: Luke Latham <1622880+guardrex@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the passkey documentation to better match the .NET 11 Blazor Web App template behavior, primarily by versioning JavaScript snippets and correcting/refreshing related guidance.

Changes:

  • Adds monikered JavaScript snippets to differentiate .NET 10 vs .NET 11 flows (notably removing the headers argument for .NET 11).
  • Updates guidance around PasskeySignInAsync behavior and refreshes template/source links.
  • Fixes Blazor guidance for referencing the correct script paths via @Assets[...] and expands the model-class list for .NET 11.
File summaries
File Description
aspnetcore/security/authentication/passkeys/index.md Adds .NET 10/11 monikered JS guidance and updates passkey sign-in behavior documentation.
aspnetcore/security/authentication/passkeys/blazor.md Aligns Blazor template instructions (scripts/links/models) and updates metadata.
Review details

Suppressed comments (4)

aspnetcore/security/authentication/passkeys/index.md:604

  • This Step 6 snippet is described as serializing the credential for submission, but it currently just re-fetches options and calls navigator.credentials.create() again (same as Step 2/4). It should serialize the created credential (for example via JSON.stringify) so the reader can submit the JSON to the server.

This issue also appears on line 621 of the same file.

async function createCredential(headers, signal) {
  // Step 6: The credential is returned from navigator.credentials.create()
  // and is serialized to JSON for submission to the server
  const optionsResponse = 
    await fetchWithErrorHandling('/Account/PasskeyCreationOptions', 

aspnetcore/security/authentication/passkeys/index.md:625

  • This Step 6 snippet is described as serializing the credential for submission, but it currently just re-fetches options and calls navigator.credentials.create() again (same as Step 2/4). It should serialize the created credential (for example via JSON.stringify) so the reader can submit the JSON to the server.
async function createCredential(signal) {
  // Step 6: The credential is returned from navigator.credentials.create()
  // and is serialized to JSON for submission to the server
  const optionsResponse = 
    await fetchWithErrorHandling('/Account/PasskeyCreationOptions', 

aspnetcore/security/authentication/passkeys/index.md:836

  • This Step 6 snippet is described as serializing the assertion for submission, but it currently just re-fetches options and calls navigator.credentials.get() again (same as Step 2/4). It should serialize the returned assertion so the reader can submit the JSON to the server.

This issue also appears on line 853 of the same file.

async function requestCredential(email, mediation, headers, signal) {
  // Step 6: The assertion is returned from navigator.credentials.get()
  // and is serialized to JSON for submission to the server
  const optionsResponse = 
    await fetchWithErrorHandling(`/Account/PasskeyRequestOptions?username=${email}`, 

aspnetcore/security/authentication/passkeys/index.md:857

  • This Step 6 snippet is described as serializing the assertion for submission, but it currently just re-fetches options and calls navigator.credentials.get() again (same as Step 2/4). It should serialize the returned assertion so the reader can submit the JSON to the server.
async function requestCredential(email, mediation, signal) {
  // Step 6: The assertion is returned from navigator.credentials.get()
  // and is serialized to JSON for submission to the server
  const optionsResponse = 
    await fetchWithErrorHandling(`/Account/PasskeyRequestOptions?username=${email}`, 
  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread aspnetcore/security/authentication/passkeys/index.md Outdated
Comment thread aspnetcore/security/authentication/passkeys/blazor.md Outdated
Comment thread aspnetcore/security/authentication/passkeys/index.md Outdated
@rolandVi
rolandVi removed the request for review from rokonec September 1, 2026 11:11
@rolandVi
rolandVi requested a review from guardrex September 1, 2026 11:27

@guardrex guardrex left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again, thank you so much for submitting this PR. I'll approve, and I presume that you want to wait to merge it until @rokonec looks at it and provides feedback.

UPDATE: Oh! I see that you removed that review request. In that case, are you ready to merge it now?

@rolandVi

rolandVi commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Again, thank you so much for submitting this PR. I'll approve, and I presume that you want to wait to merge it until @rokonec looks at it and provides feedback.

UPDATE: Oh! I see that you removed that review request. In that case, are you ready to merge it now?

Yes, we can merge

@rolandVi
rolandVi merged commit ea99ee6 into dotnet:main Sep 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants