Skip to content

fix(serialization): clarify type trust configuration - #10424

Merged
ReubenBond merged 2 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-typeconverter-trust-docs
Aug 10, 2026
Merged

ReubenBond merged 2 commits into
dotnet:mainfrom
ReubenBond:reubenbond-fix-typeconverter-trust-docs

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

Orleans 10.2 intentionally requires affirmative trust for every component of a formatted type name, but the migration path for JSON-serialized abstract application types was not clearly documented or covered by the reporter's exact scenario.

This change adds focused IReadOnlyList<TAbstract> coverage for the fail-closed default and every supported trust route, including typed and string allow-list configuration, assembly trust, custom filters, and the broad opt-out. It also updates diagnostics and public API documentation to point to the typed helpers, explain filter precedence, distinguish serializer support from type authorization, and warn about the security implications of allowing all resolvable types.

The fail-closed default is preserved. Narrow type or assembly trust remains the recommended configuration.

Fixes: #10239

Microsoft Reviewers: Open in CodeFlow

ReubenBond and others added 2 commits August 10, 2026 14:24
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@ReubenBond
ReubenBond merged commit d6711ba into dotnet:main Aug 10, 2026
72 checks passed
@ReubenBond
ReubenBond deleted the reubenbond-fix-typeconverter-trust-docs branch August 10, 2026 22:45
This was referenced Aug 28, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Regression (10.1 to 10.2): TypeConverter rejects type-name encoding of IReadOnlyList<TAbstract> for JSON-serialized types

1 participant