Skip to content

Blazor Hybrid Security topic#25555

Merged
guardrex merged 6 commits into
mainfrom
guardrex/blazor-hybrid-security
Apr 13, 2022
Merged

Blazor Hybrid Security topic#25555
guardrex merged 6 commits into
mainfrom
guardrex/blazor-hybrid-security

Conversation

@guardrex
Copy link
Copy Markdown
Collaborator

@guardrex guardrex commented Apr 7, 2022

Addresses #25453
Addresses #24956
Fixes #25461

Internal Review Topic

  • The title, description, physical folder (URL), and UID reflect the general coverage. This will eventually be the overview of a node of security topics, and it will cover additional security scenarios as needed.
  • I commented out the "fixed-version WebView" piece until RC2. We'll leave the issue open until the RC2 update is made later. Let's review/update the commented-out text now so that I don't need to ping for a follow-up review at RC2.
  • The more general security guidance can close the issue that Safia opened AFAICT.
  • I'll leave it to you to call for additional reviewers as needed.
  • I'm OOF on Friday, but I'll 🛌💤 on it and merge Friday morning anyway if all of the reviews are in. If we're still awaiting reviews, I'll get it merged on or after Monday when all of the reviews are in.

🇺🇦

@guardrex guardrex mentioned this pull request Apr 7, 2022
25 tasks
@MackinnonBuck
Copy link
Copy Markdown
Member

@Eilon FYI

Comment thread aspnetcore/blazor/hybrid/security/index.md Outdated
Comment thread aspnetcore/blazor/hybrid/security/index.md Outdated
Comment thread aspnetcore/blazor/hybrid/security/index.md Outdated
Comment thread aspnetcore/blazor/hybrid/security/index.md Outdated
guardrex and others added 2 commits April 11, 2022 14:40
I'll make the `WebView` change locally for the next commit.

I'll circle around for that update everywhere on the new issue that I opened.

Co-authored-by: Mackinnon Buck <mackinnon.buck@gmail.com>
Copy link
Copy Markdown
Member

@MackinnonBuck MackinnonBuck left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good to me. Any other thoughts @dotnet/aspnet-blazor-eng?

@guardrex
Copy link
Copy Markdown
Collaborator Author

guardrex commented Apr 12, 2022

@MackinnonBuck ... Did you say we were withholding the commented-out bits for RC2? My understanding was that we go from RC1 to GA. If we can surface the commented-out bits with RC1, then I suggest I go ahead and surface the content now and hold this just until later today for publication. If there really is an RC2 (and we'll leave the commented-out bits in place), then I'll just wait on your final signal here to merge this.

Nevermind! I was just informed that RCs were added. I'm just waiting on you to give the final word on merging this. I'll un-comment the content we're holding at RC2. The issue won't close until then.

UPDATE (4/13): I'm going to go ahead and merge. Let me know if we need to do more here. I'll circle around and surface the comment-out text for RC2, and we'll keep the issue open until then.

@guardrex guardrex merged commit a06eeea into main Apr 13, 2022
@guardrex guardrex deleted the guardrex/blazor-hybrid-security branch April 13, 2022 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document security recommendations for remote resources in Blazor Hybrid apps

3 participants