## dotnet/aspnetcore — v11.0.0-preview.6.26359.118…v11.0.0-preview.7.26381.103

_206+ commits._

### Features
- **[release/11.0-preview7] Add OpenApiGenerationEnvironment property support for API description server document generation (#68040)** (a302455)
- **[release/11.0-preview7] Ignore From when serializing a JsonPatchDocument for add, remove, rep… (#67968)** (ebb1adb)
- **Add IEndpointMetadataProvider to UnauthorizedHttpResult (#65611)** (58c5632)
- **Support AuthorizationPolicy and IAuthorizationRequirementData metadata everywhere (#67765)** (face016)
- **Add .NET 10.0 support to aggregate site extension (#67810)** (27e5600)
- **feat: adds support for populating OpenAPI discriminator defaultMapping (#67493)** (e15a58c)
- **Enable tests for Validation changes** — Updated CI/CD pipeline configuration to automatically run Blazor end-to-end tests whenever code in the Validation module is modified, ensuring changes to that component are properly tested before merging. (8811a9e)
- **Add caching support to Blazor components** — Introduced CacheBoundary feature for Blazor that allows components to be cached across requests with configurable vary-by dimensions (query, route, headers, cookies, user, culture). Components can be marked as live-cached to maintain their own lifecycle while capturing parameters once, with support for both hybrid and memory-based cache stores. (d1866a2)
- **Add TLS channel binding token support** — Added a new `TryGetChannelBindingBytes` method to the TLS connection feature, allowing applications to access RFC 5929 TLS channel binding tokens for security purposes like protecting against authentication relay attacks. The feature is now available across HttpSys, IIS, and Kestrel servers with configurable authentication hardening levels. (1ae00e6)
- **feat: adds support for describing SSE in OpenAPI 3.2.0 (#67461)** (cf20285)
- **feat(OpenApi): surface document generation in TerminalLogger (#66922)** (44eeec3)
- **Add tests to cover all enum scenarios for OpenAPI (#67485)** (c9bdc09)
- **Add safety comment to Utf8HashLookup (#67477)** (360e42c)

### Fixes
- **Fix Virtualize scroll jump from native/JS anchoring double-compensation (#67934) (#67973)** (19fe163)
- **Fix QuickGrid virtualization viewport drift** — Fixed a bug where the viewport would drift when prepending items to a virtualized QuickGrid using Start-mode anchoring with async data providers. The fix ensures the viewport stays stable when new items are added to the top of the list. (06ed003)
- **Fix CollapseLeadingSlashes bypass via bare leading backslash (#67928)** (93148da)
- **Fix QuickGrid None-mode async-provider prepend viewport drift. (#67931)** (5c873ca)
- **Fix local WASM Components E2E 404 by applying gateway path base (#67903)** (35b67fe)
- **Fix nullability handling in OpenApi (#67661)** (8026f9f)
- **Fix ValidatableTypeInfo line endings (#67871)** (7b3625f)
- **Fix API for QuickGrid (#67733)** (0f1a256)
- **Fix API for CacheView (#67776)** (564927c)
- **Fix placeholder flash when appending to an End-anchored virtualized list (#67679)** (ef19e4d)
- **Fix array type validation generation** — Fixed the validation source generator to properly unwrap array types (like T[]) when extracting the underlying element type for validation. This enables correct validation of array properties and array parameters in API endpoints. (f82669a)
- **Strengthen Blazor passkey security** — Fixed CSRF protection for Blazor passkey registration and account management endpoints by properly validating antiforgery tokens and removing redundant token fields. The update ensures that passkey creation, passkey sign-in, and personal data download endpoints enforce antiforgery validation through the new middleware while cleaning up unused token markup across account management pages. (68dacc0)
- **Warn about non-public JSInvokable methods** — Added a code analyzer that detects when methods decorated with [JSInvokable] are not public, since they must be public to be callable from JavaScript. The analyzer includes an automatic code fix that makes the method public. (7a0af92)
- **Improved QuickGrid paginator accessibility** — Fixed keyboard navigation for QuickGrid's pagination controls by adding tabindex attributes to disabled pagination buttons, preventing them from receiving keyboard focus. The pagination links now always have valid href values and use tabindex="-1" to indicate when they're disabled. (4855e70)
- **Fix flaky QuickGrid type mismatch virtualized E2E test (#67677)** (81a85fc)
- **Fix Blazor nested validation test (#67680)** (0c3e825)
- **fix: tags ordering in OpenAPI generation (#65728)** (99ded8f)
- **Fix service parameter detection logic for minimal API validation filter (#67578)** (5cb9a24)
- **Fix RDG check for endpoint uniqueness (#67591)** (78b827c)
- **Fix OpenApiSchemaService to handle implementation different from Dictionary<,> for schema.Properties (#67384)** (45d843a)
- **[test-quarantine] Fix guardrails that let the workflow re-attempt rejected actions (#67620)** (f676999)
- **Fix array handling for JSON pointers when resolving OpenAPI schemas (#67573)** (db4dc2c)
- **Fix Virtualize AnchorMode=End re-engaging bottom after user scrolls up. (#67555)** (f90c4cb)
- **Fix eager load of currentKeyRing on resolving IDataProtector  (#67465)** (8ef91a5)
- **Fix MapFallback handling in RDG (#67562)** (0977f16)
- **Fix typos in code. (#67428)** (fa8126f)
- **Fix CsrfProtectionMiddleware perf degradations (#67488)** (e492c80)
- **Fix Blazor WASM Standalone HTTPS failure with Gateway (#67547)** (9ec4a86)
- **Fix ClientErrorMapping 500 title to match RFC 9110 (#65590)** (813b5e7)
- **Fix RDG generating invalid code for types from other source generators (#65453)** (c27b8c4)
- **Fix route document highlights across partial-class files (#66770)** (424ca14)
- **Fix QuickGridNoInteractivityTest (#66977)** (92b8fe3)

### Backend
- **[release/11.0-preview7] Obsolete JsonPatch STJ OperationBase.ShouldSerializeFrom (#68042)** (8331289)
- **Virtualize tests with `ItemProvider` should always contain a delay (#67959) (#68036)** (89467cb)
- **[release/11.0-preview7] Streamline localization in Microsoft.Extensions.Validation (#68005)** (9efdf69)
- **[release/11.0-preview7]  Handle passing a Func expression to Map* in ValidationsGenerator and RDG (#67999)** (ede598d)
- **[release/11.0-preview7] Creating Blazor Gateway CLI package and tests (#67990)** (5e09901)
- **[release/11.0-preview7] Update the weather page in the Blazor Web App template to persist prerendered state (#67989)** (949e3a5)
- **Move the abstract `Validatable*Info` from Microsoft.Extensions.Validation to be source-generated (#67956) (#67975)** (60de750)
- **[release/11.0-preview7] Respect IModelNameProvider when matching OpenAPI parameters (#67971)** (53c3bc1)
- **Backport PR #66355: Map [Obsolete] attribute to deprecated in OpenAPI documents (#67953)** (67bba0c)
- **Fix HTTP/2 test timing issues** — Updated three HTTP/2 connection tests to wait until the initial request reaches the application before initiating shutdown or closing the connection, ensuring reliable stream state validation instead of depending on transport timing. (5d6b575)
- **Close HTTP/1.1 rejected CONNECT** — Kestrel now properly closes the connection when rejecting an HTTP/1.1 CONNECT request with a 3xx or higher status code, per RFC 9931 Section 8 requirements. This ensures that rejected tunnel requests cannot inadvertently reuse the same connection. (d117bfd)
- **Fix session fixation after sign-out** — Fixed a security issue where signing out and then signing in again in the same request could reuse a deleted session key instead of creating a new one. The cookie authentication handler now properly clears its cached session key after removing it, ensuring subsequent sign-ins generate fresh session keys. (15bdfbf)
- **Clearer antiforgery token error messages** — When antiforgery validation fails because a security token was created for a logged-in user but the current request isn't authenticated, the error message now clearly states this instead of claiming there's a username mismatch. This fixes a confusing error message that would mislead developers debugging authentication issues. (1037569)
- **Removed gRPC Swagger library** — The Microsoft.AspNetCore.Grpc.Swagger package and all associated code, tests, and build configuration have been removed from the repository. This includes the library that provided Swagger/OpenAPI documentation generation support for gRPC services. (39e1ac9)
- **Updated dotnet extensions dependencies** — Updated five Microsoft.Extensions packages from version 10.7.0 to 10.8.0, including caching, diagnostics, service discovery, and time provider testing libraries. This is a backend dependency update with no user-facing changes. (f8a5cbf)
- **Updated project dependencies** — Refreshed build dependencies and version configurations to align with the latest dotnet/dotnet source updates. This routine maintenance ensures the project uses current library versions and build tools. (b2c0c20)
- **Enable prepend/append detection with the default `ItemComparer` in `Virtualize<TItem>` (#67905)** (61cd8e8)
- **Remove DataAnnotations' ValidationContext from MEV public API (#67549)** (24a934e)
- **Rename ConfigureHostApplicationBuilder to ConfigureWebApplicationBuilder (#67917)** (bd8392e)
- **Expose InitialItemIndex parameter and ScrollToItemAsync method on QuickGrid  (#67914)** (eb281b1)
- **[Blazor] Deprecate the Blazor WebAssembly DevServer package (#67862)** (94d3135)
- **Adding analyzer to warn about JSInterop calls not wrapped in a try catch block (#67900)** (6b3ab41)
- **Delete dead code in DelegateOpenApiDocumentTransformer (#67921)** (e4598cc)
- **Expose experimental `AnchorMode` and `ItemComparer` on `QuickGrid` (#67783)** (346fa53)
- **SignalR .NET client: make auth refresh work behind a redirecting server (Azure SignalR) (#67612)** (326d566)
- **Enforce MultipartHeadersLengthLimit across BufferedReadStream buffers (#67840)** (dfe3e58)
- **Improve `AnchorMode` tests (#67639)** (bf41edc)
- **Update AngleSharp to latest (#67898)** (fc4e6e0)
- **Update agentic workflows for gh aw v0.82.13 (#67901)** (5a09c12)
- **Harden wildcard matching with empty segments inside (#67757)** (70e4f65)
- **Allow `null` on `UserOptions.AllowedUserNameCharacters` (#67731)** (d516a8d)
- **[main] (deps): Bump src/submodules/googletest (#67880)** (512f313)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#67881)** (ee53595)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#67882)** (540b853)
- **[main] (deps): Bump actions/setup-dotnet from 5 to 6 (#67883)** (574547f)
- **[Blazor] Deprecate UseWebAssemblyDebugging and remove it from Blazor templates (#67861)** (1106030)
- **[wasm] Html Encode incoming parameters to debug page (#67875)** (b309e35)
- **Revert "Adding analyzer to warn about JSInterop calls not wrapped in a try ca…" (#67873)** (1d0c061)
- **Adding analyzer to warn about JSInterop calls not wrapped in a try catch block (#67530)** (f95205d)
- **API review changes for Blazor SSR client-side validation (#67855)** (081aac6)
- **Improve Blazor SSR client-side form validation (#67324)** (6a0d7ae)
- **Update milestones for August (#67836)** (3a347bb)
- **Treat QUERY as a safe HTTP method for antiforgery and CSRF protection (#67839)** (e4f3314)
- **[main] Source code updates from dotnet/dotnet (#67802)** (d89ecc4)
- **Merge pull request #67813 from kobihikri/rm-dead-codeowner** (3b67a86)
- **Cherry-pick internal commits (release/9.0) (#67805)** (1abace7)
- **[blazor] E2E test coreCLR WASM (#66331)** (1d6552f)
- **[test-quarantine] Unquarantine IIS NewShim ShutdownTests (dotnet/runtime#126925) (#67753)** (cf0ae5e)
- **[main] Source code updates from dotnet/dotnet (#67770)** (cef46b0)
- **Limit Microsoft.OpenApi to disallow next major (#67771)** (9123188)
- **Skip macOS quarantined-test job on PRs (#67767)** (0eb7bd1)
- **Update dependencies from build 322464 (#67736)** (7b0f909)
- **Avoid ArgumentException when Problem/ValidationProblem extensions conflict with defaults (#67690)** (fe4f6cd)
- **Harden test-quarantine workflow guardrails (B1/B2/B3) (#67764)** (56722f8)
- **[test-quarantine] Unquarantine DataProtectionProviderTests.System_UsesProvidedCertificateNotFromStore (#67754)** (07a46a4)
- **HttpSys: fail startup when Strict hardening cannot be applied (#67720)** (19a1265)
- **Quarantine flaky redirect test** — A test for enhanced GET redirects to external URLs was marked as quarantined due to intermittent timeout failures during initialization in CI builds. This prevents the unstable test from blocking the build while the underlying issue is investigated. (93bec6d)
- **Updated .NET runtime dependencies** — Automated dependency update for build 322287, including Microsoft .NET runtime libraries, Entity Framework, configuration extensions, and NuGet tools across multiple preview and beta versions. (c4d061a)
- **Updated testing framework dependency** — Updated the Google Test library submodule to the latest version to pick up new testing features and improvements. (e0222ac)
- **Updated backport workflow dependency** — Updated the dotnet/arcade backport workflow to the latest version to ensure compatibility and receive the latest backport automation improvements. (f297235)
- **Updated arcade workflow dependency** — Updated the inter-branch merge workflow to use the latest version from the dotnet/arcade repository, ensuring the build process uses the most recent merge logic. (af1e2a4)
- **Reverted hidden member validation fix** — This change reverts a previous fix that handled validation of hidden properties in inheritance hierarchies. The property lookup logic was simplified back to a basic call without the additional binding flags that were added to resolve AmbiguousMatchException errors. (56326e6)
- **QuickGrid virtualization fast scroll handling** — Improved QuickGrid's virtualization to better handle fast scrolling when item sizes are estimated incorrectly, preventing the viewport from getting stuck on placeholder rows. Added test coverage with both fixed and variable-height row scenarios to ensure real data remains visible during rapid scrolling. (de9f8e0)
- **Stricter Content-Length header validation** — Fixed HTTP request header validation to reject Content-Length values with leading `+` or `-` signs, and leading spaces, aligning with RFC 9110 specifications that require only digits. This prevents malformed requests from being accepted. (cf607f3)
- **Suppressed approved security alerts** — Added inline CodeQL suppressions for 19 security alerts that have been reviewed and approved by design across authentication, cookies, data protection, and dev tooling. These suppressions document accepted risks in areas like cookie security policies, JWT validation in test/sample code, and the use of managed AES-GCM encryption. (87ef375)
- **Suppress false-positive security alerts** — Added CodeQL alert suppressions across authentication and HTTP handling code to prevent false positives. These suppressions document why specific code patterns are safe—such as correlation cookies being secure by default, configuration-bound token validation parameters, and pre-encoded HTML strings—addressing review feedback to improve justification clarity. (bd8b9db)
- **Encryptors run self test** — All authenticated encryptor implementations now execute a self-test during construction to verify correct operation. If the self-test fails, resources are properly cleaned up before the error is re-thrown. (acdcaf7)
- **Limit Zstandard decompression window** — Zstandard request decompression now caps the decompression window at 8 MB as required by RFC 9659, preventing excessive memory allocation. Requests with larger compression windows will fail to decompress, while standard streaming compression remains unaffected. (68a38e1)
- **Updated .NET dependencies** — Updated 70+ NuGet package dependencies to the latest preview and release candidate versions from the .NET build 322034, including Entity Framework Core, ASP.NET Core runtime, and various System libraries. (4003b2c)
- **Clarify PageLink URL generation documentation (#67665)** (b0780af)
- **Fixed AmbiguousMatchException in DataAnnotationsValidator for Hidden Members (#67075)** (3b00cfc)
- **Improve CreateTwoFactorRecoveryCode in .NET 8+ (#67670)** (2519925)
- **[main] Source code updates from dotnet/dotnet (#67642)** (cf0040c)
- **Guard quarantine temporary_id against length-limit placeholder leaks (#67683)** (a53b5e4)
- **[main] (deps): Bump src/submodules/googletest (#67651)** (cb1ac26)
- **Make EditContext.Validate obsolete, adjust tests and project template (#67662)** (4b9040e)
- **Unify null session behaviour for TempData and SupplyParameterFromTempData (#67641)** (12fe567)
- **Update ValidationsGenerator to drop the embedded SDK-generated attribute (#67636)** (3e156e1)
- **Switch ValidateContext.ValidationErrors to `IReadOnlyList<string>` instead of `IEnumerable<string>` (#67659)** (7645238)
- **Rerun PostRoutingPipeline on Rerouting (#67618)** (caa7a7a)
- **Clarify ActionLink URL generation docs (#67481)** (fbec0e6)
- **Update Microsoft.OpenApi to 3.8.0 (#67638)** (2f6f5dc)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#67656)** (38fefbd)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#67655)** (f84ee26)
- **Enable IDE0005 analyzer in the build (#49080)** (9e65638)
- **Adopt the PAT pool for agentic workflows (#67411)** (6ce13b9)
- **Improve Blazor async form validation (#67323)** (b126e4f)
- **Remove experimental marker from validation attributes (#67634)** (a2a5480)
- **Circuit can be paused by Blazor when inactivity is detected (#67098)** (ce86c1a)
- **Reject connection-specific headers sent via HPACK/QPACK indexed names (#67584)** (ed2a147)
- **Harden "chunked" handling in ANCM (#67512)** (73d6c2a)
- **Normalize C++ PlatformToolsetVersion and centralize PlatformToolset (#67552)** (8f51f03)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#67582)** (0269304)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#67581)** (b2be87b)
- **[main] (deps): Bump actions/cache/restore from 5.0.5 to 6.1.0 (#67580)** (2801156)
- **[main] (deps): Bump src/submodules/googletest (#67579)** (f070f3f)
- **Disable compression in Microsoft.AspNetCore.App.Internal.Assets via CompressionEnabled=false (#67545)** (dfb0b04)
- **Reduce unnecessary unsafe usage in AdaptiveCapacityDictionary (#64617)** (0c72963)
- **Update Microsoft.Windows.CsWin32 from 0.3.275 to 0.3.296 (#67501)** (242c474)
- **Include LICENSE file in published SignalR npm packages (#67496)** (d37becd)
- **Update Microsoft.OpenApi to 3.7.0 (#67468)** (0e393eb)
- **Update browser-testing deps: Selenium 4.45.0, Playwright 1.61.0 (#67502)** (823c4e5)
- **Improve QuickGrid diagnostics for mismatched GridSort types (#67413)** (18ef192)
- **Update Fuzzing to run correctly (#67498)** (07881fd)
- **Avoid recompiling the shared framework when publishing to the layout root (#67469)** (1da09bd)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/dotnet/aspnetcore?utm_source=github-action)._