## dotnet/aspnetcore — v11.0.0-preview.7.26381.103…v11.0.0-rc.1.26425.128

_223+ commits._

### Features
- **Obsolete Bootstrap 4 Identity UI support (#68477) (#68575)** (0b69dba)
- **Add eng/common Copilot review instructions (#68464)** (76d1e57)
- **[Blazor] Add Components.AI rich text rendering (#68324)** (0b72e0b)
- **[Blazor] Add code-behind option to RazorComponent item template (#63813)** (624894d)
- **[Blazor] Support Aspire Dashboard on Native AOT (#68307)** (8eaeccb)
- **Add MEV analyzers (#67993)** (8372d2a)
- **Add asset path metadata attributes** — Added new `AssetPathAttribute` and `AcceptsAssetPathAttribute` classes to enable the Razor compiler to automatically expand static asset paths in component parameters and HTML elements. This includes built-in support for common HTML elements like `img`, `script`, `link`, `video`, and `audio` tags. (66eb32d)
- **generated(ai): add streaming chat recordings** (3aa4e3c)
- **feat(dojo): connect DojoClient through a separate AG-UI API** (2023588)
- **feat(ai): stream plain text into observable content blocks** (3c38598)
- **Native AOT Components testing harness** — Added a comprehensive Native AOT testing framework for Blazor Components, including a build-only package, test harness generator, manifest support, and end-to-end validation for native application publishing. The system now exposes server instance properties to external tests and properly handles Native AOT configuration across project references. (330e89c)
- **Allow nullable array element types** — Added support for nullable elements within array parameters and responses in OpenAPI schemas. When an array parameter has nullable element types (like `string?[]`), the schema now correctly documents that individual array items can be null, while keeping non-nullable array parameters unaffected. (73babb0)
- **Add tests for validating null values of minimal API parameters (#67395)** (a81552c)
- **Add MessagePack submodule diagnostic (#68142)** (c3b8222)
- **Secure sample app rendering** — Added security hardening to the SocialSample authentication example by encoding user input and tokens before displaying them in HTML responses, preventing potential injection attacks. Also added README files across all sample directories to clarify they are for development use only, and created tests for the SocialSample app. (9f99606)
- **Add authentication token refresh** — Added support for refreshing authentication tokens in SignalR TypeScript connections. Developers can now call a refresh method to update expired tokens without reconnecting, with optional automatic refresh. This is useful for long-lived connections that need fresh credentials. (747d2cd)

### Fixes
- **[Routing] Fix case-insensitive host DFA edges (#68670) (#68690)** (29e87b5)
- **Fix  InitialItemIndex viewport underfill for small items in big container or on window resize (#67936) (#68689)** (88cf74b)
- **Fix auto-pause when circuit starts after enhanced navigation (#68540) (#68612)** (96b7ae9)
- **Fix TryServeFromCacheAsync_ReturnsFalse_IfVaryByKeyContainsDelimiters failure (#68554) (#68578)** (1a82e94)
- **Fix app_offline.htm file detection** — Corrected the file notification matching logic in the IIS AspNetCore module to properly detect exact `app_offline.htm` file changes using the correct string length comparison method. Added comprehensive unit tests to verify the fix handles exact matches while correctly ignoring partial matches. (75c3218)
- **Require proof before verifying bug fixes** — Added guidance to the Copilot instructions requiring agents to demonstrate that a relevant test fails without a fix and passes with it before claiming a bug fix is verified, rather than relying solely on reading code or seeing tests pass in isolation. (733b51b)
- **Fix shutdown hang with IIS (#65733)** (f97c0ff)
- **Fix `InitialItemIndex` is intermittently ignored on fresh page load  (#68114)** (1f689ce)
- **[Identity] Fix nullref in Identity on netfx/netstandard (#68460)** (1825bfe)
- **Fix BL0013 diagnostic span mapping (#68451)** (b201479)
- **Fix OpenAPI nullability for ignored setters (#68454)** (d04c380)
- **fix(ai): address streaming chat review feedback** (dd3447f)
- **Fixed nested function return detection** — Fixed a false positive in the ASP0016 analyzer that was incorrectly flagging return statements from nested anonymous functions and local functions inside request delegates. The analyzer now properly distinguishes between returns belonging to nested functions versus the outer request delegate itself. (3600ca0)
- **Fix persisted state on enhanced navigation** — Fixed a bug where component state was lost when interactive components were activated during enhanced navigation (page navigation without full reload). The issue occurred because the framework checked for persisted state before assigning renderer IDs to newly activated components. Added test coverage for this scenario, including streaming rendering cases. (4ca8f9a)
- **Fix Components AI dependency discovery** (fa90843)
- **Add descriptions to request bodies** — OpenAPI request bodies now include parameter descriptions from code attributes. The fix applies description metadata to request body schemas so API documentation displays helpful context for form parameters and complex objects. (169ace1)
- **Fix extra `\n` in resourceManagement for breaking change announcement (#68214)** (d54440a)
- **Fix flaky RefreshChangingUserIdentifierClosesConnection test (#68096)** (8425644)
- **Fix `AnchorMode_End_PrependAtTop_ViewportStaysStable` (#68064)** (9b8c2c8)
- **Fix Persistent Component State for Re-executed Endpoints (#68032)** (c445615)
- **Add exclude-paths to nuget dependabot config to fix scan timeout (#68171)** (99fa485)
- **Fix double-publish ILLink error in TestContentPackage. (#68085)** (c8d78ff)
- **Fix nullable property schema generation** — Fixed OpenAPI schema generation for nullable constructor-bound properties and get-only properties. The update corrects how nullability is represented in API documentation, ensuring properties that can accept null values are properly marked in the schema, while preventing false positives on read-only properties. (b5220c3)
- **Fix test cursor handling for date input** — Corrected a test for date input validation by using the proper SetDate method instead of direct key sending, ensuring the cursor lands correctly when testing time input behavior with edit context. (642a4a0)

### Backend
- **[release/11.0-rc1] Source code updates from dotnet/dotnet (#68668)** (c3325ee)
- **Merge pull request #68751 from DeagleGross/backport-68664-to-release-11-rc1** (db0c572)
- **Update SignalR authentication refresh APIs (#68676) (#68702)** (9245482)
- **Clarify AllowUpdates property summary comment (#68618) (#68660)** (a65d5c0)
- **[release/11.0-rc1] Extract IsAuthenticated helper method (#68658)** (4c1e2ed)
- **Use model display names in Blazor input parsing errors (#68667) (#68688)** (696ea7b)
- **Don't apply the CSRF verdict to remote authentication callbacks (#68669)** (558ba2c)
- **SignInManager: return SignInResult.Failed for expired passkey session challenge (#67539) (#68654)** (555ae4e)
- **Preserve BadHttpRequestException status codes (#68632) (#68649)** (026aff6)
- **Honor all sign-in confirmation requirements after registration (#68631) (#68655)** (6df01e3)
- **[SignalR] Reject duplicate SignalR upload stream IDs (#68525) (#68638)** (7638d71)
- **[Blazor] Hide experimental circuit JSON resolver API (#68585) (#68590)** (35b3142)
- **Harden SignalR authentication refresh (#68459) (#68593)** (d201668)
- **Avoid ignoring authorization failure reasons (#68572) (#68576)** (47b2e02)
- **Check if TwoFactorRememberMeScheme is registered before signing out (#68571) (#68577)** (593368b)
- **Remove insecure chunked parsing option** — Removed a legacy compatibility switch that allowed insecure parsing of HTTP chunked request extensions. The code now always uses the secure parsing path that validates both carriage return and line feed characters. (17b8a4a)
- **Add experimental DirectTls transport** — Introduces an opt-in DirectTls transport for Kestrel that terminates TLS directly on Linux using native OpenSSL via epoll, bypassing SslStream. It includes per-SNI certificate selection, ALPN/HTTP-2 support, and mutual TLS client-certificate modes, with the transport shipped as a standalone NuGet package separate from the shared framework. (07d11eb)
- **Updated backport workflow dependency** — Updated the dotnet/arcade backport workflow to the latest version. This is an automated dependency update that ensures the backport process uses the most recent workflow logic from the arcade repository. (efe577d)
- **Updated arcade workflow dependency** — A GitHub Actions workflow dependency from the dotnet/arcade repository was updated to a newer version. This is a routine maintenance update to keep the inter-branch merge workflow current with the latest changes from the shared arcade repository. (e6a7426)
- **Propagate ScrollToItemAsync cancellation to pending item-provider work. (#68478)** (401bbfb)
- **Resolve NuGet Audit warnings (#68514)** (656195d)
- **Validate the query component of the HTTP/2 and HTTP/3 :path pseudo-header (#68320)** (a6dab8a)
- **Harden Response/Output cache (#68517)** (f4cf688)
- **Merge pull request #67988 from surya3655/6326-incorrect-validation** (757a459)
- **Merge pull request #68111 from PreethikaSelvam/67518-test-update** (0f91a13)
- **Use ASCII group separate (GS) for separating key/value in caching middleware (#68510)** (a019c0b)
- **Addressed the review suggestion by adding comments.** (fbacb6c)
- **Merge branch 'main' of https://github.com/surya3655/aspnetcore-main into 6326-incorrect-validation** (079745c)
- **Update Microsoft.OpenApi to 3.10 (#68462)** (5467b04)
- **Update repo ownership mappings (#66642)** (c0c8774)
- **Derive Helix tool versions from dotnet-tools.json (#68499)** (01b15bd)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#68502)** (a9a6754)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#68503)** (8ff6e4c)
- **Exclude dotnet-dump and dotnet-serve from Dependabot (#68496)** (87485f0)
- **Update agentic workflows to gh-aw v0.86.2 (#68500)** (1a4a830)
- **Document framework assembly access rule (#68493)** (80de79a)
- **Bump the JobMonitor (#68472)** (43acd80)
- **Merge branch 'main' of https://github.com/surya3655/aspnetcore-main into 6326-incorrect-validation** (832fba9)
- **Use TLS channel binding in Negotiate authentication (#68317)** (704fddd)
- **removed redundant test cases** (348c2d9)
- **reduce bindconverter test case** (726bcc5)
- **Remove Publish-Build-Assets variable group (#68260)** (2a0388b)
- **[main] Source code updates from dotnet/dotnet (#68285)** (7df7e8e)
- **[test-quarantine] Quarantine flaky IISExpress RequestResponseTests class (#68272)** (ec6b9d0)
- **Avoid duplicate WebAssembly publish asset compression (#68463)** (9d6f69a)
- **Revert "Use 1es ubuntu for Linux x64 job (#66054)" (#68461)** (8a3632c)
- **Bump dotnet-serve from 1.10.93 to 1.10.194 (#68359)** (a3714d9)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#68356)** (7a1c5c1)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#68357)** (4a54fb7)
- **[main] (deps): Bump src/submodules/googletest (#68353)** (fbf8544)
- **Avoid resolving HybridCache during Redis connection (#68127)** (78cf766)
- **Merge pull request #68358 from dotnet/dependabot/nuget/dot-config/dotnet-dump-6.0.408101** (2cc1a4e)
- **Merge pull request #68323 from dotnet/javiercn/components-ai-01-chat** (fa2e746)
- **Cache display names per UI culture (#68347)** (208aaaf)
- **Message key conventions for validation localization (#68202)** (f508645)
- **Validate QPack static table index in QPackDecoder (#68321)** (be6114d)
- **Merge pull request #68221 from kotlarmilos/blazor-auth-refresh-circuit-user** (ee12843)
- **Simplify and unify TempData and SupplyParameterFromSession serialization (#65483)** (2daa22c)
- **Updated build dependency** — Bumped Microsoft.Build.NoTargets from version 3.7.0 to 3.7.134 to get the latest patch updates for the build system. (933baa0)
- **Simplify NuGet dependency scanning** — NuGet Dependabot configuration was streamlined to scan only the discovery project instead of the entire repository with multiple exclusions. This change improves scanning efficiency by focusing on the dedicated discovery tool rather than attempting to process 600+ project files across the codebase. (a55bb8b)
- **Updated code documentation guidance** — Added clarified guidance for Components developers on writing clear, durable code through naming and structure rather than comments, and on limiting public XML documentation to consumer-observable behavior rather than internal implementation details. (4e5ba32)
- **Fix flaky virtualization test** — Fixed a flaky virtualization test by moving a scroll command inside a timing-safe wait block, ensuring the scroll completes before checking the result. The test was then unquarantined since it now reliably passes. (651fc25)
- **Speed up HTTP header parsing** — Improved the performance of HTTP header parsers by avoiding re-scanning malformed input that has already been processed. This optimization allows the parser to recover more efficiently when encountering invalid header values and move on to parse the next valid header. (66e8a02)
- **Clarify refresh sign-in documentation** — Updated documentation for RefreshSignInAsync to clarify that it refreshes an existing sign-in rather than creating a new one, and removed unnecessary null-conditional operators in the code since the principal is guaranteed to exist at that point. (45317be)
- **cleanup(ai): use repository package feeds** (15524ec)
- **Re-enable nested validation test** — A previously quarantined integration test for form validation with nested components has been re-enabled. The test was disabled based on outdated CI data from before a related fix was applied, and has been passing consistently since then. (a9ffda9)
- **Re-enable Blazor passkey test** — A previously quarantined test for Blazor passkey functionality has been re-enabled. The underlying regression it was tracking has been fixed, and the test has been stable on the main branch. (c4278c0)
- **Migrate testing from xUnit to MSTest** — The Blazor Components.Testing library was migrated from xUnit v3 to MSTest 4.x with a new source generator that decouples the library from MSTest while emitting test framework integration code into consumer projects. New base classes (PlaywrightTest, BrowserTest, ContextTest, PageTest) provide Playwright testing utilities, and the test asset was updated with 23 MSTest tests replacing the previous xUnit collection-based approach. (1d5f6d8)
- **Merge branch 'main' into 67518-test-update** (1dcde72)
- **Merge branch 'main' of https://github.com/surya3655/aspnetcore-main into 6326-incorrect-validation** (12da73d)
- **test cases improvement** (3faf3b0)
- **Update optimization runtime dependencies** — Updated dotnet-optimization MIBC Runtime packages across all platforms (Windows x64/x86/ARM64, Linux x64/ARM64) to the latest prerelease version from the automated dependency build pipeline. (44c4b60)
- **Merge branch 'main' of https://github.com/surya3655/aspnetcore-main into 6326-incorrect-validation** (41c6f70)
- **Use HubConnection for authentication refresh test** (97251a5)
- **Enable MSBuild node reuse locally** — Removed the workaround that disabled MSBuild node reuse for local builds in both PowerShell and Bash build scripts. This allows MSBuild to reuse compiler nodes across builds, improving build performance. (a5ee747)
- **Updated dotnet dependencies and removed analyzers** — This commit syncs source code updates from the dotnet/dotnet repository, updating tool and version configurations. It also removes the entire Mvc.Api.Analyzers module (source code, tests, and test files), which previously provided code analysis and fixes for ASP.NET Core API controllers. (a728d98)
- **Update MCP template dependency** — Updated the Model Context Protocol dependency from version 1.2.0 to 2.1.0 for .NET 11 templates. (92f07e2)
- **Add logging for missing resources** — The localizer now logs a debug message whenever a localization resource is not found, helping developers track down missing translations. This includes three scenarios: when a resource manifest is missing, when a specific resource key isn't found, and when a resource is successfully located (in which case nothing is logged). (f0e6aa6)
- **Improve Sections warning messaging (#67977)** (294cab2)
- **[main] Source code updates from dotnet/dotnet (#68246)** (5409db8)
- **Improve Blazor WebAssembly E2E startup diagnostics (#68200)** (dc1fb6c)
- **Clarify Components E2E build workflow (#68238)** (8e7c5ab)
- **Drop ApiDescription.Client package (#68211)** (0916dab)
- **Mark RenderFragment serialization API as experimental (#68230)** (968922c)
- **[Infrastructure] Update vulnerable npm packages (#68233)** (5b85db2)
- **Update dependencies from build 325626 (#68210)** (5aca3b4)
- **Quarantine AddValidationIntegrationTest.FormWithNestedValidation_Works (#68224)** (c10ee0e)
- **Quarantine VirtualizationTest.AnchorMode_WindowScroll_HomeKeyJumpsToTop (#68226)** (8c76631)
- **Address review feedback on authentication refresh tests** (20ee2cb)
- **[Blazor] Propagate SignalR authentication refresh to server circuits** (3ba28b7)
- **Update CHANGELOG for version 11.0.0-rc1 (#68207)** (31b9bcd)
- **Recompile agentic workflow lockfiles (#68208)** (c7e9984)
- **Update dependencies from build 325363 (#68190)** (58b4fc9)
- **Integrate Helix Job Monitor into all Helix-submitting pipelines (#68007)** (28dd8a5)
- **Emit framework versions from Blazor WASM benchmark Driver (#68119)** (3ea89c5)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/inter-branch-merge-base.yml (#68176)** (51e6c94)
- **[main] (deps): Bump dotnet/arcade/.github/workflows/backport-base.yml (#68177)** (5de3c46)
- **[main] (deps): Bump src/submodules/googletest (#68174)** (764d4ad)
- **Quarantine HubConnectionTests.RefreshChangingUserIdentifierClosesConnection (#68151)** (ab732c4)
- **Update dependencies from https://github.com/dotnet/extensions build 20260727.2 (#68164)** (d3542c3)
- **[main] Source code updates from dotnet/dotnet (#68145)** (e483d28)
- **[Infrastructure] Updated npm packages 2026-07-29 (#68091)** (1a93b55)
- **Quarantine ShutdownTests.ConfigurationChangeForcesChildProcessRestart (#68152)** (73ae049)
- **OpenAPI: Delete unused overload of WillBeComponentized (#68135)** (77d9143)
- **Simplify OpenAPI primitive format handling** — Refactored the internal logic for applying OpenAPI format specifications to primitive types, removing unnecessary schema object creation and consolidating the format application process. This cleanup reduces code complexity while maintaining the same external functionality for API documentation generation. (87bea93)
- **Replaced async utility class** — Switched from a custom `TaskToApm` class to the standard inbox `TaskToAsyncResult` class across multiple middleware and server components. This simplifies the codebase by removing duplicate functionality and standardizing on the built-in implementation. (4061277)
- **Merge branch 'main' into 67518-test-update** (db8ad2c)
- **Fixed flaky virtualization test** — Improved the stability of a virtualization test by removing a quarantine marker and refactoring the test logic to use more reliable polling checks instead of direct element references, making it less prone to timing issues. (8d2e54b)
- **Updated build dependencies** — This update refreshes internal build and testing dependencies to the latest versions from the dotnet/dotnet repository, including updates to version tracking files and build infrastructure templates. (cd4daf1)

### Tests
- **test(ai): cover streaming and multi-turn chat over AG-UI** (87a127b)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/dotnet/aspnetcore?utm_source=github-action)._