{"record":{"id":"015fc69e41b7cb32","repo":"dotnet/aspnetcore","slug":"the-provided-identity-of-type-0-is-marked-1","errorCode":null,"errorMessage":"The provided identity of type '{0}' is marked {1} = {2} but does not have a value for {3}. By default, the antiforgery system requires that all authenticated identities have a unique {3}. If it is not possible to provide a unique {3} for this identity, consider extending {4} by overriding the {5} or a custom type that can provide some form of unique identifier for the current user.","messagePattern":"The provided identity of type '(.+?)' is marked (.+?) = (.+?) but does not have a value for (.+?)\\. By default, the antiforgery system requires that all authenticated identities have a unique (.+?)\\. If it is not possible to provide a unique (.+?) for this identity, consider extending (.+?) by overriding the (.+?) or a custom type that can provide some form of unique identifier for the current user\\.","errorType":"exception","errorClass":"InvalidOperationException","httpStatus":null,"severity":"error","filePath":"src/Antiforgery/src/Internal/DefaultAntiforgeryTokenGenerator.cs","lineNumber":86,"sourceCode":"            if (requestToken.ClaimUid == null)\n            {\n                requestToken.Username = authenticatedIdentity.Name;\n            }\n        }\n\n        // populate AdditionalData\n        if (_additionalDataProvider != null)\n        {\n            requestToken.AdditionalData = _additionalDataProvider.GetAdditionalData(httpContext);\n        }\n\n        if (isIdentityAuthenticated\n            && string.IsNullOrEmpty(requestToken.Username)\n            && requestToken.ClaimUid == null\n            && string.IsNullOrEmpty(requestToken.AdditionalData))\n        {\n            // Application says user is authenticated, but we have no identifier for the user.\n            throw new InvalidOperationException(\n                Resources.FormatAntiforgeryTokenValidator_AuthenticatedUserWithoutUsername(\n                    authenticatedIdentity?.GetType() ?? typeof(ClaimsIdentity),\n                    nameof(IIdentity.IsAuthenticated),\n                    \"true\",\n                    nameof(IIdentity.Name),\n                    nameof(IAntiforgeryAdditionalDataProvider),\n                    nameof(DefaultAntiforgeryAdditionalDataProvider)));\n        }\n\n        return requestToken;\n    }\n\n    /// <inheritdoc />\n    public bool IsCookieTokenValid(AntiforgeryToken? cookieToken)\n    {\n        return cookieToken != null && cookieToken.IsCookieToken;\n    }\n","sourceCodeStart":68,"sourceCodeEnd":104,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Antiforgery/src/Internal/DefaultAntiforgeryTokenGenerator.cs#L68-L104","documentation":"Thrown when generating an antiforgery token for an authenticated user whose identity has no username (IIdentity.Name empty), no ClaimUid (no anti-forgery claim-based identifier), and no AdditionalData supplied by a custom provider. The system requires every authenticated identity to have a unique identifier so tokens can be bound to the user.","triggerScenarios":"A signed-in ClaimsIdentity reaches the token generator with IsAuthenticated==true, but Name claim is unset, the claim used to build ClaimUid is missing, and no IAntiforgeryAdditionalDataProvider is registered to fill AdditionalData.","commonSituations":"Custom authentication that sets IsAuthenticated without a Name claim (or without ClaimTypes.NameIdentifier); cookie/auth configured without setting a NameClaimType; a federated login that doesn't map a unique id claim; upgrading to a claims identity without configuring UniqueClaimTypeIdentifier.","solutions":["Ensure the ClaimsIdentity has a Name claim populated (set NameClaimType or add a Claim of that type) so IIdentity.Name is non-empty.","Or configure AntiforgeryOptions to use a unique claim via a custom IAntiforgeryAdditionalDataProvider that fills AdditionalData.","Set the identity's NameClaimType to a claim that is guaranteed present (e.g. ClaimTypes.NameIdentifier) when constructing the ClaimsIdentity.","If the user truly has no stable identifier, mark the identity as not authenticated for that resource so the username requirement is bypassed."],"exampleFix":"// before: identity with no Name claim\nvar id = new ClaimsIdentity(claims, \"MyAuth\"); // Name is null\n\n// after: declare the unique claim as the name source\nvar id = new ClaimsIdentity(claims, \"MyAuth\", ClaimTypes.NameIdentifier, ClaimTypes.Role);","handlingStrategy":"validation","validationCode":"var identity = httpContext.User.Identity as ClaimsIdentity;\nif (identity?.IsAuthenticated == true && string.IsNullOrEmpty(identity.Name)) { /* ensure a Name claim or register an IAntiforgeryAdditionalDataProvider before generating the token */ }","typeGuard":"static bool HasAntiforgeryIdentity(IIdentity? id) => !(id?.IsAuthenticated == true && string.IsNullOrEmpty(id.Name));","tryCatchPattern":null,"preventionTips":["Set NameClaimType on custom ClaimsIdentity to a claim that is always present.","Register an IAntiforgeryAdditionalDataProvider when you cannot guarantee a Name claim.","Add a unit test that signs in a claimless principal and asserts token generation succeeds."],"tags":["antiforgery","aspnetcore","authentication","claims","security"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}