{"record":{"id":"01f84d7cc835852b","repo":"dotnet/aspnetcore","slug":"authorization-requires-a-cascading-parameter-of-ty","errorCode":null,"errorMessage":"Authorization requires a cascading parameter of type Task<AuthenticationState>. Consider using CascadingAuthenticationState to supply this.","messagePattern":"Authorization requires a cascading parameter of type Task<AuthenticationState>\\. Consider using CascadingAuthenticationState to supply this\\.","errorType":"exception","errorClass":"InvalidOperationException","httpStatus":null,"severity":"error","filePath":"src/Components/Authorization/src/AuthorizeViewCore.cs","lineNumber":85,"sourceCode":"        {\n            builder.AddContent(0, NotAuthorized?.Invoke(currentAuthenticationState!));\n        }\n    }\n\n    /// <inheritdoc />\n    protected override async Task OnParametersSetAsync()\n    {\n        // We allow 'ChildContent' for convenience in basic cases, and 'Authorized' for symmetry\n        // with 'NotAuthorized' in other cases. Besides naming, they are equivalent. To avoid\n        // confusion, explicitly prevent the case where both are supplied.\n        if (ChildContent != null && Authorized != null)\n        {\n            throw new InvalidOperationException($\"Do not specify both '{nameof(Authorized)}' and '{nameof(ChildContent)}'.\");\n        }\n\n        if (AuthenticationState == null)\n        {\n            throw new InvalidOperationException($\"Authorization requires a cascading parameter of type Task<{nameof(AuthenticationState)}>. Consider using {typeof(CascadingAuthenticationState).Name} to supply this.\");\n        }\n\n        // Clear the previous result of authorization\n        // This will cause the Authorizing state to be displayed until the authorization has been completed\n        isAuthorized = null;\n\n        currentAuthenticationState = await AuthenticationState;\n        isAuthorized = await IsAuthorizedAsync(currentAuthenticationState.User);\n    }\n\n    /// <summary>\n    /// Gets the data required to apply authorization rules.\n    /// </summary>\n    protected abstract IAuthorizeData[]? GetAuthorizeData();\n\n    internal virtual object[]? GetAuthorizationMetadata() => GetAuthorizeData();\n\n    private async Task<bool> IsAuthorizedAsync(ClaimsPrincipal user)","sourceCodeStart":67,"sourceCodeEnd":103,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Components/Authorization/src/AuthorizeViewCore.cs#L67-L103","documentation":"Thrown by AuthorizeViewCore.OnParametersSetAsync when the AuthenticationState cascading parameter is null. AuthorizeView/AuthorizeRouteView need a Task<AuthenticationState> supplied via a CascadingAuthenticationState ancestor to evaluate authorization.","triggerScenarios":"Rendering <AuthorizeView> (or using [CascadingParameter] Task<AuthenticationState>) without a <CascadingAuthenticationState> wrapper in the component tree, or without AddCascadingAuthenticationState registered in DI.","commonSituations":"Adding AuthorizeView to a Blazor Server/WebAssembly app that hasn't wired up authentication; forgetting to wrap App.razor/Routes.razor in <CascadingAuthenticationState>; missing services.AddAuthorizationCore() / AddCascadingAuthenticationState() in Program.cs.","solutions":["Wrap the root component (e.g. <Router>) in <CascadingAuthenticationState>...</CascadingAuthenticationState>.","Or call builder.Services.AddCascadingAuthenticationState() (preferred for .NET 8+) so the cascade is registered globally.","Ensure services.AddAuthorizationCore() and the relevant authentication provider (e.g. AddAuthentication) are registered.","For Blazor WebAssembly, confirm CustomAuth/Identity provider setup in Program.cs."],"exampleFix":"// before: no cascading auth state in Program.cs\nbuilder.Services.AddAuthorizationCore();\n\n// after: register the cascading provider\nbuilder.Services.AddAuthorizationCore();\nbuilder.Services.AddCascadingAuthenticationState();\n\n<!-- or wrap in App.razor/Routes.razor -->\n<CascadingAuthenticationState>\n    <Router AppAssembly=\"@typeof(Program).Assembly\">...</Router>\n</CascadingAuthenticationState>","handlingStrategy":"validation","validationCode":"// Program.cs\nbuilder.Services.AddAuthorizationCore();\nbuilder.Services.AddCascadingAuthenticationState();","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Register AddCascadingAuthenticationState() during project scaffolding.","Add a root-level test that renders AuthorizeView and asserts no exception.","Document the requirement in the project template readme."],"tags":["blazor","aspnetcore","authorization","authentication","components"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}