{"record":{"id":"4742b82751d3917e","repo":"dotnet/aspnetcore","slug":"the-required-antiforgery-cookie-0-is-not-prese","errorCode":null,"errorMessage":"The required antiforgery cookie \"{0}\" is not present.","messagePattern":"The required antiforgery cookie \"(.+?)\" is not present\\.","errorType":"validation","errorClass":"AntiforgeryValidationException","httpStatus":null,"severity":"error","filePath":"src/Antiforgery/src/Internal/DefaultAntiforgery.cs","lineNumber":148,"sourceCode":"        else\n        {\n            _logger.ValidationFailed(message!);\n        }\n\n        return result;\n    }\n\n    /// <inheritdoc />\n    public async Task ValidateRequestAsync(HttpContext httpContext)\n    {\n        ArgumentNullException.ThrowIfNull(httpContext);\n\n        CheckSSLConfig(httpContext);\n\n        var tokens = await _tokenStore.GetRequestTokensAsync(httpContext);\n        if (tokens.CookieToken == null)\n        {\n            throw new AntiforgeryValidationException(\n                Resources.FormatAntiforgery_CookieToken_MustBeProvided(_options.Cookie.Name));\n        }\n\n        if (tokens.RequestToken == null)\n        {\n            if (_options.HeaderName == null)\n            {\n                var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);\n                throw new AntiforgeryValidationException(message);\n            }\n            else if (!httpContext.Request.HasFormContentType)\n            {\n                var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);\n                throw new AntiforgeryValidationException(message);\n            }\n            else\n            {\n                var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(","sourceCodeStart":130,"sourceCodeEnd":166,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Antiforgery/src/Internal/DefaultAntiforgery.cs#L130-L166","documentation":"DefaultAntiforgery.ValidateRequestAsync obtains the request tokens via the token store and requires a cookie token to be present. If the antiforgery cookie (named per options.Cookie.Name) is absent from the request, validation fails before a request/form token is even checked, throwing AntiforgeryValidationException.","triggerScenarios":"A POST/PUT/PATCH (or manual ValidateRequestAsync) request reaches validation but the client did not send the antiforgery cookie token - tokens.CookieToken is null (DefaultAntiforgery.cs:145-150). The cookie normally accompanies the request token pair issued by GetAndStoreTokensAsync.","commonSituations":"The client never received/echoed the antiforgery cookie (no GET to mint it, or SameSite/Secure blocked it); cross-origin requests where credentials/cookies are not sent; cookie expired or was cleared; a different Cookie.Name configured than what the client holds.","solutions":["Ensure the client first obtains the antiforgery cookie - issue a GET that calls GetAndStoreTokensAsync (or rely on the auto-validation flow which sets the cookie) before the unsafe verb.","Send credentials cross-origin: fetch/Ajax with credentials:'include' / HttpClient with cookies, and set proper CORS + SameSite.","Confirm options.Cookie.Name matches the cookie actually issued and that Secure/SameSite allow transmission."],"exampleFix":"// before - client POSTs with no antiforgery cookie\nawait antiforgery.ValidateRequestAsync(HttpContext); // throws\n// after - mint+set the cookie first (e.g. on a prior GET)\nvar tokens = antiforgery.GetAndStoreTokens(httpContext);\n// client then sends the cookie + token on the POST","handlingStrategy":"try-catch","validationCode":"// Make sure the cookie exists before validating an unsafe verb\nif (!httpContext.Request.Cookies.ContainsKey(antiforgeryOptions.Cookie.Name)) {\n    // mint+store the cookie (e.g. on a prior GET via GetAndStoreTokensAsync)\n    return Results.BadRequest(\"Missing antiforgery cookie.\");\n}","typeGuard":"bool hasCookieToken(HttpContext ctx, AntiforgeryOptions opt) =>\n    ctx.Request.Cookies.ContainsKey(opt.Cookie.Name);","tryCatchPattern":"try {\n    await antiforgery.ValidateRequestAsync(httpContext);\n} catch (AntiforgeryValidationException ex) when (ex.Message.Contains(\"not present\")) {\n    // cookie/token missing - return 400 / challenge the client to obtain tokens\n    return Results.BadRequest(ex.Message);\n}","preventionTips":["Issue the antiforgery cookie via GetAndStoreTokensAsync on a GET before unsafe verbs.","Send credentials cross-origin (credentials:'include') and set CORS + SameSite appropriately.","Ensure options.Cookie.Name/Secure/SameSite allow the cookie to travel with the request."],"tags":["csharp","dotnet","aspnetcore","antiforgery","security","csrf","cookies"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}