{"record":{"id":"726246468c8e928a","repo":"dotnet/aspnetcore","slug":"the-authorization-data-specifies-an-authentication","errorCode":null,"errorMessage":"The authorization data specifies an authentication scheme with value '{0}'. Authentication schemes cannot be specified for components.","messagePattern":"The authorization data specifies an authentication scheme with value '(.+?)'\\. Authentication schemes cannot be specified for components\\.","errorType":"exception","errorClass":"NotSupportedException","httpStatus":null,"severity":"error","filePath":"src/Components/Authorization/src/AuthorizeViewCore.cs","lineNumber":135,"sourceCode":"        {\n            // The metadata contained nothing that contributes to a policy.\n            return true;\n        }\n\n        var result = await AuthorizationService.AuthorizeAsync(user, Resource, policy);\n        return result.Succeeded;\n    }\n\n    private static void EnsureNoAuthenticationSchemeSpecified(object[] metadata)\n    {\n        // It's not meaningful to specify a nonempty scheme, since by the time Components\n        // authorization runs, we already have a specific ClaimsPrincipal (we're stateful).\n        // To avoid any confusion, ensure the developer isn't trying to specify a scheme.\n        for (var i = 0; i < metadata.Length; i++)\n        {\n            if (metadata[i] is IAuthorizeData entry && !string.IsNullOrEmpty(entry.AuthenticationSchemes))\n            {\n                throw new NotSupportedException($\"The authorization data specifies an authentication scheme with value '{entry.AuthenticationSchemes}'. Authentication schemes cannot be specified for components.\");\n            }\n        }\n    }\n}\n","sourceCodeStart":117,"sourceCodeEnd":140,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Components/Authorization/src/AuthorizeViewCore.cs#L117-L140","documentation":"Thrown by AuthorizeViewCore.EnsureNoAuthenticationSchemeSpecified when the authorization metadata (an IAuthorizeData, e.g. from [Authorize] or <AuthorizeView Roles=...>) carries a non-empty AuthenticationSchemes value. Blazor components already operate on a resolved ClaimsPrincipal, so specifying which auth scheme to use is meaningless and is rejected.","triggerScenarios":"Applying [Authorize(AuthenticationSchemes = \"...\")] to a Blazor component (page/route), or setting AuthorizeView.AuthenticationSchemes, or any IAuthorizeData where AuthenticationSchemes is non-empty in the component authorization pipeline.","commonSituations":"Reusing an MVC-style [Authorize(AuthenticationSchemes = \"Bearer\")] attribute on a Razor component; pasting controller authorization attributes onto a Blazor page; mapping a policy that implies a scheme.","solutions":["Remove the AuthenticationSchemes argument from [Authorize] on Blazor components.","Use a policy/roles instead: [Authorize(Roles = \"admin\")] or [Authorize(Policy = \"...\")].","If you genuinely need a scheme, resolve the principal at the host/hub level and let it cascade into the component rather than declaring a scheme in component metadata."],"exampleFix":"<!-- before: scheme on a component -->\n@attribute [Authorize(AuthenticationSchemes = \"Bearer\")]\n\n<!-- after: use roles/policy only -->\n@attribute [Authorize(Policy = \"CanViewDashboard\")]","handlingStrategy":"validation","validationCode":"// At startup, scan component attributes for IAuthorizeData with a non-empty AuthenticationSchemes and fail fast.\nforeach (var a in componentAuthorizes) { if (!string.IsNullOrEmpty(a.AuthenticationSchemes)) throw new InvalidOperationException(\"Components cannot specify schemes.\"); }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep MVC controller auth attributes and Blazor component auth attributes in separate folders/imports.","Use [Authorize(Policy=...)] / [Authorize(Roles=...)] for components.","Code review [Authorize(...)] usages on .razor files."],"tags":["blazor","aspnetcore","authorization","authentication","components"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}