{"record":{"id":"7aff7f4d93bd5236","repo":"dotnet/aspnetcore","slug":"the-antiforgery-system-has-the-configuration-value","errorCode":null,"errorMessage":"The antiforgery system has the configuration value {optionName} = {value}, but the current request is not an SSL request.","messagePattern":"The antiforgery system has the configuration value (.+?) = (.+?), but the current request is not an SSL request\\.","errorType":"exception","errorClass":"InvalidOperationException","httpStatus":null,"severity":"error","filePath":"src/Antiforgery/src/Internal/DefaultAntiforgery.cs","lineNumber":256,"sourceCode":"        {\n            // Persist the new cookie if it is not null.\n            _tokenStore.SaveCookieToken(httpContext, cookieToken);\n        }\n\n        if (!_options.SuppressXFrameOptionsHeader && !httpContext.Response.Headers.ContainsKey(HeaderNames.XFrameOptions))\n        {\n            // Adding X-Frame-Options header to prevent ClickJacking. See\n            // http://tools.ietf.org/html/draft-ietf-websec-x-frame-options-10\n            // for more information.\n            httpContext.Response.Headers.XFrameOptions = \"SAMEORIGIN\";\n        }\n    }\n\n    private void CheckSSLConfig(HttpContext context)\n    {\n        if (_options.Cookie.SecurePolicy == CookieSecurePolicy.Always && !context.Request.IsHttps)\n        {\n            throw new InvalidOperationException(Resources.FormatAntiforgery_RequiresSSL(\n                string.Join(\".\", nameof(AntiforgeryOptions), nameof(AntiforgeryOptions.Cookie), nameof(CookieBuilder.SecurePolicy)),\n                nameof(CookieSecurePolicy.Always)));\n        }\n    }\n\n    private static IAntiforgeryFeature GetAntiforgeryFeature(HttpContext httpContext)\n    {\n        var antiforgeryFeature = httpContext.Features.Get<IAntiforgeryFeature>();\n        if (antiforgeryFeature is null)\n        {\n            antiforgeryFeature = new AntiforgeryFeature();\n            httpContext.Features.Set(antiforgeryFeature);\n        }\n\n        return antiforgeryFeature;\n    }\n\n    private IAntiforgeryFeature GetCookieTokens(HttpContext httpContext)","sourceCodeStart":238,"sourceCodeEnd":274,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Antiforgery/src/Internal/DefaultAntiforgery.cs#L238-L274","documentation":"Thrown in CheckSSLConfig when the antiforgery cookie is configured with CookieSecurePolicy.Always but the current request is not HTTPS. The cookie policy demands an encrypted channel, so the validator refuses to operate over plain HTTP. It is an InvalidOperationException indicating a deployment/configuration mismatch.","triggerScenarios":"AntiforgeryOptions.Cookie.SecurePolicy == CookieSecurePolicy.Always and a request arrives where context.Request.IsHttps is false (http:// URL, or HTTPS terminated upstream and not forwarded with the right headers).","commonSituations":"Running locally over http://localhost with SecurePolicy.Always; HTTPS terminated at a load balancer/reverse proxy without ForwardedHeaders configured so IsHttps reads false; cookie policy set globally to Always but a health/internal endpoint exposed over HTTP.","solutions":["Use HTTPS for the endpoint that performs antiforgery (set ASPNETCORE_URLS=https://, bind a dev cert, or terminate TLS at the edge correctly).","If HTTPS is terminated upstream, enable ForwardedHeaders middleware so IsHttps reflects the original scheme.","If plain HTTP is genuinely required in a trusted context, set Cookie.SecurePolicy to SameAsRequest or None (not recommended for production).","For local dev, launch the app with the https:// profile (dotnet run --launch-profile https) so IsHttps is true."],"exampleFix":"// before: HTTPS terminated at proxy but not forwarded\napp.UseAntiforgery(); // throws over http\n\n// after: forward upstream TLS info\napp.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedProto });","handlingStrategy":"validation","validationCode":"if (antiforgeryOptions.Cookie.SecurePolicy == CookieSecurePolicy.Always && !httpContext.Request.IsHttps) { /* reject/redirect to https before validation */ }","typeGuard":null,"tryCatchPattern":"try { CheckSSLConfig(httpContext); }\ncatch (InvalidOperationException) { httpContext.Response.Redirect(httpsUrl); return; }","preventionTips":["Always run antiforgery-protected endpoints over HTTPS, including local dev.","Configure ForwardedHeaders when TLS is terminated upstream.","Add a startup check that warns if SecurePolicy.Always is set but URLs lack https://.","Use the https launch profile in development."],"tags":["antiforgery","aspnetcore","ssl","security","configuration"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}