{"record":{"id":"8572b8b3da9a3a31","repo":"dotnet/aspnetcore","slug":"do-not-specify-both-authorized-and-childcontent","errorCode":null,"errorMessage":"Do not specify both 'Authorized' and 'ChildContent'.","messagePattern":"Do not specify both 'Authorized' and 'ChildContent'\\.","errorType":"exception","errorClass":"InvalidOperationException","httpStatus":null,"severity":"error","filePath":"src/Components/Authorization/src/AuthorizeViewCore.cs","lineNumber":80,"sourceCode":"        {\n            var authorized = Authorized ?? ChildContent;\n            builder.AddContent(0, authorized?.Invoke(currentAuthenticationState!));\n        }\n        else\n        {\n            builder.AddContent(0, NotAuthorized?.Invoke(currentAuthenticationState!));\n        }\n    }\n\n    /// <inheritdoc />\n    protected override async Task OnParametersSetAsync()\n    {\n        // We allow 'ChildContent' for convenience in basic cases, and 'Authorized' for symmetry\n        // with 'NotAuthorized' in other cases. Besides naming, they are equivalent. To avoid\n        // confusion, explicitly prevent the case where both are supplied.\n        if (ChildContent != null && Authorized != null)\n        {\n            throw new InvalidOperationException($\"Do not specify both '{nameof(Authorized)}' and '{nameof(ChildContent)}'.\");\n        }\n\n        if (AuthenticationState == null)\n        {\n            throw new InvalidOperationException($\"Authorization requires a cascading parameter of type Task<{nameof(AuthenticationState)}>. Consider using {typeof(CascadingAuthenticationState).Name} to supply this.\");\n        }\n\n        // Clear the previous result of authorization\n        // This will cause the Authorizing state to be displayed until the authorization has been completed\n        isAuthorized = null;\n\n        currentAuthenticationState = await AuthenticationState;\n        isAuthorized = await IsAuthorizedAsync(currentAuthenticationState.User);\n    }\n\n    /// <summary>\n    /// Gets the data required to apply authorization rules.\n    /// </summary>","sourceCodeStart":62,"sourceCodeEnd":98,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Components/Authorization/src/AuthorizeViewCore.cs#L62-L98","documentation":"Thrown by AuthorizeViewCore.OnParametersSetAsync when a developer supplies both the ChildContent render fragment (the default unnamed child) and the explicit Authorized render fragment. They are functionally equivalent for the authorized case, so supplying both is ambiguous and rejected to prevent confusion.","triggerScenarios":"Authoring a <AuthorizeView> (or derived AuthorizeViewRole/Policy) that has both inline body content (ChildContent) and an <Authorized> child template inside the same component.","commonSituations":"Copy-pasting examples that combine the convenience inline form with the <Authorized> template; migrating from inline-only to template-based and forgetting to remove the inline content; tooling that auto-generates a default fragment.","solutions":["Remove one of the two: either delete the inline body and keep <Authorized>...</Authorized>, or delete the <Authorized> template and rely on the inline content.","Use <Authorized>/<Authorizing>/<NotAuthorized> as a set for full control, and leave the inline content empty.","Validate the .razor markup renders in the designer / dotnet build before running."],"exampleFix":"<!-- before: both inline and Authorized -->\n<AuthorizeView>\n    <p>Welcome back!</p>\n    <Authorized><p>Welcome back!</p></Authorized>\n</AuthorizeView>\n\n<!-- after: keep only Authorized -->\n<AuthorizeView>\n    <Authorized><p>Welcome back!</p></Authorized>\n</AuthorizeView>","handlingStrategy":"validation","validationCode":"<!-- In the .razor file, ensure only one of inline body or <Authorized> is present. -->\n@if (authorizeViewChildContent != null && authorizeViewAuthorized != null) { throw new InvalidOperationException(\"Pick one\"); }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Standardize on the <Authorized>/<NotAuthorized> template style for AuthorizeView.","Review .razor diffs in code review for accidental dual fragments.","Compile-blazor at CI to catch markup errors early."],"tags":["blazor","aspnetcore","authorization","components","configuration"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}