dotnet/aspnetcore · error · InvalidOperationException
Authorization requires a cascading parameter of type Task
Error message
Authorization requires a cascading parameter of type Task<AuthenticationState>. Consider using CascadingAuthenticationState to supply this.
What it means
Thrown by AuthorizeViewCore.OnParametersSetAsync when the AuthenticationState cascading parameter is null. AuthorizeView/AuthorizeRouteView need a Task<AuthenticationState> supplied via a CascadingAuthenticationState ancestor to evaluate authorization.
Solutions
- Wrap the root component (e.g. <Router>) in <CascadingAuthenticationState>...</CascadingAuthenticationState>.
- Or call builder.Services.AddCascadingAuthenticationState() (preferred for .NET 8+) so the cascade is registered globally.
- Ensure services.AddAuthorizationCore() and the relevant authentication provider (e.g. AddAuthentication) are registered.
- For Blazor WebAssembly, confirm CustomAuth/Identity provider setup in Program.cs.
Example fix
// before: no cascading auth state in Program.cs
builder.Services.AddAuthorizationCore();
// after: register the cascading provider
builder.Services.AddAuthorizationCore();
builder.Services.AddCascadingAuthenticationState();
<!-- or wrap in App.razor/Routes.razor -->
<CascadingAuthenticationState>
<Router AppAssembly="@typeof(Program).Assembly">...</Router>
</CascadingAuthenticationState> Defensive patterns
Strategy: validation
Validate before calling
// Program.cs builder.Services.AddAuthorizationCore(); builder.Services.AddCascadingAuthenticationState();
Prevention
- Register AddCascadingAuthenticationState() during project scaffolding.
- Add a root-level test that renders AuthorizeView and asserts no exception.
- Document the requirement in the project template readme.
When it happens
Trigger: Rendering <AuthorizeView> (or using [CascadingParameter] Task<AuthenticationState>) without a <CascadingAuthenticationState> wrapper in the component tree, or without AddCascadingAuthenticationState registered in DI.
Common situations: Adding AuthorizeView to a Blazor Server/WebAssembly app that hasn't wired up authentication; forgetting to wrap App.razor/Routes.razor in <CascadingAuthenticationState>; missing services.AddAuthorizationCore() / AddCascadingAuthenticationState() in Program.cs.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- The authorization data specifies an authentication scheme…
- Do not specify both 'Authorized' and 'ChildContent'.
- ' ' is flagged with SingleDelivery, but the selected…
- The parameter ' ' for component ' ' does not allow null or…
- The type ' ' does not have an associated TypeConverter that…
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/01f84d7cc835852b.
Report an issue: GitHub.
Appendix: source
Thrown at src/Components/Authorization/src/AuthorizeViewCore.cs:85
{
builder.AddContent(0, NotAuthorized?.Invoke(currentAuthenticationState!));
}
}
/// <inheritdoc />
protected override async Task OnParametersSetAsync()
{
// We allow 'ChildContent' for convenience in basic cases, and 'Authorized' for symmetry
// with 'NotAuthorized' in other cases. Besides naming, they are equivalent. To avoid
// confusion, explicitly prevent the case where both are supplied.
if (ChildContent != null && Authorized != null)
{
throw new InvalidOperationException($"Do not specify both '{nameof(Authorized)}' and '{nameof(ChildContent)}'.");
}
if (AuthenticationState == null)
{
throw new InvalidOperationException($"Authorization requires a cascading parameter of type Task<{nameof(AuthenticationState)}>. Consider using {typeof(CascadingAuthenticationState).Name} to supply this.");
}
// Clear the previous result of authorization
// This will cause the Authorizing state to be displayed until the authorization has been completed
isAuthorized = null;
currentAuthenticationState = await AuthenticationState;
isAuthorized = await IsAuthorizedAsync(currentAuthenticationState.User);
}
/// <summary>
/// Gets the data required to apply authorization rules.
/// </summary>
protected abstract IAuthorizeData[]? GetAuthorizeData();
internal virtual object[]? GetAuthorizationMetadata() => GetAuthorizeData();
private async Task<bool> IsAuthorizedAsync(ClaimsPrincipal user)View on GitHub (pinned to 3600ca084e)