dotnet/aspnetcore · error · InvalidOperationException

Authorization requires a cascading parameter of type Task

Error message

Authorization requires a cascading parameter of type Task<AuthenticationState>. Consider using CascadingAuthenticationState to supply this.

What it means

Thrown by AuthorizeViewCore.OnParametersSetAsync when the AuthenticationState cascading parameter is null. AuthorizeView/AuthorizeRouteView need a Task<AuthenticationState> supplied via a CascadingAuthenticationState ancestor to evaluate authorization.

Solutions

  1. Wrap the root component (e.g. <Router>) in <CascadingAuthenticationState>...</CascadingAuthenticationState>.
  2. Or call builder.Services.AddCascadingAuthenticationState() (preferred for .NET 8+) so the cascade is registered globally.
  3. Ensure services.AddAuthorizationCore() and the relevant authentication provider (e.g. AddAuthentication) are registered.
  4. For Blazor WebAssembly, confirm CustomAuth/Identity provider setup in Program.cs.

Example fix

// before: no cascading auth state in Program.cs
builder.Services.AddAuthorizationCore();

// after: register the cascading provider
builder.Services.AddAuthorizationCore();
builder.Services.AddCascadingAuthenticationState();

<!-- or wrap in App.razor/Routes.razor -->
<CascadingAuthenticationState>
    <Router AppAssembly="@typeof(Program).Assembly">...</Router>
</CascadingAuthenticationState>
Defensive patterns

Strategy: validation

Validate before calling

// Program.cs
builder.Services.AddAuthorizationCore();
builder.Services.AddCascadingAuthenticationState();

Prevention

When it happens

Trigger: Rendering <AuthorizeView> (or using [CascadingParameter] Task<AuthenticationState>) without a <CascadingAuthenticationState> wrapper in the component tree, or without AddCascadingAuthenticationState registered in DI.

Common situations: Adding AuthorizeView to a Blazor Server/WebAssembly app that hasn't wired up authentication; forgetting to wrap App.razor/Routes.razor in <CascadingAuthenticationState>; missing services.AddAuthorizationCore() / AddCascadingAuthenticationState() in Program.cs.

Understand the failure class

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/01f84d7cc835852b. Report an issue: GitHub.

Appendix: source

Thrown at src/Components/Authorization/src/AuthorizeViewCore.cs:85

        {
            builder.AddContent(0, NotAuthorized?.Invoke(currentAuthenticationState!));
        }
    }

    /// <inheritdoc />
    protected override async Task OnParametersSetAsync()
    {
        // We allow 'ChildContent' for convenience in basic cases, and 'Authorized' for symmetry
        // with 'NotAuthorized' in other cases. Besides naming, they are equivalent. To avoid
        // confusion, explicitly prevent the case where both are supplied.
        if (ChildContent != null && Authorized != null)
        {
            throw new InvalidOperationException($"Do not specify both '{nameof(Authorized)}' and '{nameof(ChildContent)}'.");
        }

        if (AuthenticationState == null)
        {
            throw new InvalidOperationException($"Authorization requires a cascading parameter of type Task<{nameof(AuthenticationState)}>. Consider using {typeof(CascadingAuthenticationState).Name} to supply this.");
        }

        // Clear the previous result of authorization
        // This will cause the Authorizing state to be displayed until the authorization has been completed
        isAuthorized = null;

        currentAuthenticationState = await AuthenticationState;
        isAuthorized = await IsAuthorizedAsync(currentAuthenticationState.User);
    }

    /// <summary>
    /// Gets the data required to apply authorization rules.
    /// </summary>
    protected abstract IAuthorizeData[]? GetAuthorizeData();

    internal virtual object[]? GetAuthorizationMetadata() => GetAuthorizeData();

    private async Task<bool> IsAuthorizedAsync(ClaimsPrincipal user)

View on GitHub (pinned to 3600ca084e)