Can I remove [IgnoreAntiforgeryToken] from error.cshtml.cs?

Viewed 44

When you start a new blazor server project, the page error.cshtml and error.cshtml.cs was created automatically (it's default when you create a new project).

But the security team are complainging about the [IgnoreAntiforgeryToken] they said..

Cross-Site Request Forgery (CSRF) Disabling CSRF protections is security sensitive HIGH CRITICAL 1

So, the question is: What if I just comment that line on this file ? what is the consequences ? this is a blazor-server project.

Bellow is the code...


using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Mvc.RazorPages;
using System.Diagnostics;

namespace IsraPharmaExp.Pages
{
    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]
    [IgnoreAntiforgeryToken] // This is the line. What if I just comment it ?
    public class ErrorModel : PageModel
    {
        public string? RequestId { get; set; }

        public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);

        private readonly ILogger<ErrorModel> _logger;

        public ErrorModel(ILogger<ErrorModel> logger)
        {
            _logger = logger;
        }

        public void OnGet()
        {
            RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier;
        }
    }
}
0 Answers
Related