Implement IEndpointMetadataProvider on Result types like Forbid, Unauthorized, etc
See original GitHub issueRecently, I noticed some types at https://github.com/dotnet/aspnetcore/tree/main/src/Http/Http.Results/src are not implementing IEndpointMetadataProvider.PopulateMetadata(...). Doing so would allow types like ForbidHttpResult and UnauthorizedHttpResult to shown up in Swagger/OpenAPI when used.
Issue Analytics
- State:
- Created 9 months ago
- Comments:8 (8 by maintainers)
 Top Results From Across the Web
Top Results From Across the Web
How to return Unathorized from .Net Core Web API
Since StatusCode() and Unauthorized() return an ActionResult, you'll want to change your action's return type to IActionResult instead.
Read more >ASP.NET Core updates in .NET 7 Preview 4
IEndpointMetadataProvider can be implemented by types either returned from a route handler, or accepted by a route handler as a parameter.
Read more >Minimal APIs in .NET 6
Controller-based APIs have been around for a long time, but .NET 6 changes everything with a new option. Shawn shows you how it...
Read more >Asp.Net Core Action Results Explained - Hamid Mosalla
This post explains in detail how Asp.Net Core action results works, what each one of them does and when and why to use...
Read more > Top Related Medium Post
Top Related Medium Post
No results found
 Top Related StackOverflow Question
Top Related StackOverflow Question
No results found
 Troubleshoot Live Code
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free Top Related Reddit Thread
Top Related Reddit Thread
No results found
 Top Related Hackernoon Post
Top Related Hackernoon Post
No results found
 Top Related Tweet
Top Related Tweet
No results found
 Top Related Dev.to Post
Top Related Dev.to Post
No results found
 Top Related Hashnode Post
Top Related Hashnode Post
No results found

There are 2 things that typed results do:
I think we should do this for
UnauthorizedHttpResultas the workaround currently is to fallback to manual produces metadata.ForbidHttpResultis a bit trickier because it relies on the authentication handler implementation ofForbid. We might need another result type here that’s purely a 403 without going through the authN system.If there are situations where people want to avoid advertising the 401 in their APIs after this change, we’d need a way to suppress this metadata, but also keep the type safety. I don’t know how big of a deal this is today or how easy it needs to be though.
This issue has been automatically marked as stale because it has been marked as requiring author feedback but has not had any activity for 4 days. It will be closed if no further activity occurs within 3 days of this comment. If it is closed, feel free to comment when you are able to provide the additional information and we will re-investigate.
See our Issue Management Policies for more information.