Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article highlights the most significant changes in ASP.NET Core in .NET 10 with links to relevant documentation.
Blazor
This section describes new features for Blazor.
New and updated Blazor Web App security samples
We've added and updated the Blazor Web App security samples linked in the following articles:
- Secure an ASP.NET Core Blazor Web App with OpenID Connect (OIDC)
- Secure an ASP.NET Core Blazor Web App with Microsoft Entra ID
- Secure an ASP.NET Core Blazor Web App with Windows Authentication
All of our OIDC and Entra sample solutions now include a separate web API project (MinimalApiJwt) to demonstrate how to configure and call an external web API securely. Calling web APIs is demonstrated with a token handler and named HTTP client for an OIDC identity provider or Microsoft Identity Web packages/API for Microsoft Entra ID.
The sample solutions are configured in C# code in their Program files. To configure the solutions from app settings files (for example, appsettings.json) see the new Supply configuration with the JSON configuration provider (app settings) section of the OIDC or Entra articles.
Our Entra article and sample apps also include new guidance on the following approaches:
- How to use an encrypted distributed token cache for web farm hosting scenarios.
- How to use Azure Key Vault with Azure Managed Identities for data protection.
QuickGrid RowClass parameter
Apply a stylesheet class to a row of the grid based on the row item using the new RowClass parameter. In the following example, the GetRowCssClass method is called on each row to conditionally apply a stylesheet class based on the row item:
...
@code {
private string GetRowCssClass(MyGridItem item) =>
item.IsArchived ? "row-archived" : null;
}
For more information, see ASP.NET Core Blazor `QuickGrid` component.
Blazor script as static web asset
In prior releases of .NET, the Blazor script is served from an embedded resource in the ASP.NET Core shared framework. In .NET 10 or later, the Blazor script is served as a static web asset with automatic compression and fingerprinting.
The Blazor script (blazor.web.js or blazor.server.js) is included by the framework if the project contains at least one Razor component file (.razor). If your app requires the Blazor script but doesn't contain at least one component, add the following MSBuild property to the app's project file to force unconditional script inclusion:
true
For more information, see the following resources:
Route template highlights
The [Route] attribute now supports route syntax highlighting to help visualize the structure of the route template:

NavigateTo no longer scrolls to the top for same-page navigations
Previously, NavigationManager.NavigateTo scrolled to the top of the page for same-page navigations. This behavior has been changed in .NET 10 so that the browser no longer scrolls to the top of the page when navigating to the same page. This means the viewport is no longer reset when making updates to the address for the current page, such as changing the query string or fragment.
Reconnection UI component added to the Blazor Web App project template
The Blazor Web App project template now includes a ReconnectModal component, including collocated stylesheet and JavaScript files, for improved developer control over the reconnection UI when the client loses the WebSocket connection to the server. The component doesn't insert styles programmatically, ensuring compliance with stricter Content Security Policy (CSP) settings for the style-src policy. In prior releases, the default reconnection UI was created by the framework in a way that could cause CSP violations. Note that the default reconnection UI is still used as fallback when the app doesn't define the reconnection UI, such as by using the project template's ReconnectModal component or a similar custom component.
New reconnection UI features:
- Apart from indicating the reconnection state by setting a specific CSS class on the reconnection UI element, the new
components-reconnect-state-changedevent is dispatched for reconnection state changes. - Code can better differentiate the stages of the reconnection process with the new reconnection state "
retrying," indicated by both the CSS class and the new event.
For more information, see ASP.NET Core Blazor SignalR guidance.
Ignore the query string and fragment when using NavLinkMatch.All
The NavLink component now ignores the query string and fragment when using the NavLinkMatch.All value for the Match parameter. This means that the link retains the active class if the URL path matches but the query string or fragment change. To revert to the original behavior, use the Microsoft.AspNetCore.Components.Routing.NavLink.EnableMatchAllForQueryStringAndFragment AppContext switch set to true.
You can also override the ShouldMatch method on NavLink to customize the matching behavior:
public class CustomNavLink : NavLink
{
protected override bool ShouldMatch(string currentUriAbsolute)
{
// Custom matching logic
}
}
For more information, see ASP.NET Core Blazor navigation.
Close QuickGrid column options
You can now close the QuickGrid column options UI using the new HideColumnOptionsAsync method.
The following example uses the HideColumnOptionsAsync method to close the column options UI as soon as the title filter is applied:
movieGrid.HideColumnOptionsAsync())" />
@code {
private QuickGrid? movieGrid;
private string titleFilter = string.Empty;
private IQueryable movies = new List { ... }.AsQueryable();
private IQueryable filteredMovies =>
movies.Where(m => m.Title!.Contains(titleFilter));
}
HttpClient response streaming enabled by default
In prior Blazor releases, response streaming for HttpClient requests was opt-in. Now, response streaming is enabled by default.
This is a breaking change because calling HttpContent.ReadAsStreamAsync for an HttpResponseMessage.Content (response.Content.ReadAsStreamAsync()) returns a BrowserHttpReadStream and no longer a MemoryStream. BrowserHttpReadStream doesn't support synchronous operations, such as Stream.Read(Span. If your code uses synchronous operations, you can opt-out of response streaming or copy the Stream into a MemoryStream yourself.
To opt-out of response streaming globally, use either of the following approaches:
Add the
property to the project file with a value offalse:false Set the
DOTNET_WASM_ENABLE_STREAMING_RESPONSEenvironment variable tofalseor0.
To opt-out of response streaming for an individual request, set SetBrowserResponseStreamingEnabled to false on the HttpRequestMessage (requestMessage in the following example):
requestMessage.SetBrowserResponseStreamingEnabled(false);
For more information, see HttpClient and HttpRequestMessage with Fetch API request options (Call web API article).
Client-side fingerprinting
The release of .NET 9 introduced server-side fingerprinting of static assets in Blazor Web Apps with the introduction of Map Static Assets routing endpoint conventions (MapStaticAssets), the ImportMap component, and the ComponentBase.Assets property (@Assets["..."]) to resolve fingerprinted JavaScript (JS) modules. For .NET 10, you can opt-into client-side fingerprinting of JS modules for standalone Blazor WebAssembly apps.
In standalone Blazor WebAssembly apps during build and publish, the framework overrides placeholders in index.html with values computed during build to fingerprint static assets. A fingerprint is placed into the blazor.webassembly.js script file name.
The following markup must be present in the wwwroot/index.html file to adopt the fingerprinting feature:
...
+
...
-
+