Blazor Server SignalR circuit authorization caching with revoked credentials
0 reputation · 12 May 2020, 20:14 UTC
Authorization caching in long-lived SignalR circuits
Blazor Server maintains a persistent SignalR circuit for each connected client. When policy-based authorization is applied to components, the authorization decision is evaluated during the initial render and then cached for the lifetime of that circuit. The authentication cookie issued by ASP.NET Core Identity is validated on each hub invocation, but the cookie only carries an expiration timestamp—it does not reflect server-side changes such as account lockout, role removal, or user deletion.
This creates a window where a client holding a still-valid cookie continues to operate with stale privileges until the cookie naturally expires or the circuit is terminated. The framework does not provide a built-in mechanism to push revocation events from the identity store to active circuits, nor does it automatically re-evaluate authorization policies after the initial render.
Questions
- What is the recommended pattern for forcing re-evaluation of component-level authorization policies on each SignalR hub invocation without tearing down the circuit?
- Can a custom
AuthorizeHubFilterorCircuitHandlerreliably callUserManager.GetUserAsyncon every invocation to close the stale-privilege gap, and what are the performance implications at scale? - Is there a supported way to signal credential revocation to specific connected clients so they can proactively re-authenticate?