Enable hot reloading for Blazor inside an iframe - #51006
Conversation
Co-authored-by: javiercn <6995051+javiercn@users.noreply.github.com>
b5cd38b to
738eccb
Compare
There was a problem hiding this comment.
Pull Request Overview
This PR enables hot reload functionality for Blazor applications running inside iframes by expanding the accepted Sec-Fetch-Dest header values in the browser refresh middleware. Previously, only "document" requests would trigger script injection, but iframe contexts use "frame" or "iframe" values, preventing hot reload from working in tools like Blazing Story.
- Updated
IsBrowserDocumentRequestmethod to accept "frame" and "iframe"Sec-Fetch-Destheader values - Added comprehensive test coverage for the new frame/iframe functionality
- Maintained existing behavior for all other header values
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| src/BuiltInTools/BrowserRefresh/BrowserRefreshMiddleware.cs | Modified header validation logic to include frame and iframe requests |
| test/Microsoft.AspNetCore.Watch.BrowserRefresh.Tests/BrowserRefreshMiddlewareTest.cs | Added new test case to verify frame/iframe requests return true |
|
/backport to release/10.0.3xx |
|
Started backporting to |
|
/backport to release/10.0.1xx |
|
Started backporting to |
|
@lewing 2xx as well? though you shouldn't need it since sdk does inter-branch merges so the 3xx one isn't needed either because it'll flow from 1xx |
iirc 3xx doesn't require servicing approval so I hedged |
Fixes hot reload functionality for Blazor applications running inside iframes by allowing
Sec-Fetch-Dest: frameandSec-Fetch-Dest: iframerequests to trigger browser refresh script injection.Problem
Hot Reload on Blazor apps doesn't work inside iframes because the
BrowserRefreshMiddleware.IsBrowserDocumentRequest()method only accepts requests withSec-Fetch-Dest: document. Requests from iframes useSec-Fetch-Dest: frameorSec-Fetch-Dest: iframe, causing the middleware to reject them and skip script injection.This prevents hot reload from working in scenarios like:
Solution
Updated the
IsBrowserDocumentRequestmethod to also accept "frame" and "iframe" values for theSec-Fetch-Destheader, in addition to the existing "document" value. This allows the browser refresh middleware to inject hot reload scripts into iframe-embedded Blazor applications.The change is minimal and surgical - it only adds two additional string comparisons to the existing validation logic without affecting any other functionality.
Testing
truewhile other values like "serviceworker" still returnfalseAddresses the "escape hatch" API request mentioned in the original issue for enabling hot reloading in iframe scenarios.
Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.