Update security.md (#28433)

pull/28434/head
jimolinah 2023-02-17 10:32:19 +01:00 committed by GitHub
parent 0694f7db7b
commit aae31c5afc
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 1 additions and 1 deletions

View File

@ -101,7 +101,7 @@ In the following code, <xref:Microsoft.Extensions.DependencyInjection.PolicyServ
- Adds authorization-related services to the DI container. - Adds authorization-related services to the DI container.
- Returns an <xref:Microsoft.AspNetCore.Authorization.AuthorizationBuilder> that can be used to directly register authentication policies. - Returns an <xref:Microsoft.AspNetCore.Authorization.AuthorizationBuilder> that can be used to directly register authentication policies.
The code creates a new authorization policy, named `policy_greetings`, that encapsulates two authorization requirements: The code creates a new authorization policy, named `admin_greetings`, that encapsulates two authorization requirements:
- A role-based requirement via <xref:Microsoft.AspNetCore.Authorization.AuthorizationPolicyBuilder.RequireRole%2A> for users with an `admin` role. - A role-based requirement via <xref:Microsoft.AspNetCore.Authorization.AuthorizationPolicyBuilder.RequireRole%2A> for users with an `admin` role.
- A claim-based requirement via <xref:Microsoft.Identity.Web.PolicyBuilderExtensions.RequireScope%2A> that the user must provide a `greetings_api` scope. - A claim-based requirement via <xref:Microsoft.Identity.Web.PolicyBuilderExtensions.RequireScope%2A> that the user must provide a `greetings_api` scope.