Only allow PublicAuthOptions to be accessed in Razor pages #3623
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
GetAuthOptions had a return type of PublicAuthOptions, but was returning all auth options (since AuthOptions extends PublicAuthOptions, the types are compatible). In practice this doesn't leak anything to the Razor pages unless the object is serialized, but since the entire purpose of PublicAuthOptions is to limit what is provided to the Razor pages, it seems more complete to not even allow the secrets to be available in the scope of the templates.
@pmachapman What do you think? Too pedantic, or reasonable change?
This change is