Skip to content

Updating doc to set correct expectations when using restrictive XAML mode in WPF - #2278

Open
dipeshmsft wants to merge 2 commits into
mainfrom
user/dipesh/restrictivexamlreader-doc-update
Open

Updating doc to set correct expectations when using restrictive XAML mode in WPF#2278
dipeshmsft wants to merge 2 commits into
mainfrom
user/dipesh/restrictivexamlreader-doc-update

Conversation

@dipeshmsft

@dipeshmsft dipeshmsft commented Aug 21, 2026

Copy link
Copy Markdown
Member

Summary

Reverting the security guidance added in #2261 for loading untrusted XAML, BAML and XPS packages. Most of the added changes are redundant as the expectations for the above scenario is already present in the doc. However, retaining the doc changes on restrictive XAML reader mode in WPF as the latest findings suggested that lack of documentation regarding this mode is setting wrong expectations for the developers.


Internal previews

File Preview link
dotnet-desktop-guide/wpf/security-wpf.md dotnet-desktop-guide/wpf/security-wpf
dotnet-desktop-guide/xaml-services/security-considerations.md dotnet-desktop-guide/xaml-services/security-considerations

Copilot AI lite review requested due to automatic review settings August 21, 2026 10:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates WPF and .NET XAML Services security documentation by reverting the broader “loading untrusted markup” guidance introduced in PR #2261, while keeping and emphasizing guidance that clarifies what WPF’s restrictive XAML reader mode does—and does not—guarantee.

Changes:

  • Removed the recently added “untrusted XAML/binary XAML/restrictive reader” guidance block from the .NET XAML Services security considerations article.
  • Removed the “Loading Untrusted XAML, BAML, and XPS Content” section from the WPF security article.
  • Added a focused “Restrictive XAML reader mode” subsection under the existing loose XAML sandboxing section to set expectations about process/boundary behavior.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
dotnet-desktop-guide/xaml-services/security-considerations.md Reverts the PR #2261 guidance block and updates metadata date.
dotnet-desktop-guide/wpf/security-wpf.md Removes the “untrusted markup” section, adds restrictive reader expectations, and refreshes the in-article section list.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread dotnet-desktop-guide/wpf/security-wpf.md Outdated
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants