Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
162448 stories
·
33 followers

What is middleware in ASP.NET Core and the gotchas

1 Share

What is middleware in ASP.NET Core and the gotchas
6 minutes by David Grace

Middleware in ASP.NET Core runs on every HTTP request and response. You can write it as a class, but watch out for common mistakes. Forgetting to call next stops the rest of the pipeline from running. Scoped services must be injected into InvokeAsync, not the constructor, since middleware itself lives for the whole app lifetime. You also cannot modify a response after it has started, and background tasks need their own fresh scope to avoid using disposed services.

Beyond grep: Testing codebase memory MCP on .NET
12 minutes by Marek Sirkovský

Most AI coding tools waste tokens by scanning entire codebases when asked simple questions. Codebase Memory MCP tries to fix this by building a local knowledge graph of your code using tree-sitter, then exposing it to AI assistants through MCP. It works well for navigating within a single repository, but struggles with newer C# features and fails to trace relationships across repositories or NuGet package boundaries, a limitation shared by similar tools like GitNexus and Grafel.

Automatic CSRF protection based on fetch metadata headers
14 minutes by Andrew Lock

Andrew takes a look at the new Cross-Site Request Forgery protection added to ASP.NET Core in .NET 11 preview 6, which relies on the Fetch Metadata HTTP headers, instead of the "traditional" anti-CSRF tokens used in earlier versions of .NET Core. He talks about CSRF attacks, the existing protections in ASP.NET Core, discusses why a new approach is possible, and provides a brief recap on Fetch Metadata headers. He also shows how this works in ASP.NET Core as of .NET 11 preview 6, and finally, he takes a look at the implementation behind the feature, as well as dives into why the new feature doesn't really help you if you're using MVC or Razor Pages.

The hidden trap of fixed buffers in C#
7 minutes by Kevin Gosse

Adding a constructor to a struct with a fixed buffer changes how memory is initialized. Without a constructor, the compiler zeroes all memory automatically. With one, fixed buffers are exempt from that zeroing rule, so they retain whatever values were in memory before. This is by design in the C# spec but easy to miss. The fix is to manually clear the buffer inside the constructor.

Guid.CreateVersion7 is NOT a sequential guid for SQL server
5 minutes by Bart Wullems

Using version 7 GUIDs in SQL Server causes index fragmentation, just like random GUIDs do. This happens because SQL Server sorts GUID bytes in a different order than the RFC standard, putting the timestamp in the least significant position. Bart says the fix is to let EF Core or SQL Server generate the ID, or use a library that reorders the bytes to match SQL Server's sorting rules.

And the most popular article from the last issue was:

Read the whole story
alvinashcraft
11 seconds ago
reply
Pennsylvania, USA
Share this story
Delete

100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it

1 Share

One hundred days ago, Mozilla released Over The Edge 2.0, the second independent report from leading experts on deceptive design Dr. Harry Brignull and Cennydd Bowles, on how Windows, Edge, Bing, and Copilot are designed to steer people away from the browser they chose. 

We published the report, and the researchers published the evidence for anyone to analyze. 

Browsers are a powerful tool. So it’s no surprise that the history of the web has many examples of powerful platforms trying to deny people browser choice. Now, as AI reshapes our online experiences, the stakes couldn’t be higher. Browsers are a key distribution layer for AI tools and services, while still determining many of the privacy and security functionality people rely on every day. Steering people toward one browser can therefore shape which AI services reach users and the protections that come with it. 

We also shared the report with Microsoft and talked to them about the issues raised in the report. We knew that an immediate change was unlikely, but we hoped that, when faced with independent evidence of harmful design practices impacting Windows users, they would also want better for people.

Instead, it became clear that Microsoft will respect user choice only when it is forced to. It is important to think about what that means for a company whose operating system runs on more than a billion machines. Microsoft’s standard for respecting people’s choices is legal compliance. Not what’s best for its users. Not its own published principles. Not what’s technically feasible. Not even what it already does for users in Europe.

That’s the most shocking part. Not that Microsoft engages in such tactics – we’ve seen that before. It’s the fact that a better version of Windows already exists, and it is already available today – but only if you live in the European Economic Area (EEA), where the Digital Markets Act (DMA) forced the issue. If you live in the United States, India, the United Kingdom, or most other locations around the world, your experience and your freedom to choose for yourself are worse.

One hundred days later, here is what people outside of the EEA still get: 

  • The Windows 10 message “You’re almost done setting up your PC” uses tricky wording to pull people off the default they picked. 
  • Windows Search and Widgets open links in Edge instead of the browser set as default. 
  • Windows keeps Edge as the default for common browser file types like PDFs and SVG images, even after another browser has been set as default.

And people in the EEA also deserve better:

  • Edge remains pre-pinned to the taskbar; this seems to directly violate the “principled approach to app pinning and app defaults.” 
  • Copilot, Microsoft’s AI tool opens web links in a side-panel instead of the browser people chose, in every region tested, Europe included.
  • Windows Backup, the tool Microsoft uses to guide people through the migration to Windows 11, silently tries to set Edge as the default when it restores a PC and fails to properly bring the user’s own browser along. 

Most of the 2024 patterns are still there. The 2026 patterns are worse. Microsoft is using new surfaces like Copilot and the migration to Windows 11 to further undermine user choice.

Our ask has always been simple: First, give all Windows users the fairer designs that are live in the EEA – regardless of where they are located. Second, stop the remaining harmful design practices that persist in the EEA. That means:

  • Stopping the remaining harmful design tactics in the EEA and ship that standard worldwide.
  • Honoring people’s browser choice everywhere it is currently ignored, including Windows Search, Widgets, Copilot, and Windows Backup restoration. 
  • Applying Microsoft’s own 2023 app pinning principles to Edge itself. 

The Mozilla-commissioned report has never been about intent. It’s about accountability and Microsoft’s responsibility to stop undermining people’s choices. The practices we documented need to change. Statements about intent are not a substitute for action.

In the past 100 days, we’ve stopped waiting for Microsoft to act. Instead, we’ve stepped up public pressure on the company to respect people’s choices.

We are also taking the report’s findings to regulators and policymakers. In Europe, the DMA is the only thing that has moved Microsoft. Everywhere else, the lesson is the same: Microsoft ships only when a regulator requires fairer design. 

We hope that regulators in the US, the UK, India, and Brazil are paying attention. 

Microsoft can do better. It already has, for people in the EEA.

Until it does the same in all jurisdictions, we will keep pointing out the company’s choices and the impact they have on hundreds of millions of users who want something different.

The post 100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it appeared first on The Mozilla Blog.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete

What’s up, Docsy? Google’s docs project joins the Linux Foundation as AI agents become readers

1 Share
Docsy sticker on a laptop keyboard

Technical documentation is increasingly being read by AI agents, creating a new set of demands around how that information is published and structured. Docsy, the Google-created documentation project used by major cloud native projects, is now moving to the Linux Foundation as it adds features aimed specifically at that machine audience.

Erin McKean, senior developer relations engineer at Google and a member of the Docsy steering committee, announced the move in a keynote on Wednesday at the Linux Foundation’s Open Source Summit Europe in Prague.

First announced by Google in 2019, Docsy is an open source theme for the Hugo static site generator designed for technical documentation. It can be used for documentation generally, including proprietary projects, though it has become particularly widely used in the open source sphere. By the end of 2024, some 2,200 projects were using Docsy, with adopters across the Cloud Native Computing Foundation (CNCF) including Kubernetes, OpenTelemetry, gRPC and Jaeger.

That existing footprint inside Linux Foundation communities is part of the rationale behind the move. Speaking to The New Stack after the keynote, McKean says bringing Docsy into the foundation puts it closer to many of the projects already using it.

“Open source projects work best when they are close to the users,” she says.

“Open source projects work best when they are close to the users.”

AI needs good documentation, too

In her keynote, McKean focused heavily on the arrival of AI as a new consumer of technical documentation. Some technical writers, she acknowledges, are “a little bit salty” that it took AI to bring more resources to documentation. But the important part, she argues, is whether the information ultimately reaches and helps developers, regardless of the route it takes.

“When we’re making technical documentation, it really doesn’t matter how the information becomes useful to humans, as long as it does it.”

“When we’re making technical documentation, it really doesn’t matter how the information becomes useful to humans, as long as it does it,” McKean says. “If someone told me that there was evidence that said opera is the best way to reach your project users, I’d be writing operas.”

Docsy has already begun adapting its output for AI tools. Since version 0.15.0 in May, it can generate a Markdown copy of each page alongside the regular HTML, as well as an llms.txt file that gives AI tools an index of a site’s content. Both features are opt-in and remain experimental.

The broader idea is to give AI systems a more direct route to the information projects want them to use.

“You can redirect your LLMs and agents to the text that tells them how to use the project.”

“You can redirect your LLMs and agents to the text that tells them how to use the project,” McKean says.

Docsy has continued adding features around that basic concept. Version 0.16.0, released in July, included an upgrade guide written so that it could also be followed by an AI assistant, with conditions, steps and checks built into the instructions. And with version 0.17.0, released in August, Docsy went further on helping agents consume the documentation itself. Sites that enable llms.txt now automatically include a hidden directive at the top of each page pointing visiting agents toward the site’s llms.txt index. That feature is also experimental.

Scoring docs for agents

Next on the roadmap are “AF,” or agent-friendly, “documentation scores,” designed to give maintainers a way to assess how easily AI tools can find, navigate and consume their documentation. McKean says that should give projects a benchmark to work toward.

“You won’t have to guess,” she says. “You can measure how agent friendly your docs are.”

There is a more conventional payoff to better documentation too: fewer routine questions landing on maintainers. McKean says good docs can answer those questions before someone has to step in manually.

“When you have good docs, it reduces the number of questions that can be easily answered by documentation, reducing the burden on maintainers,” she says.

The post What’s up, Docsy? Google’s docs project joins the Linux Foundation as AI agents become readers appeared first on The New Stack.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete

Creating Agile Value Stream Visibility Without More Administration | Oluyomi Emmanuel

1 Share

Oluyomi Emmanuel: Creating Agile Value Stream Visibility Without More Administration

Read the full Show Notes and search through the world's largest audio library on Agile and Scrum directly on the Scrum Master Toolbox Podcast website: http://bit.ly/SMTP_ShowNotes.

 

"Transparency is not created by displaying more information. Transparency is created when people share enough meaning to interpret that information in the same way." - Oluyomi Emmanuel

 

Oluyomi's current challenge is helping an organization create end-to-end visibility and ownership across several value streams without turning the solution into another layer of administration. At first, the problem looked like a Jira hierarchy issue: initiatives, epics, stories, and tasks needed shared definitions. But the conversations exposed something deeper. Different groups used the same work item names to mean different things, and those differences made prioritization, dependency management, coordination, and reporting harder. Together with a colleague, Oluyomi framed the work as alignment experiments instead of a large rollout. One workshop asked what makes an initiative different from an epic, what information must exist before work moves forward, and when the next level of work should be created. The biggest tension was ownership, not terminology. A second experiment, a cross-value-stream visibility session, used real initiatives to expose overlapping work, unclear ownership, and weak links to outcomes. Vasco then pushed the conversation toward intake: perhaps the problem was not only shared meaning, but the absence of a single view of what the organization needs to do. Oluyomi's next experiment is linking initiatives to quarterly goals and OKRs to see what really deserves attention.

 

In this episode, we refer to value streams, OKRs, and portfolio management.

 

Self-reflection Question: Does your organization have one visible list of important work, or many competing lists with unclear ownership?

 

[The Scrum Master Toolbox Podcast Recommends]

🔥In the ruthless world of fintech, success isn't just about innovation—it's about coaching!🔥

Angela thought she was just there to coach a team. But now, she's caught in the middle of a corporate espionage drama that could make or break the future of digital banking. Can she help the team regain their mojo and outwit their rivals, or will the competition crush their ambitions? As alliances shift and the pressure builds, one thing becomes clear: this isn't just about the product—it's about the people.

 

🚨 Will Angela's coaching be enough? Find out in Shift: From Product to People—the gripping story of high-stakes innovation and corporate intrigue.

 

Buy Now on Amazon

 

[The Scrum Master Toolbox Podcast Recommends]

 

About Oluyomi Emmanuel

 

Oluyomi is a Scrum Master, Agile Coach, and Product Lead with over seven years of experience helping teams work better and deliver meaningful digital products. Having worked across energy, consumer platforms, and fintech, he is passionate about building high-performing teams, creating clarity, and turning Agile principles into real business and customer value.

 

You can link with Oluyomi Emmanuel on LinkedIn.





Download audio: https://traffic.libsyn.com/secure/scrummastertoolbox/20261007_Oluyomi_Emmanuel_W.mp3?dest-id=246429
Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete

Change is inevitable: versioning event-driven systems - Laila Bougria - NDC Oslo 2026

1 Share
From: NDC
Duration: 1:02:06
Views: 79

This talk was recorded at NDC Oslo in Oslo, Norway. #ndcoslo #ndcconferences #developer #softwaredeveloper

Attend the next NDC conference near you:
https://ndcconferences.com
https://ndcoslo.com/

Subscribe to our YouTube channel and learn every day:
/ @NDC

Follow our Social Media!

https://www.facebook.com/ndcconferences
https://twitter.com/NDC_Conferences
https://www.instagram.com/ndc_conferences/

#architecture #dotnet #cloud #microservices

Building an event-driven system is anything but trivial. However, once you make it past the sea of pub-sub vs. command-response debates and the service boundaries conundrum, you'll soon face the inevitable: change.

The conversations that follow sound all too familiar... "Who's subscribed to this message?" "Do other services depend on this field in the payload?" "Why on earth is that thing in the payload?" "That service should never rely on this data!" And, of course, the obvious "Can't we -just- remove this?"

But are those the right questions to ask? As software developers, we aim to be agents of change, not chaos. To achieve this, we need to understand the impact of tweaking a message contract without breaking half of the system or forcing other teams beyond their deadlines. We should prioritize techniques that ensure compatibility while also considering how long that compatibility needs to be sustained. Oh, and let’s not forget that we’re supposed to solve this problem with zero downtime, as our users are spread across every time zone. In this session, we’ll discuss practical techniques and tooling that can enable the evolution of your event-driven system so that, next time a stakeholder approaches with a change request, your heart doesn't sink to the floor.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete

Azure SQL Database is retiring Always Encrypted with Intel SGX enclaves

1 Share

On October 31, 2027, Azure SQL Database will retire Intel Software Guard Extensions (SGX) enclave functionality for Always Encrypted. Workloads that still depend on Intel SGX enclaves after that date will no longer work as configured.

The path forward is Virtualization-Based Security (VBS) enclaves, a hardware-independent option that does not require attestation. To retain secure-enclave capabilities, move databases from DC-series compute to a supported standard-series, non-DC tier and update affected applications for VBS enclave mode.

What is changing?

Intel SGX enclaves are tied to DC-series compute. After October 31, 2027, databases on these tiers must move to supported compute to retain enclave-enabled capabilities. Applications configured for Intel SGX enclaves may also need driver and connection-string updates.

For workloads that do not require isolation from the host operating system, VBS enclaves offer a straightforward migration within Azure SQL Database. If your threat model requires Intel SGX-equivalent host isolation, evaluate SQL Server on Azure Confidential VMs instead.

Choose the right migration path

Use the migration guide to identify databases and elastic pools on DC-series compute, choose the target architecture that matches your threat model, update application connectivity and attestation settings, and validate the workload before production cutover.

Move to VBS enclaves in Azure SQL Database

Choose VBS enclaves when you need to protect sensitive data from unauthorized users or malicious insiders but do not require isolation from the host operating system. VBS enclaves run on supported non-DC compute tiers and eliminate attestation requirements.

Consider SQL Server on Azure Confidential VMs

If your threat model requires stronger isolation from the host operating system, assess SQL Server on Azure Confidential VMs. Compare architecture, operations, compatibility, and cost with the Azure SQL Database option.

Start planning early

Start now. Discovery, compute-tier changes, application updates, security review, and production validation all take time. Complete the migration before October 31, 2027, to keep enclave-enabled workloads running without interruption.

Help and support

Have questions? Ask community experts in Microsoft Q&A. If you have an Azure support plan and need technical help, create a support request.

Review service retirements that may affect your resources in the Azure Retirement Workbook. For more ways to find impacted resources, see the retirement guidance. Retirement information may take up to two weeks to appear.

Read the whole story
alvinashcraft
5 hours ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories