Skip to content

[release/13.5] Constrain aspire-starter port replacers to localhost: URLs - #20110

Merged
Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.5from
backport/pr-20031-to-release/13.5
Sep 14, 2026
Merged

Jose Perez Rodriguez (joperezr) merged 1 commit into
release/13.5from
backport/pr-20031-to-release/13.5

Conversation

@JamesNK

@JamesNK James Newton-King (JamesNK) commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Backport of #20031 to release/13.5

/cc James Newton-King (@JamesNK) Bart Koelman (@bart-vmware)

Customer Impact

Aspire Starter App generation can replace matching port-number literals in unrelated vendored JavaScript files, producing randomly different Bootstrap artifacts and noisy diffs between otherwise equivalent projects.

Testing

The source PR manually installed pre-fix and post-fix templates and generated projects with different ports. Before the fix, bootstrap.bundle.js changed; after the fix, launchSettings.json used the requested ports while bootstrap.bundle.js remained byte-for-byte identical.

Risk

Low. The change is limited to replacement conditions for ten dynamic port symbols and preserves substitutions in localhost: URL contexts.

Regression?

No

The dynamic port symbols (webHttpPortReplacer, apiServiceHttpPortReplacer,
appHostHttpPortReplacer, etc.) used a bare numeric "replaces" value, so the
template engine substituted that number everywhere in generated content, not
just in launchSettings.json. Since the default ports (5000, 7000, 5301, 7301,
15000, 17000, 19000, 20000, 21000, 22000) also occur as plain numeric literals
in vendored files such as wwwroot/lib/bootstrap/dist/js/bootstrap.bundle.js
(e.g. carousel interval: 5000), those files ended up with churned values that
differ between generated projects, making diffs across template runs noisy.

Add "onlyIf": [{"after": "localhost:"}] to each port replacer so substitution
only fires in "localhost:<port>" contexts, matching the fix already applied
upstream for the same class of bug (dotnet/aspnetcore#65165, dotnet/sdk#48811).

Fixes #20030
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20110

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20110"

@github-actions

Copy link
Copy Markdown
Contributor

Tests selector (audit mode)

The full test matrix and all jobs still run in audit mode. The tests and jobs below are what selective CI would run under enforcement.

1 / 100 test projects · 1 job, from 1 changed file.

Selected test projects (1 / 100)

Aspire.Templates.Tests

Selected jobs (1)

deployment-e2e


How these were chosen — grouped by what changed

🔧 src/Aspire.ProjectTemplates/templates/aspire-starter/.template.config/template.json (changed source)
→ 1 directly: Aspire.Templates.Tests

Job reasons

Job Triggered by
deployment-e2e src/Aspire.ProjectTemplates/templates/aspire-starter/.template.config/template.json

Selection computed for commit 0018a59.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The regression is not protected by an automated template-generation test.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Constrains dynamic port replacement to localhost: URLs, preventing unintended changes to vendored JavaScript.

Changes:

  • Adds onlyIf conditions to all ten port replacers.
  • Preserves expected substitutions in launch settings.
File summaries
File Description
src/Aspire.ProjectTemplates/templates/aspire-starter/.template.config/template.json Restricts port substitutions to localhost URLs.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Balanced

@JamesNK James Newton-King (JamesNK) added the Servicing-consider Issue for next servicing release review label Sep 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

@joperezr

Copy link
Copy Markdown
Member

Failure here is unrelated, it is because of missing #19965 which is now being backported. I'll go ahead and merge this in.

@joperezr
Jose Perez Rodriguez (joperezr) merged commit bd4a8e2 into release/13.5 Sep 14, 2026
1687 of 1703 checks passed
@joperezr
Jose Perez Rodriguez (joperezr) deleted the backport/pr-20031-to-release/13.5 branch September 14, 2026 16:59
@github-actions github-actions Bot added this to the 13.5.x milestone Sep 14, 2026
@microsoft-github-policy-service microsoft-github-policy-service Bot removed this from the 13.5.x milestone Sep 14, 2026
@aspire-repo-bot

Copy link
Copy Markdown
Contributor

✅ No documentation update needed.

Step 5 branch: excluded → base_branch_is_release, head_branch_is_backport, title_release_prefix, body_backport_marker

This PR is a backport (title [release/13.5] ..., body contains Backport of #20031 to release/13.5, head branch is a backport branch, and base branch is release/13.5). Per workflow policy, backport PRs are excluded from doc generation because user-facing documentation is authored against the original forward PR (#20031) on the default branch; drafting a second docs PR here would be duplicate noise.

Triggered signals (1): project_template_changed (evidence: src/Aspire.ProjectTemplates/templates/aspire-starter/.template.config/template.json matched path pattern ^src/Aspire\.ProjectTemplates/.+$).

No docs PR was drafted.

@bart-vmware

Copy link
Copy Markdown
Contributor

Thanks!

This was referenced Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-templates Servicing-consider Issue for next servicing release review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants