[release/13.5] Constrain aspire-starter port replacers to localhost: URLs - #20110
Jose Perez Rodriguez (joperezr) merged 1 commit into
Conversation
The dynamic port symbols (webHttpPortReplacer, apiServiceHttpPortReplacer,
appHostHttpPortReplacer, etc.) used a bare numeric "replaces" value, so the
template engine substituted that number everywhere in generated content, not
just in launchSettings.json. Since the default ports (5000, 7000, 5301, 7301,
15000, 17000, 19000, 20000, 21000, 22000) also occur as plain numeric literals
in vendored files such as wwwroot/lib/bootstrap/dist/js/bootstrap.bundle.js
(e.g. carousel interval: 5000), those files ended up with churned values that
differ between generated projects, making diffs across template runs noisy.
Add "onlyIf": [{"after": "localhost:"}] to each port replacer so substitution
only fires in "localhost:<port>" contexts, matching the fix already applied
upstream for the same class of bug (dotnet/aspnetcore#65165, dotnet/sdk#48811).
Fixes #20030
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20110Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20110" |
Tests selector (audit mode)The full test matrix and all jobs still run in audit mode. The tests and jobs below are what selective CI would run under enforcement. 1 / 100 test projects · 1 job, from 1 changed file. Selected test projects (1 / 100)
Selected jobs (1)
How these were chosen — grouped by what changed🔧 Job reasons
Selection computed for commit |
There was a problem hiding this comment.
🟡 Changes recommended
The regression is not protected by an automated template-generation test.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Constrains dynamic port replacement to localhost: URLs, preventing unintended changes to vendored JavaScript.
Changes:
- Adds
onlyIfconditions to all ten port replacers. - Preserves expected substitutions in launch settings.
File summaries
| File | Description |
|---|---|
src/Aspire.ProjectTemplates/templates/aspire-starter/.template.config/template.json |
Restricts port substitutions to localhost URLs. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Failure here is unrelated, it is because of missing #19965 which is now being backported. I'll go ahead and merge this in. |
bd4a8e2
into
release/13.5
|
✅ No documentation update needed. Step 5 branch: excluded → base_branch_is_release, head_branch_is_backport, title_release_prefix, body_backport_marker This PR is a backport (title Triggered signals (1): No docs PR was drafted. |
|
Thanks! |
Backport of #20031 to release/13.5
/cc James Newton-King (@JamesNK) Bart Koelman (@bart-vmware)
Customer Impact
Aspire Starter App generation can replace matching port-number literals in unrelated vendored JavaScript files, producing randomly different Bootstrap artifacts and noisy diffs between otherwise equivalent projects.
Testing
The source PR manually installed pre-fix and post-fix templates and generated projects with different ports. Before the fix,
bootstrap.bundle.jschanged; after the fix,launchSettings.jsonused the requested ports whilebootstrap.bundle.jsremained byte-for-byte identical.Risk
Low. The change is limited to replacement conditions for ten dynamic port symbols and preserves substitutions in
localhost:URL contexts.Regression?
No