Constructor Argument Value¶
What does this mean ?¶
WPF's ConstructorArgumentAttribute maps a property to the named constructor parameter used for XAML serialization. Its string value is metadata; it is not a parameter declaration or a requirement that every ordinary C# constructor use the attribute.
What can happen ?¶
A mismatched name can cause incorrect or failed XAML serialization/reconstruction. The precise failure depends on the XAML processor and usage. The attribute does not itself validate untrusted input or establish a security boundary.
Recommendation¶
Use the exact parameter name for the corresponding property and test the extension with the supported WPF/XAML runtime. Implement the required ProvideValue method. Keep a separate review of any objects or services the extension accesses.
Sample Code¶
This Windows/WPF example maps Value to constructor parameter value:
using System;
using System.Windows.Markup;
public sealed class ValueExtension : MarkupExtension
{
public ValueExtension(object value) { Value = value; }
// Incorrect mapping would be [ConstructorArgument("otherValue")].
[ConstructorArgument("value")]
public object Value { get; set; }
public override object ProvideValue(IServiceProvider serviceProvider)
{
return Value;
}
}
Regression checks¶
On Windows with the target WPF runtime, load and serialize a local XAML fixture using the extension. Assert that the supplied constructor value survives the intended round trip. A normal C# compilation is not sufficient to verify all XAML metadata behavior.