Atis.Identity.Token 2.0.0-preview.4

This is a prerelease version of Atis.Identity.Token.
dotnet add package Atis.Identity.Token --version 2.0.0-preview.4
                    
NuGet\Install-Package Atis.Identity.Token -Version 2.0.0-preview.4
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Atis.Identity.Token" Version="2.0.0-preview.4" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Atis.Identity.Token" Version="2.0.0-preview.4" />
                    
Directory.Packages.props
<PackageReference Include="Atis.Identity.Token" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Atis.Identity.Token --version 2.0.0-preview.4
                    
#r "nuget: Atis.Identity.Token, 2.0.0-preview.4"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Atis.Identity.Token@2.0.0-preview.4
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Atis.Identity.Token&version=2.0.0-preview.4&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Atis.Identity.Token&version=2.0.0-preview.4&prerelease
                    
Install as a Cake Tool

Atis.Identity.Token

ATIS claim kontraktı və icazə modeli. Identity/EF asılılığı yoxdur — yalnız ClaimsPrincipal oxuyur.

Qeydiyyat

using Atis.Identity.Token.DependencyInjection;

services.AddAtisAuthorization(options => options.AddPermissionPolicies(StaffPermissions.All));

StaffPermissions.All — servisin öz icazə sabitlərinin siyahısı. Policy adı = icazə adı.

İstifadə

using Atis.Identity.Token.Authorization;
using Atis.Identity.Token.Constants;

[Authorize(Policy = StaffPermissions.StaffIndex)]
[Authorize(Roles = SystemRoles.AdminOrMinEduOrInstitution)]
public async Task<IActionResult> Index() { ... }

Razor-da:

<div permission="@StaffPermissions.StaffEdit">
    <button>Redaktə et</button>
</div>

_ViewImports.cshtml-ə əlavə et: @addTagHelper *, Atis.Identity.Token

Servislərdə: ICurrentUser (Atis.Identity.Token.Abstractions) inject et (UserId, Fin, InstitutionId, InstitutionAtisId, Roles, HasPermission), və ya Atis.Identity.Token.Extensions.ClaimsPrincipalExtensions üzərindəki ClaimsPrincipal extension-larını birbaşa işlət.

Bu paketdəki nümunələr dörd namespace-ə bölünür:

using Atis.Identity.Token.Abstractions;       // ICurrentUser
using Atis.Identity.Token.Authorization;      // PermissionPolicyBuilder, PermissionRequirement
using Atis.Identity.Token.Constants;          // SystemRoles, UserKey, AtisClaimTypes
using Atis.Identity.Token.DependencyInjection; // AddAtisIdentity / AddAtisAuthorization

İki davranış qərarı

  1. Fail-closed. İcazə claim-i olmayan istifadəçi HEÇ NƏ görmür. ATIS Core-un köhnə handler-i əksini edirdi (claim-i olmayana hər şeyi açırdı) — o davranış qəsdən köçürülməyib.
  2. Issuer yoxlanılmır. Claim OIDC token-indən gələndə issuer identity serverin adresi olur, lokal Identity-də isə "LOCAL AUTHORITY". Issuer yoxlaması claim mənbəyi dəyişəndə bütün icazələri səssizcə söndürərdi.

⚠ Deploy-dan ƏVVƏL: fail-closed real davranış dəyişikliyidir

Bu paketə keçəndən əvvəl permission claim-i olmayan istifadəçi HƏR ŞEYİ görürdü (fail-open). Keçdikdən sonra həmin istifadəçi HEÇ NƏ görmür. Bu, kod dəyişikliyi deyil, istifadəçi təcrübəsi dəyişikliyidir — planlanmamış halda dəstək müraciətlərinin partlaması ilə üzləşə bilərsiniz.

Deploy-dan ƏVVƏL ATIS DB-də bunu işlət və nəticəni qiymətləndir:

SELECT u.Id, u.UserName
FROM AspNetUsers u
-- aktiv istifadəçi şərtini öz sxeminizə uyğunlaşdırın; mötərizələr VACİBDİR:
-- T-SQL-də AND, OR-dan güclü bağlayır, mötərizəsiz sorğu icazəsi OLAN istifadəçiləri də qaytarar
WHERE (u.LockoutEnabled = 0 OR u.LockoutEnd IS NULL)
  AND NOT EXISTS (
      SELECT 1 FROM AspNetUserClaims c
      WHERE c.UserId = u.Id AND c.ClaimType = 'permission'
  );

Bu sorğunun qaytardığı hər istifadəçi deploy-dan sonra əvvəllər gördüyü hər şeyi itirəcək. Say əvvəlcədən məlum olmalıdır — deploy GÖZLƏNİLMƏZ nəticə ilə deyil, bilinən "blast radius" ilə edilməlidir.

Qeydiyyatdan keçməmiş policy = exception

AuthorizeAsync (deməli, [Authorize(Policy = ...)] VƏ <div permission="..."> da) adı ilə qeydiyyatdan keçməmiş policy üçün çağırılarsa exception atır — səssizcə rədd ETMİR. Bu qəsdəndir: Razor view-da icazə adında yazı səhvi 500 kimi dərhal görünür (səssiz "gizli düymə" və ya səssiz "hamıya açıq düymə"-dən daha yaxşıdır), amma bu o deməkdir ki, hər permission="..." atributunun və hər [Authorize(Policy = ...)]-in qarşılığı AddPermissionPolicies(...) çağırışında olmalıdır — yoxsa production-da 500 alarsınız.

Atis.TokenManager-dən miqrasiya

Köhnə (Atis.TokenManager) Yeni (Atis.Identity.Token) Fərq
UserUtils (extension class) ClaimsPrincipalExtensions Ad dəyişdi, metod imzaları oxşardır.
principal.GetUserId() → string, claim yoxdursa exception atırdı principal.GetUserId() → string?, claim yoxdursa null qaytarır Çağıran kodun null yoxlaması olmalıdır — köhnə kodda try/catch var idisə artıq lazımsızdır.
principal.GetUserInstitutionId() → string? principal.GetUserInstitutionId() → int? Tip dəyişdi — int.Parse/Convert.ToInt32 çağırışlarını sil.
~12 rol-spesifik metod (IsInstitutionUser, IsAccreditationUser, IsExternal, IsAccCommissionUser, IsAccCouncilUser, IsAppCommissionUser, IsOrganizationUser, IsEmbassieUser, IsAppealUser, IsSabahUser, IsSuperAdminOrTn, ...) Yalnız 4: IsSuperAdmin, IsMinEduUser, IsInstitutionUser, IsSuperAdminOrMinEdu Digərləri üçün principal.IsInRole(SystemRoles.X) işlət (məs. IsAccreditationUser() əvəzinə principal.IsInRole(SystemRoles.AccreditationUser)).

Rollar

SystemRoles ATIS Core-un və köhnə Atis.TokenManager-in siyahılarının birləşməsidir (14 rol) — ortaq DB-yə hər iki tərəf rol seed edir. Dəyərlər PascalCase-dir və normallaşdırılmır.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net8.0

    • No dependencies.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Atis.Identity.Token:

Package Downloads
Atis.Hosting.AspNetCore

Host defaults for ATIS services: one call per host type (API or MVC WebUI) wiring Serilog/Graylog, health endpoints, CORS, Consul, correlation ids, ProblemDetails, forwarded headers, and — for APIs — Swagger, versioning and JWT bearer.

Atis.Identity.Sso

OIDC relying-party defaults for ATIS MVC WebUIs: one call wires cookie + OpenID Connect (authorization code + PKCE) against the atis-service-user OpenIddict server, pulls the permission claims from userinfo into the cookie principal and registers the fail-closed permission policies of Atis.Identity.Token.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.0.0-preview.4 103 9/14/2026

2.0.0-preview.1: Atis.TokenManager-in oxuma yarısı — fail-closed PermissionAuthorizationHandler (issuer yoxlanmır), 14 SystemRoles, ICurrentUser, ClaimsPrincipalExtensions, permission tag helper; Identity/EF Core asılılığı yoxdur. preview.2: SystemRoles.AllRoles (mövcud, 14 rolun tam siyahısı) indi ayrıca test-lə pin olunub — seed və yoxlama üçün. preview.4: claim oxuyucuları (GetClaim/HasPermission/GetRoles) tipi ORDINAL müqayisə edir — OIDC-nin standart `name`/`email` claim-ləri UserKey.Name/Email-i üstələyirdi (GetName() istifadəçi adını qaytarırdı).