Behrouzan.Auth.AspNetCore
0.1.0-preview.1
dotnet add package Behrouzan.Auth.AspNetCore --version 0.1.0-preview.1
NuGet\Install-Package Behrouzan.Auth.AspNetCore -Version 0.1.0-preview.1
<PackageReference Include="Behrouzan.Auth.AspNetCore" Version="0.1.0-preview.1" />
<PackageVersion Include="Behrouzan.Auth.AspNetCore" Version="0.1.0-preview.1" />
<PackageReference Include="Behrouzan.Auth.AspNetCore" />
paket add Behrouzan.Auth.AspNetCore --version 0.1.0-preview.1
#r "nuget: Behrouzan.Auth.AspNetCore, 0.1.0-preview.1"
#:package Behrouzan.Auth.AspNetCore@0.1.0-preview.1
#addin nuget:?package=Behrouzan.Auth.AspNetCore&version=0.1.0-preview.1&prerelease
#tool nuget:?package=Behrouzan.Auth.AspNetCore&version=0.1.0-preview.1&prerelease
Behrouzan.Auth.AspNetCore
Prepared for preview release 0.1.0-preview.1 under the MIT license:
dotnet add package Behrouzan.Auth.AspNetCore --version 0.1.0-preview.1
The command becomes usable from nuget.org after this version is published; this README does not assert that the push has already occurred. Installation brings Behrouzan.Auth as a package dependency, but its Core services and the ASP.NET Core integration still have separate registrations and configuration responsibilities described below.
Behrouzan.Auth.AspNetCore integrates the core library with ASP.NET Core and ASP.NET Core Identity. It provides permission-authorization policy support, a user-ID resolver, password sign-in orchestration, access-JWT creation, and token login/refresh orchestration.
It depends on Behrouzan.Auth. It does not provide EF Core storage; use Behrouzan.Auth.EntityFrameworkCore or register your own core storage interfaces. It also does not configure a bearer handler, validate JWTs, choose a signing algorithm/key, expose HTTP endpoints, or implement antiforgery policy. Those responsibilities remain with the consuming application.
Minimal Identity and password-sign-in registration
using Behrouzan.Auth.AspNetCore.Authentication;
using Behrouzan.Auth.AspNetCore.DependencyInjection;
builder.Services.AddAuthorization();
builder.Services.AddBehrouzanAuthAspNetCore<Guid>();
builder.Services.AddBehrouzanPasswordSignIn<ApplicationUser>(options =>
options.AllowedIdentifiers =
SignInIdentifier.UserName | SignInIdentifier.Email);
The application must already configure ASP.NET Core Identity and its authentication schemes. After var app = builder.Build(), add app.UseAuthentication() and app.UseAuthorization() before mapping protected endpoints. Inject PasswordSignInManager<ApplicationUser> into an application endpoint and call SignInAsync(identifier, password, isPersistent, cancellationToken); Identity owns the resulting application-cookie sign-in.
Token registration outline
The following registrations use existing API, but the application must supply the interfaces, refresh-token persistence, and bearer validation policy shown below. A complete runnable reference is Sample.Api's registration.
using Behrouzan.Auth.AspNetCore.Authentication;
using Behrouzan.Auth.AspNetCore.DependencyInjection;
using Behrouzan.Auth.Authentication;
using Behrouzan.Auth.DependencyInjection;
using Microsoft.AspNetCore.Authentication.JwtBearer;
using Microsoft.IdentityModel.Tokens;
builder.Services.AddAuthentication().AddJwtBearer(
JwtBearerDefaults.AuthenticationScheme,
options => options.TokenValidationParameters = new TokenValidationParameters
{
ValidateIssuer = true,
ValidIssuer = issuer,
ValidateAudience = true,
ValidAudience = audience,
ValidateIssuerSigningKey = true,
IssuerSigningKey = signingKey,
ValidAlgorithms = [SecurityAlgorithms.HmacSha256],
ValidateLifetime = true
});
builder.Services.AddBehrouzanAccessTokens(options =>
{
options.Issuer = issuer;
options.Audience = audience;
options.Lifetime = TimeSpan.FromMinutes(15);
});
builder.Services.AddBehrouzanIdentityTokenLogin<ApplicationUser, Guid>();
builder.Services.AddBehrouzanTokenRefresh<ApplicationUser, Guid>();
builder.Services.AddRefreshTokens(options =>
options.Lifetime = TimeSpan.FromDays(14));
builder.Services.AddScoped<IRefreshTokenStore<Guid>, ApplicationRefreshTokenStore>();
builder.Services.AddSingleton<IAccessTokenSigningCredentialsProvider>(
new ApplicationSigningCredentialsProvider(signingKey));
builder.Services.AddScoped<IRefreshTokenUserResolver<ApplicationUser, Guid>,
ApplicationRefreshTokenUserResolver>();
Here issuer, audience, and signingKey are application configuration, ApplicationSigningCredentialsProvider implements IAccessTokenSigningCredentialsProvider, ApplicationRefreshTokenUserResolver implements IRefreshTokenUserResolver<ApplicationUser, Guid>, and ApplicationRefreshTokenStore implements IRefreshTokenStore<Guid>. AddRefreshTokens(...) and that store registration are required for TokenLoginManager and TokenRefreshManager; the registrations above alone are insufficient. AddBehrouzanIdentityTokenLogin supplies the standard resolver only for an IdentityUser<TKey>-based user; applications with another user model use AddBehrouzanTokenLogin and register ITokenUserIdentityResolver<TUser, TKey> themselves.
An application endpoint can handle token login through the registered manager. Every login outcome returns from this flow:
var login = await tokenLoginManager.LoginAsync(
identifier, password, cancellationToken);
if (login.IsSuccess)
{
return Results.Ok(new
{
accessToken = login.AccessToken!.Token,
accessTokenExpiresAt = login.AccessToken.ExpiresAt,
refreshToken = login.RefreshToken!
});
}
return login.ErrorCode switch
{
TokenLoginErrorCode.RequiresTwoFactor => Results.Problem(
title: "Two-factor authentication is required.",
statusCode: StatusCodes.Status403Forbidden),
TokenLoginErrorCode.RefreshTokenCreationFailed => Results.Problem(
title: "Token creation failed.",
statusCode: StatusCodes.Status503ServiceUnavailable),
_ => Results.Unauthorized()
};
Refresh is a separate endpoint flow. It returns the rotated token pair on success and maps every failure to an application response:
var refresh = await tokenRefreshManager.RefreshAsync(
refreshToken, cancellationToken);
if (refresh.IsSuccess)
{
return Results.Ok(new
{
accessToken = refresh.AccessToken!.Token,
accessTokenExpiresAt = refresh.AccessToken.ExpiresAt,
refreshToken = refresh.RefreshToken!
});
}
return refresh.ErrorCode switch
{
TokenRefreshErrorCode.RequiresTwoFactor => Results.Problem(
title: "Two-factor authentication is required.",
statusCode: StatusCodes.Status403Forbidden),
TokenRefreshErrorCode.LockedOut or
TokenRefreshErrorCode.NotAllowed => Results.StatusCode(
StatusCodes.Status403Forbidden),
TokenRefreshErrorCode.ConcurrencyConflict => Results.Conflict(),
_ => Results.Unauthorized()
};
The default refresh branch covers invalid, expired, revoked, and reused tokens. These status codes follow Sample.Api; applications can choose another response policy while preserving the result semantics.
For controller actions, the registered authorization services support the permission attributes directly:
[RequirePermission("Products.View")]
public IActionResult Get() => Ok();
[RequireAnyPermission("Products.Create", "Products.Edit")]
public IActionResult Create() => Ok();
[RequireAllPermissions("Products.View", "Products.Edit")]
public IActionResult Update() => NoContent();
Security and flow limits
- Token login and refresh return
RequiresTwoFactorwhen Identity requires 2FA. This package does not complete a token-based 2FA flow or issue tokens before that factor is satisfied. - Signing access JWTs and validating bearer JWTs are consuming-application responsibilities; configure compatible issuer, audience, algorithm, and key policy on both sides.
- Refresh-token logout prevents subsequent refreshes, but an already-issued access JWT remains valid until its configured expiration. Security-stamp changes do not automatically revoke refresh tokens.
- For user-wide logout, invoke
IRefreshTokenManager<TKey>.RevokeAllAsyncwith a trusted authenticated user ID.
For controller authorization with RequirePermission, RequireAnyPermission, and RequireAllPermissions, plus the required role-based permission model, see the Permissions guide.
Detailed repository guidance:
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Behrouzan.Auth (>= 0.1.0-preview.1)
- System.IdentityModel.Tokens.Jwt (>= 8.0.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0-preview.1 | 62 | 9/25/2026 |