Behrouzan.Auth.EntityFrameworkCore 0.1.0-preview.1

This is a prerelease version of Behrouzan.Auth.EntityFrameworkCore.
dotnet add package Behrouzan.Auth.EntityFrameworkCore --version 0.1.0-preview.1
                    
NuGet\Install-Package Behrouzan.Auth.EntityFrameworkCore -Version 0.1.0-preview.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Behrouzan.Auth.EntityFrameworkCore" Version="0.1.0-preview.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Behrouzan.Auth.EntityFrameworkCore" Version="0.1.0-preview.1" />
                    
Directory.Packages.props
<PackageReference Include="Behrouzan.Auth.EntityFrameworkCore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Behrouzan.Auth.EntityFrameworkCore --version 0.1.0-preview.1
                    
#r "nuget: Behrouzan.Auth.EntityFrameworkCore, 0.1.0-preview.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Behrouzan.Auth.EntityFrameworkCore@0.1.0-preview.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Behrouzan.Auth.EntityFrameworkCore&version=0.1.0-preview.1&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Behrouzan.Auth.EntityFrameworkCore&version=0.1.0-preview.1&prerelease
                    
Install as a Cake Tool

Behrouzan.Auth.EntityFrameworkCore

Prepared for preview release 0.1.0-preview.1 under the MIT license:

dotnet add package Behrouzan.Auth.EntityFrameworkCore --version 0.1.0-preview.1

The command becomes usable from nuget.org after this version is published; this README does not assert that the push has already occurred. Installation brings Behrouzan.Auth as a package dependency, but Core service registration and EF Core model, provider, and migration configuration remain separate steps described below.

Behrouzan.Auth.EntityFrameworkCore provides Entity Framework Core storage for the core package: refresh-token persistence, role-permission grants, role-grant lookup, phone-number user lookup, and model configuration.

It depends on Behrouzan.Auth and requires an Identity EF Core model. It does not configure a database provider, create or apply migrations, configure ASP.NET Core authentication, issue JWTs, or expose endpoints. The consuming application owns those concerns.

Identity and model requirements

The DI and model APIs require a context derived from IdentityDbContext<TUser, TRole, TKey>, where TUser : IdentityUser<TKey>, TRole : IdentityRole<TKey>, and TKey : IEquatable<TKey>.

using Behrouzan.Auth.EntityFrameworkCore.Extensions;
using Microsoft.AspNetCore.Identity.EntityFrameworkCore;
using Microsoft.EntityFrameworkCore;

public sealed class ApplicationDbContext
    : IdentityDbContext<ApplicationUser, ApplicationRole, Guid>
{
    public ApplicationDbContext(DbContextOptions<ApplicationDbContext> options)
        : base(options) { }

    protected override void OnModelCreating(ModelBuilder builder)
    {
        base.OnModelCreating(builder);
        builder.ConfigureBehrouzanAuth<ApplicationUser, ApplicationRole, Guid>();
    }
}

Call the extension after base.OnModelCreating. It configures the refresh-token and role-permission-grant entities; generate and apply migrations with the application's selected EF Core provider.

Minimal registration

using Behrouzan.Auth.EntityFrameworkCore.DependencyInjection;
using Microsoft.EntityFrameworkCore;

builder.Services.AddDbContext<ApplicationDbContext>(options =>
    options.UseSqlite(builder.Configuration.GetConnectionString("DefaultConnection")));

builder.Services.AddBehrouzanAuthEntityFrameworkCore<
    ApplicationDbContext,
    ApplicationUser,
    ApplicationRole,
    Guid>();

This registers the EF implementations of IRefreshTokenStore<TKey>, IPermissionGrantStore<TKey>, IRolePermissionGrantStore<TKey>, and IUserIdentifierLookup<TUser>. Register the core services separately with AddBehrouzanAuth() and AddRefreshTokens(...); use the ASP.NET Core package separately if its integration is needed.

Permission grants are persisted for roles in BehrouzanRolePermissionGrants. The EF permission checker derives a user's permissions from that user's Identity role memberships; it does not store direct user permission grants. See the Permissions guide for the complete flow.

How the stores participate

After core and EF registrations, the core managers use these EF stores through their interfaces; no EF-specific manager calls are needed:

await rolePermissionManager.GrantAsync(
    roleId,
    "Products.View",
    cancellationToken);

var isGranted = await permissionChecker.IsGrantedAsync(
    userId,
    "Products.View",
    cancellationToken);

The first call writes a role grant. The second reads the user's Identity role memberships and the matching role-grant rows. The same registration supplies the hashed refresh-token store used by IRefreshTokenManager<TKey>.

ExpiresAt migration warning

Refresh-token ExpiresAt is mapped as UTC .NET ticks so that expiration comparison can be translated during conditional token rotation. Existing databases that used the earlier DateTimeOffset representation require a provider-specific, data-converting migration. Do not deploy a type-only AlterColumn migration; it can reinterpret existing values incorrectly.

For a new database, generate and apply the normal migration after adding ConfigureBehrouzanAuth. Use the data-converting migration process only when upgrading an existing database that contains refresh-token rows using the earlier representation.

For the full conversion and concurrency guidance, see:

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.1.0-preview.1 63 9/25/2026