ComplianceAuth.Sdk
1.0.4
dotnet add package ComplianceAuth.Sdk --version 1.0.4
NuGet\Install-Package ComplianceAuth.Sdk -Version 1.0.4
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="ComplianceAuth.Sdk" Version="1.0.4" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="ComplianceAuth.Sdk" Version="1.0.4" />
<PackageReference Include="ComplianceAuth.Sdk" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add ComplianceAuth.Sdk --version 1.0.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: ComplianceAuth.Sdk, 1.0.4"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package ComplianceAuth.Sdk@1.0.4
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=ComplianceAuth.Sdk&version=1.0.4
#tool nuget:?package=ComplianceAuth.Sdk&version=1.0.4
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
ComplianceAuth.Sdk
SDK for integrating microservices with ComplianceAuth. Provides JWT validation, permission-based authorization, and strongly-typed permission keys.
Installation
dotnet add package ComplianceAuth.Sdk
Quick Start
1. Configure authentication and authorization
In Program.cs:
using ComplianceAuth.Sdk;
builder.Services.AddComplianceAuth(options =>
{
options.Authority = "https://base-url.com";
options.Audience = "ComplianceAuth-Services";
});
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
This single call configures:
- JWT Bearer authentication via the ComplianceAuth JWKS endpoint
- Permission-based authorization handler
Adminauthorization policy
2. Protect endpoints with permissions
using ComplianceAuth.Sdk;
[ApiController]
[Route("api/reports")]
[Authorize]
public class ReportsController : ControllerBase
{
[HasPermission(PermissionKeys.AuditRead)]
[HttpGet]
public IActionResult GetReports() { ... }
}
3. Combine with role-based policies
[Authorize(Policy = "Admin")] // requires Admin role
[HasPermission(PermissionKeys.UsersRead)] // requires specific permission
[HttpGet("users")]
public IActionResult GetUsers() { ... }
4. Check permissions in code
var permissions = User.FindAll("permissions").Select(c => c.Value);
if (permissions.Contains(PermissionKeys.UsersUpdate))
{
// user has permission
}
Wildcard Permission
The * permission grants full access. A user with this permission passes all [HasPermission] checks automatically.
// PermissionKeys.Wildcard = "*"
// If user's JWT contains permissions: ["*"], all checks pass
Available Permission Keys
| Constant | Value |
|---|---|
PermissionKeys.Wildcard |
* |
PermissionKeys.UsersRead |
users.read |
PermissionKeys.UsersCreate |
users.create |
PermissionKeys.UsersUpdate |
users.update |
PermissionKeys.UsersDelete |
users.delete |
PermissionKeys.UsersAssignRoles |
users.assign-roles |
PermissionKeys.RolesRead |
roles.read |
PermissionKeys.RolesCreate |
roles.create |
PermissionKeys.RolesUpdate |
roles.update |
PermissionKeys.RolesDelete |
roles.delete |
PermissionKeys.RolesAssignPermissions |
roles.assign-permissions |
PermissionKeys.PermissionsRead |
permissions.read |
PermissionKeys.AuditRead |
audit.read |
JWT Claims Structure
The SDK expects JWT tokens with the following claims:
{
"sub": "user-id",
"email": "user@example.com",
"roles": ["Admin"],
"permissions": ["users.read", "users.create"]
}
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net7.0 is compatible. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.5)
-
net7.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 7.0.20)
-
net8.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 8.0.16)
-
net9.0
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.