DotCruz.Shared.Security
1.0.9
dotnet add package DotCruz.Shared.Security --version 1.0.9
NuGet\Install-Package DotCruz.Shared.Security -Version 1.0.9
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="DotCruz.Shared.Security" Version="1.0.9" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="DotCruz.Shared.Security" Version="1.0.9" />
<PackageReference Include="DotCruz.Shared.Security" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add DotCruz.Shared.Security --version 1.0.9
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: DotCruz.Shared.Security, 1.0.9"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package DotCruz.Shared.Security@1.0.9
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=DotCruz.Shared.Security&version=1.0.9
#tool nuget:?package=DotCruz.Shared.Security&version=1.0.9
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
DotCruz.Shared.Security
Pacote de segurança oficial contendo utilitários de autenticação, autorização, auditoria e propagação de contexto de multi-tenancy para a plataforma DotCruz.
Instalação
Você pode instalar o pacote via NuGet CLI:
dotnet add package DotCruz.Shared.Security
Ou via Gerenciador de Pacotes do Visual Studio procurando por DotCruz.Shared.Security.
Conteúdo do Pacote
Autenticação e Autorização
- AddSharedSecurity: Método de extensão unificado para configuração de autenticação JWT Bearer (JWKS/Chave assimétrica) e autenticação M2M baseada em API Key.
- ApiKey: Handlers e validadores para autenticação baseada em chaves de serviço.
Contexto de Segurança
- ISecurityContext: Interface injetável que fornece acesso seguro aos dados do usuário/serviço autenticado na requisição atual:
UserId: ID do usuário autenticado.TenantId: ID do Tenant ativo (resolvido via claims ou cabeçalhoX-Tenant-ID).Roles: Funções atribuídas ao usuário.IsAuthenticatedUser: Indica se a chamada é de um usuário final autenticado.IsAuthenticatedService: Indica se a chamada é de integração de serviços (M2M) autenticada.
Observabilidade
- AuditLogMiddleware: Middleware integrado para gravação de logs de auditoria detalhados de requisições HTTP (usuário, serviço, tenant, método, endpoint e status de retorno).
Propagação de Contexto
- AddServiceApiKeyPropagation: Extensão para
IHttpClientBuilderque registra automaticamente oServiceApiKeyHttpClientHandler, propagando a chave de API do serviço e o cabeçalhoX-Tenant-IDda requisição atual para chamadas HTTP de saída.
Exemplo de Uso
1. Registro e Configuração no Startup (Program.cs)
using DotCruz.Shared.Security;
var builder = WebApplication.CreateBuilder(args);
// Adiciona os serviços de segurança da biblioteca
builder.Services.AddSharedSecurity(builder.Configuration);
var app = builder.Build();
// Habilita o log de auditoria no pipeline (deve ser registrado antes da autenticação)
app.UseSharedSecurityAuditLog();
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();
app.Run();
2. Configurando a Propagação em HttpClients
Para propagar a segurança e o TenantId em chamadas para outros microsserviços do ecossistema:
using DotCruz.Shared.Security;
builder.Services.AddHttpClient<ICoreAuthClient, CoreAuthClient>(client =>
{
client.BaseAddress = new Uri("http://dotcruz-coreauth-api:8080/");
})
.AddServiceApiKeyPropagation();
3. Utilizando o Contexto de Segurança nas Classes de Negócio
using DotCruz.Shared.Security.Context;
public class CustomService(ISecurityContext securityContext)
{
public void ExecutarAcao()
{
var tenantId = securityContext.TenantId;
var userId = securityContext.UserId;
if (securityContext.IsAuthenticatedService)
{
var serviceName = securityContext.ServiceName;
// Lógica para chamada vinda de outro microsserviço
}
}
}
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.12)
- Microsoft.IdentityModel.Protocols (>= 8.22.0)
- Microsoft.IdentityModel.Tokens (>= 8.22.0)
- System.IdentityModel.Tokens.Jwt (>= 8.22.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.