Eigenverft.NetLib.Security.DataProtection
1.0.0.5
dotnet add package Eigenverft.NetLib.Security.DataProtection --version 1.0.0.5
NuGet\Install-Package Eigenverft.NetLib.Security.DataProtection -Version 1.0.0.5
<PackageReference Include="Eigenverft.NetLib.Security.DataProtection" Version="1.0.0.5" />
<PackageVersion Include="Eigenverft.NetLib.Security.DataProtection" Version="1.0.0.5" />
<PackageReference Include="Eigenverft.NetLib.Security.DataProtection" />
paket add Eigenverft.NetLib.Security.DataProtection --version 1.0.0.5
#r "nuget: Eigenverft.NetLib.Security.DataProtection, 1.0.0.5"
#:package Eigenverft.NetLib.Security.DataProtection@1.0.0.5
#addin nuget:?package=Eigenverft.NetLib.Security.DataProtection&version=1.0.0.5
#tool nuget:?package=Eigenverft.NetLib.Security.DataProtection&version=1.0.0.5
Eigenverft.NetLib.Security.DataProtection
ASP.NET Core Data Protection adapters for reversible string transforms and persisted configuration-value codecs.
✨ At a glance
| Capability | What it does | Starting point |
|---|---|---|
| Reversible string protection | Protect and unprotect values with a persistent ASP.NET Core Data Protection key ring | AspNetDataProtectionStringTransforms.DataProtection(...) |
| Configuration values | Create a self-describing codec for persisted protected values | AspNetDataProtectionConfigurationValueCodecs.DataProtection(...) |
| Purpose isolation | Separate protected values by stable application name and purpose | applicationName, purpose |
📦 Installation
dotnet add package Eigenverft.NetLib.Security.DataProtection
🚀 Quick start
Create a transform with a persistent key-ring directory and stable isolation values:
using System;
using System.IO;
using Eigenverft.NetLib.Security.DataProtection.Transformations;
using Eigenverft.NetLib.Transformations;
ReversibleStringTransform transform = AspNetDataProtectionStringTransforms.DataProtection(
Path.Combine(AppContext.BaseDirectory, "AppProtectionKeys"),
applicationName: "Worker",
purpose: "configuration-values");
string protectedValue = transform.Apply("persisted value");
if (!transform.TryReverse(protectedValue, out string clearText))
{
throw new InvalidOperationException("The value could not be unprotected.");
}
For configuration-value persistence, use AspNetDataProtectionConfigurationValueCodecs.DataProtection(...) to create a ConfigurationValueCodec. Its directory-layout overload uses DefaultDirectory.ApplicationProtectionKeys and the process entry assembly name; its explicit overload accepts the key path and application name directly.
🔑 Key-ring and package dependencies
The key ring is durable state. Back up the complete ring with the values that depend on it, retain old keys for as long as those values may be used, and protect the files with deployment-appropriate filesystem permissions. This adapter does not configure an additional at-rest encryptor; directory separation alone is not an access-control boundary. If a previously used installation unexpectedly points at a new or empty ring, existing protected values may become unavailable.
Keep applicationName and purpose stable while values must remain reversible. Changing either creates an isolation context that cannot unprotect values from the previous one. Data Protection does not add machine binding: another machine with the same key ring and isolation context can unprotect the values.
The configuration codec integrates with Eigenverft.NetLib.Configuration.Values and uses Eigenverft.NetLib.Hosting.DirectoryLayout for its standard key-ring path. The transform API builds on Eigenverft.NetLib.Transformations; these dependencies are declared by the package.
Data Protection is distinct from physical-machine binding: the same ring, application name, and purpose can be used on another machine, while PhysicalMachineBoundAes() is a separate transform exposed by Transformations and a convenience codec in Configuration.Values. This package does not manage TLS certificates; WebLib's Kestrel.Sni uses the separate Security.Certificates package.
🎯 Target frameworks
net8.0net10.0
🔗 Project links
📄 License
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Eigenverft.NetLib.Configuration.Values (>= 1.0.0.6)
- Eigenverft.NetLib.Hosting.DirectoryLayout (>= 1.0.0.5)
- Eigenverft.NetLib.Transformations (>= 1.0.0.5)
- Microsoft.AspNetCore.DataProtection.Extensions (>= 10.0.11)
- System.Security.Cryptography.Xml (>= 10.0.11)
-
net8.0
- Eigenverft.NetLib.Configuration.Values (>= 1.0.0.6)
- Eigenverft.NetLib.Hosting.DirectoryLayout (>= 1.0.0.5)
- Eigenverft.NetLib.Transformations (>= 1.0.0.5)
- Microsoft.AspNetCore.DataProtection.Extensions (>= 8.0.22)
- System.Security.Cryptography.Xml (>= 8.0.4)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
Initial Eigenverft.NetLib.Security.DataProtection capability package extracted from the historic WebLib Infrastructure implementation; public namespaces and APIs remain unchanged.