Eternet.Identity.AspNetCore
1.0.0-preview.7
Prefix Reserved
dotnet add package Eternet.Identity.AspNetCore --version 1.0.0-preview.7
NuGet\Install-Package Eternet.Identity.AspNetCore -Version 1.0.0-preview.7
<PackageReference Include="Eternet.Identity.AspNetCore" Version="1.0.0-preview.7" />
<PackageVersion Include="Eternet.Identity.AspNetCore" Version="1.0.0-preview.7" />
<PackageReference Include="Eternet.Identity.AspNetCore" />
paket add Eternet.Identity.AspNetCore --version 1.0.0-preview.7
#r "nuget: Eternet.Identity.AspNetCore, 1.0.0-preview.7"
#:package Eternet.Identity.AspNetCore@1.0.0-preview.7
#addin nuget:?package=Eternet.Identity.AspNetCore&version=1.0.0-preview.7&prerelease
#tool nuget:?package=Eternet.Identity.AspNetCore&version=1.0.0-preview.7&prerelease
Eternet.Identity.AspNetCore
Shared ASP.NET Core integration for Eternet.Identity cookie session validation and OpenID Connect Back-Channel Logout.
services.AddEternetIdentitySessionValidation(options =>
{
options.ClientId = "client-id";
options.OpenIdConnectScheme = "oidc-scheme";
});
app.MapEternetIdentityBackChannelLogout();
Applications register a scoped CookieAuthenticationEvents implementation and call
EternetIdentityCookieSessionBoundary.ValidateAsync from ValidatePrincipal.
Applications with server-side session storage also replace
IEternetIdentitySessionStateProvider to resolve and revoke their local sessions.
Automatic browser SSO
Version 1.0.0-preview.2 adds AddEternetIdentityBrowserSso and
UseEternetIdentityBrowserSso. Register after application OIDC event configuration,
then insert the middleware after authentication and before HTML hosting/authorization.
Set the cookie/OIDC scheme names, an application-specific probe cookie name, and any
additional login/registration paths to exclude. Enabled=false disables recovery.
Recovery uses protected OIDC state and prompt=none through a top-level navigation.
The provider must support the silent no-session error response. The short negative cache
is invalidated by EternetIdentityBrowserSession's opaque change hint, which never
authenticates a user. The full contract, release order and local browser demonstration
are documented in the repository's docs/browser-sso.md.
Open browser tabs
Version 1.0.0-preview.3 also serves an optional browser observer from the middleware. Load it early in the document, after the application's base element:
<script src="_eternet/identity/browser-session.js" data-login-paths="/ingresar /registrarme"></script>
List the application's interactive login/registration routes to keep their callbacks in control of navigation. Paths are relative to the document's base URL. The observer does not run inside frames. Disabled browser SSO serves an inert script.
Identity publishes a separate readable BrowserSessionChange cookie whenever its
session changes. It contains only an opaque notification; the existing authoritative
hint and credentials remain HttpOnly. Modern browsers listen for Cookie Store changes.
Older browsers check local cookie metadata every two seconds while visible, without
HTTP polling. A changed session reloads the document through normal server-side SSO.
Hidden or suspended tabs reconcile on visibility, focus or restoration from history.
An unchanged session does not reload. The browser signal never authenticates, signs
out, or revokes a server session by itself.
Use 1.0.0-preview.7 for verified notifications and inline login support. The server
seeds the initial marker and verifies changed signals against its HttpOnly hint before
the document reloads. Invalid signals cannot cause reload loops; stable sessions send
no verification requests. Mark an active inline iframe with data-eternet-identity-login
and emit eternet:identity-session-applied after confirming the host session, before
its continuation. Emit eternet:identity-login-ended when that form unmounts. This
preserves the inline flow's state and rechecks changes after cancellation.
A public page's stale prompt=login flag does not block later session changes.
After server verification, the observer removes only that flag before navigating,
allowing normal silent SSO. Login routes and embedded forms still retain their callbacks.
Shared coordination for open login forms
After mounting a normal login iframe, register it with the coordinator installed by the script. Dispose the registration when the form unmounts:
const dispose = window.eternetIdentityBrowserSession?.registerLoginForm(
iframe,
async isCurrent => {
if (!isCurrent()) return false;
return confirmApplicationSessionAndContinue(isCurrent);
});
The application callback only reads its own session and updates its UI or navigates
to its existing completion URL. It must check isCurrent() after asynchronous work.
Cookie observation, notification validation, backoff, OIDC recovery and message
correlation are shared. Do not register account-linking, registration or deliberate
account-selection workflows as ordinary login forms.
If the host validates post-login navigation URLs, add EternetIdentityBrowserSsoOptions.FormCompletionPath
to that allowlist. This is an internal protocol completion page, not an OAuth redirect
URI; the registered OIDC callback remains unchanged. Middleware must precede HTML
hosting and authorization, as for document recovery.
On a verified change the coordinator performs a fresh authorization-code request with
prompt=none in a separate hidden protocol iframe. The visible login frame is never
replaced. ASP.NET validates state/correlation, nonce, PKCE and tokens before issuing
the host cookie. Only a nonce-bound same-origin message from that protocol frame can
notify the registered form, and the application still confirms its own session.
login_required leaves the visible form available without retrying indefinitely.
This follows the silent reauthentication procedure described by OIDC Session Management.
The opaque Eternet cookie is an internal change hint for this same-site deployment;
it is not an OIDC session_state, credential, or an implementation of the optional
check_session_iframe extension. Cross-site cookie restrictions can prevent iframe
recovery; direct document recovery and interactive login remain available.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.0-preview.7 | 74 | 9/15/2026 |
| 1.0.0-preview.6 | 56 | 9/15/2026 |
| 1.0.0-preview.5 | 57 | 9/15/2026 |
| 1.0.0-preview.4 | 59 | 9/15/2026 |
| 1.0.0-preview.3 | 59 | 9/15/2026 |
| 1.0.0-preview.2 | 57 | 9/14/2026 |
| 1.0.0-preview.1 | 176 | 9/1/2026 |