Eternet.Identity.AspNetCore 1.0.0-preview.7

Prefix Reserved
This is a prerelease version of Eternet.Identity.AspNetCore.
dotnet add package Eternet.Identity.AspNetCore --version 1.0.0-preview.7
                    
NuGet\Install-Package Eternet.Identity.AspNetCore -Version 1.0.0-preview.7
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Eternet.Identity.AspNetCore" Version="1.0.0-preview.7" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Eternet.Identity.AspNetCore" Version="1.0.0-preview.7" />
                    
Directory.Packages.props
<PackageReference Include="Eternet.Identity.AspNetCore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Eternet.Identity.AspNetCore --version 1.0.0-preview.7
                    
#r "nuget: Eternet.Identity.AspNetCore, 1.0.0-preview.7"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Eternet.Identity.AspNetCore@1.0.0-preview.7
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Eternet.Identity.AspNetCore&version=1.0.0-preview.7&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Eternet.Identity.AspNetCore&version=1.0.0-preview.7&prerelease
                    
Install as a Cake Tool

Eternet.Identity.AspNetCore

Shared ASP.NET Core integration for Eternet.Identity cookie session validation and OpenID Connect Back-Channel Logout.

services.AddEternetIdentitySessionValidation(options =>
{
    options.ClientId = "client-id";
    options.OpenIdConnectScheme = "oidc-scheme";
});

app.MapEternetIdentityBackChannelLogout();

Applications register a scoped CookieAuthenticationEvents implementation and call EternetIdentityCookieSessionBoundary.ValidateAsync from ValidatePrincipal. Applications with server-side session storage also replace IEternetIdentitySessionStateProvider to resolve and revoke their local sessions.

Automatic browser SSO

Version 1.0.0-preview.2 adds AddEternetIdentityBrowserSso and UseEternetIdentityBrowserSso. Register after application OIDC event configuration, then insert the middleware after authentication and before HTML hosting/authorization. Set the cookie/OIDC scheme names, an application-specific probe cookie name, and any additional login/registration paths to exclude. Enabled=false disables recovery.

Recovery uses protected OIDC state and prompt=none through a top-level navigation. The provider must support the silent no-session error response. The short negative cache is invalidated by EternetIdentityBrowserSession's opaque change hint, which never authenticates a user. The full contract, release order and local browser demonstration are documented in the repository's docs/browser-sso.md.

Open browser tabs

Version 1.0.0-preview.3 also serves an optional browser observer from the middleware. Load it early in the document, after the application's base element:

<script src="_eternet/identity/browser-session.js" data-login-paths="/ingresar /registrarme"></script>

List the application's interactive login/registration routes to keep their callbacks in control of navigation. Paths are relative to the document's base URL. The observer does not run inside frames. Disabled browser SSO serves an inert script.

Identity publishes a separate readable BrowserSessionChange cookie whenever its session changes. It contains only an opaque notification; the existing authoritative hint and credentials remain HttpOnly. Modern browsers listen for Cookie Store changes. Older browsers check local cookie metadata every two seconds while visible, without HTTP polling. A changed session reloads the document through normal server-side SSO. Hidden or suspended tabs reconcile on visibility, focus or restoration from history. An unchanged session does not reload. The browser signal never authenticates, signs out, or revokes a server session by itself.

Use 1.0.0-preview.7 for verified notifications and inline login support. The server seeds the initial marker and verifies changed signals against its HttpOnly hint before the document reloads. Invalid signals cannot cause reload loops; stable sessions send no verification requests. Mark an active inline iframe with data-eternet-identity-login and emit eternet:identity-session-applied after confirming the host session, before its continuation. Emit eternet:identity-login-ended when that form unmounts. This preserves the inline flow's state and rechecks changes after cancellation.

A public page's stale prompt=login flag does not block later session changes. After server verification, the observer removes only that flag before navigating, allowing normal silent SSO. Login routes and embedded forms still retain their callbacks.

Shared coordination for open login forms

After mounting a normal login iframe, register it with the coordinator installed by the script. Dispose the registration when the form unmounts:

const dispose = window.eternetIdentityBrowserSession?.registerLoginForm(
    iframe,
    async isCurrent => {
        if (!isCurrent()) return false;
        return confirmApplicationSessionAndContinue(isCurrent);
    });

The application callback only reads its own session and updates its UI or navigates to its existing completion URL. It must check isCurrent() after asynchronous work. Cookie observation, notification validation, backoff, OIDC recovery and message correlation are shared. Do not register account-linking, registration or deliberate account-selection workflows as ordinary login forms.

If the host validates post-login navigation URLs, add EternetIdentityBrowserSsoOptions.FormCompletionPath to that allowlist. This is an internal protocol completion page, not an OAuth redirect URI; the registered OIDC callback remains unchanged. Middleware must precede HTML hosting and authorization, as for document recovery.

On a verified change the coordinator performs a fresh authorization-code request with prompt=none in a separate hidden protocol iframe. The visible login frame is never replaced. ASP.NET validates state/correlation, nonce, PKCE and tokens before issuing the host cookie. Only a nonce-bound same-origin message from that protocol frame can notify the registered form, and the application still confirms its own session. login_required leaves the visible form available without retrying indefinitely.

This follows the silent reauthentication procedure described by OIDC Session Management. The opaque Eternet cookie is an internal change hint for this same-site deployment; it is not an OIDC session_state, credential, or an implementation of the optional check_session_iframe extension. Cross-site cookie restrictions can prevent iframe recovery; direct document recovery and interactive login remain available.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0-preview.7 74 9/15/2026
1.0.0-preview.6 56 9/15/2026
1.0.0-preview.5 57 9/15/2026
1.0.0-preview.4 59 9/15/2026
1.0.0-preview.3 59 9/15/2026
1.0.0-preview.2 57 9/14/2026
1.0.0-preview.1 176 9/1/2026