Ez4.ClientAccess
8.0.1
dotnet add package Ez4.ClientAccess --version 8.0.1
NuGet\Install-Package Ez4.ClientAccess -Version 8.0.1
<PackageReference Include="Ez4.ClientAccess" Version="8.0.1" />
<PackageVersion Include="Ez4.ClientAccess" Version="8.0.1" />
<PackageReference Include="Ez4.ClientAccess" />
paket add Ez4.ClientAccess --version 8.0.1
#r "nuget: Ez4.ClientAccess, 8.0.1"
#:package Ez4.ClientAccess@8.0.1
#addin nuget:?package=Ez4.ClientAccess&version=8.0.1
#tool nuget:?package=Ez4.ClientAccess&version=8.0.1
Ez4.ClientAccess
A client-path authorization library for ASP.NET Core: a request is allowed only when the calling
client — identified by the azp claim on its already-authenticated JWT — appears in that client's
allowed-path list. Rules are held in memory as an immutable snapshot, loaded from a JSON file with
no database required. Denies render 403 application/problem+json; the only exemption from
default-deny is [AllowAnonymous] on the endpoint itself.
Usage
using Ez4.ClientAccess.Policy;
var builder = WebApplication.CreateBuilder(args);
builder.AddClientPathFromJsonPolicy();
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapGet("/health", () => Results.Ok()).AllowAnonymous();
app.MapGet("/api/orders/{id}", (string id) => Results.Ok(new { id }))
.RequireAuthorization("ClientPath");
app.Run();
appsettings.json:
{
"ClientAccess": {
"ServiceName": "orders-api",
"SecretFile": { "PathPattern": "secret.{Environment}.json", "ReloadOnChange": true },
"RefreshInterval": "00:00:30",
"ChangeDebounce": "00:00:01"
}
}
Rule file (secret.{Environment}.json), resolved from SecretFile.PathPattern:
{
"ClientAccess": {
"Rules": {
"clientA": ["/api/orders", "/api/invoices"],
"clientB": ["/api/orders"],
"clientC": []
}
}
}
Run the sample
dotnet run --project samples/SampleApi
curl http://localhost:5000/health # 200, no token needed
curl -H "Authorization: Bearer clientA" http://localhost:5000/api/orders/1 # 200
curl http://localhost:5000/api/orders/1 # 401, no token
Run the tests
dotnet test tests/Ez4.ClientAccess.Tests
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- StackExchange.Redis (>= 3.1.13)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|