Fhi.Lmr.Authentication.TokenValidation
10.1.2
The owner has unlisted this package.
This could mean that the package is deprecated, has security vulnerabilities or shouldn't be used anymore.
dotnet add package Fhi.Lmr.Authentication.TokenValidation --version 10.1.2
NuGet\Install-Package Fhi.Lmr.Authentication.TokenValidation -Version 10.1.2
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Fhi.Lmr.Authentication.TokenValidation" Version="10.1.2" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Fhi.Lmr.Authentication.TokenValidation" Version="10.1.2" />
<PackageReference Include="Fhi.Lmr.Authentication.TokenValidation" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Fhi.Lmr.Authentication.TokenValidation --version 10.1.2
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Fhi.Lmr.Authentication.TokenValidation, 10.1.2"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Fhi.Lmr.Authentication.TokenValidation@10.1.2
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Fhi.Lmr.Authentication.TokenValidation&version=10.1.2
#tool nuget:?package=Fhi.Lmr.Authentication.TokenValidation&version=10.1.2
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Fhi.Lmr.Authentication.TokenValidation
NuGet-pakke for validering av JWT-tokens i API-er beskyttet av HelseId, Entra ID eller Maskinporten. Støtter både Bearer og DPoP tokens.
Installasjon
dotnet add package Fhi.Lmr.Authentication.TokenValidation
Konfigurasjon
appsettings.json
{
"ApiTokenValidation": {
"Authority": "https://helseid-sts.test.nhn.no/",
"Audience": "fhi:min.api",
"DefaultScope": "fhi:min.api/les",
"Scopes": [
"fhi:min.api/les",
"fhi:min.api/skriv",
"fhi:min.api/admin"
],
"RequireDPoP": false,
"UseAuth": true
}
}
Konfigurasjonsverdier
| Felt | Beskrivelse | Påkrevd | Default |
|---|---|---|---|
Authority |
URL til identity provider | Ja | - |
Audience |
Forventet audience-claim i token | Ja | - |
DefaultScope |
Scope som kreves på alle endepunkter (fallback policy) | Nei | null |
Scopes |
Liste over scopes det opprettes authorization policies for | Nei | [] |
RequireDPoP |
Krev DPoP-proof i tillegg til access token | Nei | false |
UseAuth |
Aktiver autentisering/autorisering (false = alle requests tillates) | Nei | true |
Bruk
Program.cs
using Fhi.Lmr.Authentication.TokenValidation.ApiAuthentication;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddControllers();
// Legg til autentisering og autorisering
builder.Services.AddApiAuthenticationAndAuthorization(builder.Configuration);
var app = builder.Build();
app.UseHttpsRedirection();
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();
app.Run();
Endepunktspesifikke scopes
Scopes definert i Scopes-listen opprettes automatisk som authorization policies med samme navn. Bruk RequireAuthorization for å kreve spesifikke scopes på endepunkter.
Med Minimal API
// Bruker DefaultScope (fhi:min.api/les)
app.MapGet("/data", () => Results.Ok("data"));
// Krever spesifikt scope
app.MapGet("/admin", () => Results.Ok("admin data"))
.RequireAuthorization("fhi:min.api/admin");
// Tillat anonym tilgang
app.MapGet("/public", () => Results.Ok("public"))
.AllowAnonymous();
Med Controllers
[ApiController]
[Route("api/[controller]")]
public class DataController : ControllerBase
{
// Bruker DefaultScope automatisk
[HttpGet]
public IActionResult Get() => Ok("data");
// Krever spesifikt scope
[HttpPost]
[Authorize(Policy = "fhi:min.api/skriv")]
public IActionResult Create() => Ok("created");
// Krever admin scope
[HttpDelete("{id}")]
[Authorize(Policy = "fhi:min.api/admin")]
public IActionResult Delete(int id) => Ok("deleted");
// Tillat anonym tilgang
[HttpGet("health")]
[AllowAnonymous]
public IActionResult Health() => Ok("healthy");
}
Støttede Identity Providers
| Provider | Bearer | DPoP | Merknad |
|---|---|---|---|
| HelseId | Ja | Ja | ValidTypes settes til at+jwt |
| Entra ID | Ja | Nei | - |
| Maskinporten | Ja | Nei | Bruker oauth-authorization-server discovery |
Feilhåndtering
Pakken returnerer detaljerte feilmeldinger i WWW-Authenticate-headeren:
| Feil | Beskrivelse |
|---|---|
invalid_request |
Manglende Authorization header |
invalid_token |
Token er ugyldig, utløpt, feil signatur, etc. |
insufficient_scope |
Token mangler påkrevd scope |
DPoP-konfigurasjon
For DPoP-beskyttede API-er, sett RequireDPoP: true. DPoP validerer at:
- DPoP-proof header er tilstede
- Proof er gyldig JWT med riktig struktur
cnf-claim i access token matcher DPoP-nøkkel- HTTP-metode og URL matcher claims i proof
- Replay-angrep forhindres via nonce og jti-validering
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.0)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.0)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.15.0)
- Microsoft.IdentityModel.Protocols.OpenIdConnect (>= 8.15.0)
- Microsoft.IdentityModel.Tokens (>= 8.15.0)
- System.IdentityModel.Tokens.Jwt (>= 8.15.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|