Fhi.Lmr.Authentication.TokenValidation 10.1.2

The owner has unlisted this package. This could mean that the package is deprecated, has security vulnerabilities or shouldn't be used anymore.
dotnet add package Fhi.Lmr.Authentication.TokenValidation --version 10.1.2
                    
NuGet\Install-Package Fhi.Lmr.Authentication.TokenValidation -Version 10.1.2
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Fhi.Lmr.Authentication.TokenValidation" Version="10.1.2" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Fhi.Lmr.Authentication.TokenValidation" Version="10.1.2" />
                    
Directory.Packages.props
<PackageReference Include="Fhi.Lmr.Authentication.TokenValidation" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Fhi.Lmr.Authentication.TokenValidation --version 10.1.2
                    
#r "nuget: Fhi.Lmr.Authentication.TokenValidation, 10.1.2"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Fhi.Lmr.Authentication.TokenValidation@10.1.2
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Fhi.Lmr.Authentication.TokenValidation&version=10.1.2
                    
Install as a Cake Addin
#tool nuget:?package=Fhi.Lmr.Authentication.TokenValidation&version=10.1.2
                    
Install as a Cake Tool

Fhi.Lmr.Authentication.TokenValidation

NuGet-pakke for validering av JWT-tokens i API-er beskyttet av HelseId, Entra ID eller Maskinporten. Støtter både Bearer og DPoP tokens.

Installasjon

dotnet add package Fhi.Lmr.Authentication.TokenValidation

Konfigurasjon

appsettings.json

{
  "ApiTokenValidation": {
    "Authority": "https://helseid-sts.test.nhn.no/",
    "Audience": "fhi:min.api",
    "DefaultScope": "fhi:min.api/les",
    "Scopes": [
      "fhi:min.api/les",
      "fhi:min.api/skriv",
      "fhi:min.api/admin"
    ],
    "RequireDPoP": false,
    "UseAuth": true
  }
}

Konfigurasjonsverdier

Felt Beskrivelse Påkrevd Default
Authority URL til identity provider Ja -
Audience Forventet audience-claim i token Ja -
DefaultScope Scope som kreves på alle endepunkter (fallback policy) Nei null
Scopes Liste over scopes det opprettes authorization policies for Nei []
RequireDPoP Krev DPoP-proof i tillegg til access token Nei false
UseAuth Aktiver autentisering/autorisering (false = alle requests tillates) Nei true

Bruk

Program.cs

using Fhi.Lmr.Authentication.TokenValidation.ApiAuthentication;

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddControllers();

// Legg til autentisering og autorisering
builder.Services.AddApiAuthenticationAndAuthorization(builder.Configuration);

var app = builder.Build();

app.UseHttpsRedirection();
app.UseAuthentication();
app.UseAuthorization();

app.MapControllers();

app.Run();

Endepunktspesifikke scopes

Scopes definert i Scopes-listen opprettes automatisk som authorization policies med samme navn. Bruk RequireAuthorization for å kreve spesifikke scopes på endepunkter.

Med Minimal API
// Bruker DefaultScope (fhi:min.api/les)
app.MapGet("/data", () => Results.Ok("data"));

// Krever spesifikt scope
app.MapGet("/admin", () => Results.Ok("admin data"))
   .RequireAuthorization("fhi:min.api/admin");

// Tillat anonym tilgang
app.MapGet("/public", () => Results.Ok("public"))
   .AllowAnonymous();
Med Controllers
[ApiController]
[Route("api/[controller]")]
public class DataController : ControllerBase
{
    // Bruker DefaultScope automatisk
    [HttpGet]
    public IActionResult Get() => Ok("data");

    // Krever spesifikt scope
    [HttpPost]
    [Authorize(Policy = "fhi:min.api/skriv")]
    public IActionResult Create() => Ok("created");

    // Krever admin scope
    [HttpDelete("{id}")]
    [Authorize(Policy = "fhi:min.api/admin")]
    public IActionResult Delete(int id) => Ok("deleted");

    // Tillat anonym tilgang
    [HttpGet("health")]
    [AllowAnonymous]
    public IActionResult Health() => Ok("healthy");
}

Støttede Identity Providers

Provider Bearer DPoP Merknad
HelseId Ja Ja ValidTypes settes til at+jwt
Entra ID Ja Nei -
Maskinporten Ja Nei Bruker oauth-authorization-server discovery

Feilhåndtering

Pakken returnerer detaljerte feilmeldinger i WWW-Authenticate-headeren:

Feil Beskrivelse
invalid_request Manglende Authorization header
invalid_token Token er ugyldig, utløpt, feil signatur, etc.
insufficient_scope Token mangler påkrevd scope

DPoP-konfigurasjon

For DPoP-beskyttede API-er, sett RequireDPoP: true. DPoP validerer at:

  • DPoP-proof header er tilstede
  • Proof er gyldig JWT med riktig struktur
  • cnf-claim i access token matcher DPoP-nøkkel
  • HTTP-metode og URL matcher claims i proof
  • Replay-angrep forhindres via nonce og jti-validering
Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated