Mediarq.Authorization
1.5.1
dotnet add package Mediarq.Authorization --version 1.5.1
NuGet\Install-Package Mediarq.Authorization -Version 1.5.1
<PackageReference Include="Mediarq.Authorization" Version="1.5.1" />
<PackageVersion Include="Mediarq.Authorization" Version="1.5.1" />
<PackageReference Include="Mediarq.Authorization" />
paket add Mediarq.Authorization --version 1.5.1
#r "nuget: Mediarq.Authorization, 1.5.1"
#:package Mediarq.Authorization@1.5.1
#addin nuget:?package=Mediarq.Authorization&version=1.5.1
#tool nuget:?package=Mediarq.Authorization&version=1.5.1
Mediarq.Authorization
ASP.NET Core policy-based authorization as a pipeline behavior: mark a command/query as
IAuthorizedRequest, and it is checked before its handler runs — no authenticated user short-circuits
with a 401, a failed policy short-circuits with a 403, both as a typed Result failure your handler
never has to think about.
dotnet add package Mediarq.Authorization
Usage
builder.Services.AddAuthorization(); // ASP.NET Core's own registration
builder.Services.AddHttpContextAccessor();
builder.Services.AddMediarqAuthorization();
public record DeleteOrder(Guid OrderId) : ICommand, IAuthorizedRequest
{
public string? PolicyName => "OrdersAdmin";
}
PolicyNameset → evaluated viaIAuthorizationService.AuthorizeAsync(user, request, policyName), so a customIAuthorizationHandlercan inspect the request itself (e.g. checkingOrderIdownership), not just the policy name.PolicyNameset tonull→ only requires an authenticated user, no specific policy.- Not authenticated →
Result.Failure(ResultError.Unauthorized(...))(maps to HTTP 401 viaMediarq.AspNetCore). - Authenticated but the policy fails →
Result.Failure(ResultError.Forbidden(...))(HTTP 403). - Requests that don't implement
IAuthorizedRequestpass straight through — this behavior costs nothing for them (IConditionalPipelineBehavior.IsActiveisfalsefor their closed type, so the pipeline never even resolves it into the chain).
Response type
The handler's response type must be Result or Result<T> — the behavior needs some way to represent an
authorization failure as a value. Result is handled without reflection; Result<T> uses a
one-time-per-T reflection fallback (cached afterwards), so it is not on the Native AOT-safe path — the
same trade-off the core ValidationBehavior makes for its own Result<T> fallback.
Learn more
Wiring extensions · Full README
MIT © Nicolas Rouffart
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Mediarq.Core (>= 1.5.1)
- Microsoft.AspNetCore.Authorization (>= 2.3.0)
- Microsoft.AspNetCore.Http.Abstractions (>= 2.3.0)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 8.0.2)
-
net8.0
- Mediarq.Core (>= 1.5.1)
- Microsoft.AspNetCore.Authorization (>= 2.3.0)
- Microsoft.AspNetCore.Http.Abstractions (>= 2.3.0)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 8.0.2)
-
net9.0
- Mediarq.Core (>= 1.5.1)
- Microsoft.AspNetCore.Authorization (>= 2.3.0)
- Microsoft.AspNetCore.Http.Abstractions (>= 2.3.0)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 8.0.2)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.