Moongazing.Veil.AspNetCore 1.0.1

dotnet add package Moongazing.Veil.AspNetCore --version 1.0.1
                    
NuGet\Install-Package Moongazing.Veil.AspNetCore -Version 1.0.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Moongazing.Veil.AspNetCore" Version="1.0.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Moongazing.Veil.AspNetCore" Version="1.0.1" />
                    
Directory.Packages.props
<PackageReference Include="Moongazing.Veil.AspNetCore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Moongazing.Veil.AspNetCore --version 1.0.1
                    
#r "nuget: Moongazing.Veil.AspNetCore, 1.0.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Moongazing.Veil.AspNetCore@1.0.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Moongazing.Veil.AspNetCore&version=1.0.1
                    
Install as a Cake Addin
#tool nuget:?package=Moongazing.Veil.AspNetCore&version=1.0.1
                    
Install as a Cake Tool

<p align="center"> <img src="https://raw.githubusercontent.com/tunahanaliozturk/Veil/master/logo.png" alt="Moongazing.Veil" width="128" /> </p>

<h1 align="center">Moongazing.Veil.AspNetCore</h1>

<p align="center"> <strong>HTTP Request/Response PII Redaction Middleware for ASP.NET Core</strong><br /> <em>Powered by <a href="https://www.nuget.org/packages/Moongazing.Veil">Moongazing.Veil</a></em> </p>


Overview

Moongazing.Veil.AspNetCore is an ASP.NET Core middleware that automatically redacts sensitive data from HTTP request and response logs. It sanitizes headers, JSON body fields, and query string parameters before they reach your logging infrastructure.

Designed to work seamlessly with the Moongazing.Veil core library.


Installation

dotnet add package Moongazing.Veil.AspNetCore

This package depends on Moongazing.Veil (installed automatically).


Quick Start

// Program.cs
builder.Services.AddVeil();
builder.Services.AddVeilAspNetCore();

var app = builder.Build();
app.UseVeilRedaction();

That's it. Default configuration redacts Authorization, X-Api-Key, Cookie, and Set-Cookie headers out of the box.


Configuration

builder.Services.AddVeilAspNetCore(options =>
{
    // Enable request/response body logging with redaction
    options.LogRequests = true;
    options.LogResponses = true;
    options.MaxBodyLength = 4096;

    // Header redaction (defaults already include Authorization, X-Api-Key, Cookie)
    options.RedactHeaders("X-Custom-Secret", "X-Auth-Token");

    // JSON body field redaction using simple path syntax
    options.RedactBodyFields("$.password", "$.creditCard", "$.ssn", "$.token");

    // Query string parameter redaction
    options.RedactQueryParams("api_key", "token", "secret");

    // Conditional full-body redaction for specific endpoints
    options.RedactWhen(context =>
        context.Request.Path.StartsWithSegments("/api/payments"));
});

How It Works

The middleware intercepts the HTTP pipeline and performs the following:

  1. Request buffering -- Enables EnableBuffering() so the request body can be read and re-read.
  2. Response wrapping -- Wraps the response stream to capture the response body for logging.
  3. Header redaction -- Replaces values of configured headers with ***.
  4. Body redaction -- Parses JSON bodies and masks fields matching configured paths using Veil.Mask().
  5. Query string redaction -- Replaces values of configured query parameters with ***.
  6. Predicate-based redaction -- When a request matches a predicate, the entire body is treated as sensitive.

All redaction happens in-memory for logging purposes only. The actual request and response flowing through the pipeline are not modified.


Log Output Examples

Before:

[INF] POST /api/users | Body: {"email":"john@test.com","password":"secret123"}
[INF] GET /api/data?api_key=sk-abc123def456 | Authorization: Bearer eyJhbG...

After:

[INF] POST /api/users | Body: {"email":"j***@t***.com","password":"***"}
[INF] GET /api/data?api_key=*** | Authorization: ***

Configuration Reference

Property Type Default Description
LogRequests bool false Log redacted request bodies
LogResponses bool false Log redacted response bodies
MaxBodyLength int 4096 Maximum body length to capture (bytes)
RedactHeaders() params string[] Auth, Cookie defaults Headers whose values are replaced with ***
RedactBodyFields() params string[] (none) JSON paths to redact in request/response bodies
RedactQueryParams() params string[] (none) Query parameters to redact
RedactWhen() Func<HttpContext, bool> (none) Predicate for full-body redaction

Requirements

  • .NET 8.0 or .NET 9.0
  • ASP.NET Core

Package Description
Moongazing.Veil Core masking library
Moongazing.Veil.Serilog Serilog integration

License

MIT -- Copyright (c) Moongazing

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.1 135 6/14/2026
1.0.0 132 4/3/2026