Moongazing.Veil.AspNetCore
1.0.1
dotnet add package Moongazing.Veil.AspNetCore --version 1.0.1
NuGet\Install-Package Moongazing.Veil.AspNetCore -Version 1.0.1
<PackageReference Include="Moongazing.Veil.AspNetCore" Version="1.0.1" />
<PackageVersion Include="Moongazing.Veil.AspNetCore" Version="1.0.1" />
<PackageReference Include="Moongazing.Veil.AspNetCore" />
paket add Moongazing.Veil.AspNetCore --version 1.0.1
#r "nuget: Moongazing.Veil.AspNetCore, 1.0.1"
#:package Moongazing.Veil.AspNetCore@1.0.1
#addin nuget:?package=Moongazing.Veil.AspNetCore&version=1.0.1
#tool nuget:?package=Moongazing.Veil.AspNetCore&version=1.0.1
<p align="center"> <img src="https://raw.githubusercontent.com/tunahanaliozturk/Veil/master/logo.png" alt="Moongazing.Veil" width="128" /> </p>
<h1 align="center">Moongazing.Veil.AspNetCore</h1>
<p align="center"> <strong>HTTP Request/Response PII Redaction Middleware for ASP.NET Core</strong><br /> <em>Powered by <a href="https://www.nuget.org/packages/Moongazing.Veil">Moongazing.Veil</a></em> </p>
Overview
Moongazing.Veil.AspNetCore is an ASP.NET Core middleware that automatically redacts sensitive data from HTTP request and response logs. It sanitizes headers, JSON body fields, and query string parameters before they reach your logging infrastructure.
Designed to work seamlessly with the Moongazing.Veil core library.
Installation
dotnet add package Moongazing.Veil.AspNetCore
This package depends on Moongazing.Veil (installed automatically).
Quick Start
// Program.cs
builder.Services.AddVeil();
builder.Services.AddVeilAspNetCore();
var app = builder.Build();
app.UseVeilRedaction();
That's it. Default configuration redacts Authorization, X-Api-Key, Cookie, and Set-Cookie headers out of the box.
Configuration
builder.Services.AddVeilAspNetCore(options =>
{
// Enable request/response body logging with redaction
options.LogRequests = true;
options.LogResponses = true;
options.MaxBodyLength = 4096;
// Header redaction (defaults already include Authorization, X-Api-Key, Cookie)
options.RedactHeaders("X-Custom-Secret", "X-Auth-Token");
// JSON body field redaction using simple path syntax
options.RedactBodyFields("$.password", "$.creditCard", "$.ssn", "$.token");
// Query string parameter redaction
options.RedactQueryParams("api_key", "token", "secret");
// Conditional full-body redaction for specific endpoints
options.RedactWhen(context =>
context.Request.Path.StartsWithSegments("/api/payments"));
});
How It Works
The middleware intercepts the HTTP pipeline and performs the following:
- Request buffering -- Enables
EnableBuffering()so the request body can be read and re-read. - Response wrapping -- Wraps the response stream to capture the response body for logging.
- Header redaction -- Replaces values of configured headers with
***. - Body redaction -- Parses JSON bodies and masks fields matching configured paths using
Veil.Mask(). - Query string redaction -- Replaces values of configured query parameters with
***. - Predicate-based redaction -- When a request matches a predicate, the entire body is treated as sensitive.
All redaction happens in-memory for logging purposes only. The actual request and response flowing through the pipeline are not modified.
Log Output Examples
Before:
[INF] POST /api/users | Body: {"email":"john@test.com","password":"secret123"}
[INF] GET /api/data?api_key=sk-abc123def456 | Authorization: Bearer eyJhbG...
After:
[INF] POST /api/users | Body: {"email":"j***@t***.com","password":"***"}
[INF] GET /api/data?api_key=*** | Authorization: ***
Configuration Reference
| Property | Type | Default | Description |
|---|---|---|---|
LogRequests |
bool |
false |
Log redacted request bodies |
LogResponses |
bool |
false |
Log redacted response bodies |
MaxBodyLength |
int |
4096 |
Maximum body length to capture (bytes) |
RedactHeaders() |
params string[] |
Auth, Cookie defaults | Headers whose values are replaced with *** |
RedactBodyFields() |
params string[] |
(none) | JSON paths to redact in request/response bodies |
RedactQueryParams() |
params string[] |
(none) | Query parameters to redact |
RedactWhen() |
Func<HttpContext, bool> |
(none) | Predicate for full-body redaction |
Requirements
- .NET 8.0 or .NET 9.0
- ASP.NET Core
Related Packages
| Package | Description |
|---|---|
Moongazing.Veil |
Core masking library |
Moongazing.Veil.Serilog |
Serilog integration |
License
MIT -- Copyright (c) Moongazing
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Moongazing.Veil (>= 1.0.1)
-
net8.0
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 9.0.3)
- Microsoft.Extensions.Options (>= 9.0.3)
- Moongazing.Veil (>= 1.0.1)
-
net9.0
- Moongazing.Veil (>= 1.0.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
See the changelog: https://github.com/tunahanaliozturk/Veil/blob/master/CHANGELOG.md