Orbyss.Foundation.Authentication.BffCookie 0.3.0

dotnet add package Orbyss.Foundation.Authentication.BffCookie --version 0.3.0
                    
NuGet\Install-Package Orbyss.Foundation.Authentication.BffCookie -Version 0.3.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Orbyss.Foundation.Authentication.BffCookie" Version="0.3.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Orbyss.Foundation.Authentication.BffCookie" Version="0.3.0" />
                    
Directory.Packages.props
<PackageReference Include="Orbyss.Foundation.Authentication.BffCookie" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Orbyss.Foundation.Authentication.BffCookie --version 0.3.0
                    
#r "nuget: Orbyss.Foundation.Authentication.BffCookie, 0.3.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Orbyss.Foundation.Authentication.BffCookie@0.3.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Orbyss.Foundation.Authentication.BffCookie&version=0.3.0
                    
Install as a Cake Addin
#tool nuget:?package=Orbyss.Foundation.Authentication.BffCookie&version=0.3.0
                    
Install as a Cake Tool

Orbyss.Foundation.Authentication.BffCookie

Session, antiforgery and signed-out JSON now use registered typed response contracts with the shell's configured success-response budget. Anonymous/authenticated property sets, nullable display names, validated account strings and distinct ordinal permissions are preserved. The BFF selects Json.AspNetCore as a feature dependency; basic Authentication and Problem Details writing remain independent of global exception-feature activation. Permission projection is admitted incrementally before an array is retained; oversized output produces a safe 500 instead of a truncated success. Configured generated resolvers must cover the public BFF response types as well as application DTOs, or use deliberately separate profiles.

The Orbyss Foundation confidential OIDC BFF profile packaged as one CShells web/middleware feature. It owns cookie/OIDC authentication, server-side tickets, antiforgery validation, and /bff/* session endpoints. Activate Orbyss.Foundation.Authentication.BffCookie in exactly one shell authentication profile. The feature owns its OIDC metadata backchannel and honors the shared optional BackchannelAuthority while preserving the public issuer authority.

The feature registers the configured CallbackPath, SignedOutCallbackPath and RemoteSignOutPath as shell-owned GET/POST routes (defaults: /signin-oidc, /signout-callback-oidc, /signout-oidc). These routes let CShells select the owning shell before the OIDC middleware processes the request. They permit anonymous protocol requests, require the handler's normal state/correlation/token validation, use private/no-store response policy, and are excluded from OpenAPI descriptions. If the OIDC handler does not consume a matched request, the route returns a safe 400 authentication_callback_invalid response rather than accepting authentication.

Callback and access-denied paths must be distinct literal absolute paths relative to the shell, without route parameters, wildcards, query strings, fragments, escapes, dot segments or trailing slashes. They cannot replace built-in /bff/* session routes. For a shell with WebRouting:Path: "tenant", retain CallbackPath: "/signin-oidc" and register the resulting /tenant/signin-oidc redirect URI with the provider. Protocol failure redirects retain this shell path prefix.

OIDC projects issuer and subject from the validated token into the public reserved claim types, replacing token-supplied reserved values. Ticket admission then requires the exact projection claims to survive user-info claim actions: removal, replacement, duplication or reintroduction fails the callback. Cookie issuance, cookie revalidation and /bff/user use the shared validated identity reader. Issuer and subject values are never normalized. Application ownership remains application policy.

Server-held ticket keys are bound to the owning shell even when shells share a distributed cache. Foreign keys cannot be read, renewed or removed through another shell's ticket store. Existing validated claim URNs remain compatible. Older unbound session keys cannot establish shell ownership and therefore require a new login after this update; no account or persisted application identity changes.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.3.0 0 10/7/2026
0.2.4 219 10/4/2026
0.2.3 47 10/3/2026
0.2.2 135 9/16/2026
0.2.1 90 9/16/2026
0.2.0 108 9/12/2026
0.1.0 102 9/8/2026