Pug.Application.Security.AzureADRoleProvider
0.0.2
dotnet add package Pug.Application.Security.AzureADRoleProvider --version 0.0.2
NuGet\Install-Package Pug.Application.Security.AzureADRoleProvider -Version 0.0.2
<PackageReference Include="Pug.Application.Security.AzureADRoleProvider" Version="0.0.2" />
<PackageVersion Include="Pug.Application.Security.AzureADRoleProvider" Version="0.0.2" />
<PackageReference Include="Pug.Application.Security.AzureADRoleProvider" />
paket add Pug.Application.Security.AzureADRoleProvider --version 0.0.2
#r "nuget: Pug.Application.Security.AzureADRoleProvider, 0.0.2"
#:package Pug.Application.Security.AzureADRoleProvider@0.0.2
#addin nuget:?package=Pug.Application.Security.AzureADRoleProvider&version=0.0.2
#tool nuget:?package=Pug.Application.Security.AzureADRoleProvider&version=0.0.2
Pug.Application.Security.AzureADRoleProvider
Microsoft Entra ID (formerly Azure AD) implementation of the
Pug.Application.Security
IPrincipalRoleProvider and IUserRoleProvider interfaces.
A role is an Entra app role of a chosen app registration: the provider reports the app role value
strings assigned to a principal — whether assigned to the principal directly or to any group the
principal is a (transitive) member of — i.e. the same roles that would appear in the roles claim of a
token issued for that application.
A principal may be any actor known to the tenant:
- a user, identified by object ID or user principal name; or
- an application, service, API or other resource — anything represented by a service principal — identified by service principal object ID or application (client) ID.
Identifiers are resolved in that order; unknown principals are reported as having no roles.
Authentication
Microsoft Graph is queried app-only (client credentials — client secret, certificate or managed identity). No signed-in user, delegated permission or interactive flow is involved, so the provider can be consumed by applications with or without user credentials.
The client identity requires the following Microsoft Graph application permissions, with admin
consent: User.Read.All, GroupMember.Read.All, Application.Read.All.
Usage
using Pug.Application.Security.AzureADRoleProvider;
IPrincipalRoleProvider roleProvider =
new PrincipalRoleProvider(
graphServiceClient,
new AzureADRoleProviderOptions { ApplicationId = applicationId } );
// user principal, by object ID or user principal name
bool authorized = await roleProvider.PrincipalIsInRoleAsync( "jane.doe@contoso.com", "Administrator" );
// application/service principal, by client ID or service principal object ID
bool trusted = await roleProvider.PrincipalIsInRoleAsync( callerClientId, "Integration" );
PrincipalIsInRoles returns true only when the principal is in all specified roles. Role name
comparison is case-sensitive (ordinal), matching Entra app role value semantics.
Resolved roles, app role definitions and role assignments are cached in memory for
AzureADRoleProviderOptions.CacheDuration (default 5 minutes); set it to TimeSpan.Zero to disable
caching.
For ASP.NET Core / IServiceCollection registration, use the companion package
Pug.Application.Security.AzureADRoleProvider.DependencyInjection.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net5.0 was computed. net5.0-windows was computed. net6.0 was computed. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
| .NET Core | netcoreapp2.0 was computed. netcoreapp2.1 was computed. netcoreapp2.2 was computed. netcoreapp3.0 was computed. netcoreapp3.1 was computed. |
| .NET Standard | netstandard2.0 is compatible. netstandard2.1 was computed. |
| .NET Framework | net461 was computed. net462 was computed. net463 was computed. net47 was computed. net471 was computed. net472 was computed. net48 was computed. net481 was computed. |
| MonoAndroid | monoandroid was computed. |
| MonoMac | monomac was computed. |
| MonoTouch | monotouch was computed. |
| Tizen | tizen40 was computed. tizen60 was computed. |
| Xamarin.iOS | xamarinios was computed. |
| Xamarin.Mac | xamarinmac was computed. |
| Xamarin.TVOS | xamarintvos was computed. |
| Xamarin.WatchOS | xamarinwatchos was computed. |
-
.NETStandard 2.0
- Microsoft.Graph (>= 6.2.0)
- Pug.Application.Security.Abstractions (>= 3.1.0)
-
net10.0
- Microsoft.Graph (>= 6.2.0)
- Pug.Application.Security.Abstractions (>= 3.1.0)
-
net8.0
- Microsoft.Graph (>= 6.2.0)
- Pug.Application.Security.Abstractions (>= 3.1.0)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Pug.Application.Security.AzureADRoleProvider:
| Package | Downloads |
|---|---|
|
Pug.Application.Security.AzureADRoleProvider.DependencyInjection
Dependency injection extensions for registering the Microsoft Entra ID (Azure AD) role provider for Pug.Application.Security. |
GitHub repositories
This package is not used by any popular GitHub repositories.