RepletoryLib.Auth.Permissions 1.0.0

dotnet add package RepletoryLib.Auth.Permissions --version 1.0.0
                    
NuGet\Install-Package RepletoryLib.Auth.Permissions -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="RepletoryLib.Auth.Permissions" Version="1.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="RepletoryLib.Auth.Permissions" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="RepletoryLib.Auth.Permissions" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add RepletoryLib.Auth.Permissions --version 1.0.0
                    
#r "nuget: RepletoryLib.Auth.Permissions, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package RepletoryLib.Auth.Permissions@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=RepletoryLib.Auth.Permissions&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=RepletoryLib.Auth.Permissions&version=1.0.0
                    
Install as a Cake Tool

RepletoryLib.Auth.Permissions

Permission-based authorization with [RequirePermission] attribute and policy provider for ASP.NET Core.

Part of the RepletoryLib ecosystem -- standalone, reusable .NET 10 libraries with zero business logic.

NuGet .NET 10 License: MIT


Overview

RepletoryLib.Auth.Permissions adds declarative, permission-based authorization to ASP.NET Core. Instead of checking roles, you decorate controllers and actions with [RequirePermission("orders.read")] and the framework handles the rest through a custom IAuthorizationPolicyProvider and AuthorizationHandler.

Key Features

  • [RequirePermission] attribute -- Declarative permission checks on controllers/actions
  • Dynamic policy provider -- Auto-creates authorization policies from permission names
  • ICurrentUserService integration -- Checks permissions via HasPermission()
  • Fine-grained RBAC -- Permission-level control instead of coarse role checks

Installation

dotnet add package RepletoryLib.Auth.Permissions

Dependencies

Package Type
RepletoryLib.Common RepletoryLib

Quick Start

using RepletoryLib.Auth.Permissions;

var builder = WebApplication.CreateBuilder(args);
builder.Services.AddRepletoryPermissions();

Usage Examples

Decorating Controllers

using RepletoryLib.Auth.Permissions.Attributes;

[ApiController]
[Route("api/[controller]")]
public class OrdersController : ControllerBase
{
    [HttpGet]
    [RequirePermission("orders.read")]
    public IActionResult GetOrders() => Ok(_orderService.GetAll());

    [HttpPost]
    [RequirePermission("orders.create")]
    public IActionResult CreateOrder(CreateOrderRequest request) => Ok(_orderService.Create(request));

    [HttpDelete("{id}")]
    [RequirePermission("orders.delete")]
    public IActionResult DeleteOrder(Guid id)
    {
        _orderService.Delete(id);
        return NoContent();
    }
}

How It Works

  1. [RequirePermission("orders.read")] translates to policy name "Permission:orders.read"
  2. PermissionPolicyProvider creates a policy with a PermissionAuthorizationRequirement
  3. PermissionAuthorizationHandler calls ICurrentUserService.HasPermission("orders.read")
  4. If the user has the permission, access is granted; otherwise, 403 Forbidden

Implementing ICurrentUserService

Your ICurrentUserService implementation must return true from HasPermission() for the user's assigned permissions:

public class HttpCurrentUserService : ICurrentUserService
{
    // ... other properties ...

    public bool HasPermission(string permission)
    {
        return _httpContext?.User.HasClaim("permission", permission) ?? false;
    }
}

Integration with Other RepletoryLib Packages

Package Relationship
RepletoryLib.Common ICurrentUserService for permission checks
RepletoryLib.Auth.Jwt JWT tokens carry permission claims; provides ICurrentUserService

License

This project is licensed under the MIT License.

Copyright (c) 2024-2026 Repletory.


For complete documentation, infrastructure setup, and configuration reference, see the RepletoryLib main repository.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 140 3/2/2026