RscCentral.Service.Lib
0.2.0
dotnet add package RscCentral.Service.Lib --version 0.2.0
NuGet\Install-Package RscCentral.Service.Lib -Version 0.2.0
<PackageReference Include="RscCentral.Service.Lib" Version="0.2.0" />
<PackageVersion Include="RscCentral.Service.Lib" Version="0.2.0" />
<PackageReference Include="RscCentral.Service.Lib" />
paket add RscCentral.Service.Lib --version 0.2.0
#r "nuget: RscCentral.Service.Lib, 0.2.0"
#:package RscCentral.Service.Lib@0.2.0
#addin nuget:?package=RscCentral.Service.Lib&version=0.2.0
#tool nuget:?package=RscCentral.Service.Lib&version=0.2.0
Resource Central service library
A set of functions that help integrate a service app into Resource Central.
Published to NuGet as RscCentral.Service.Lib.
Releasing
Releases are cut by pushing a tag of the form service-lib-vX.Y.Z to the rsc-central repository. The .github/workflows/publish-service-lib.yml workflow then builds service-lib/service-lib.csproj, packs it with the version derived from the tag (the service-lib-v prefix is stripped), and pushes the resulting .nupkg to nuget.org using the NUGET_API_KEY secret.
Example:
git tag service-lib-v0.1.0
git push origin service-lib-v0.1.0
The tag prefix is required so this workflow doesn't fire on tags used by other publishing workflows in this repo.
Bundled dependencies
The published package is self-contained: the sibling rsc-central libraries it depends on (lib, auth-lib, auth-api-lib, openapi-lib) are embedded as assemblies inside the .nupkg rather than declared as NuGet package dependencies. Consumers therefore get the public types from those libraries (e.g. RscCentral.Auth.Api.Lib.CustomClaimsPrincipal, RscCentral.Lib.OpenApi) without needing to install anything else.
This is implemented in service-lib.csproj via PrivateAssets="all" on the ProjectReference entries plus the CopyProjectReferencesToPackage target. If any of those sibling libraries are later published to NuGet in their own right, this bundling should be removed to avoid duplicate-assembly conflicts in downstream consumers.
Accepting delegated credentials
Service Central can be switched, per service version, from forwarding the caller's own credential to minting a short-lived token targeting this service. A service has to opt in on its side first, by naming its own audience:
builder.Services
.AddServiceAuthService(builder.Configuration)
.AddOpenApiServiceServices(builder.Configuration)
.AddServiceAuthentication(builder.Configuration, builder.Environment.IsDevelopment());
AddServiceAuthentication replaces a direct call to AddResourceCentralAuthentication. It reads
Service:Tag from configuration, derives the audience service/<tag>, and turns on audience
validation -- so a token minted for a different service is refused here even though the same
auth-server signed it. It throws at startup if Service:Tag is missing, rather than quietly
accepting any audience.
Nothing else changes. The token still carries the caller as its sub, so log lines and
authorization decisions are unaffected, and IServiceAuthService needs no changes -- the
capabilities arrive narrowed to this service's own subtree, which is the only part of them this
service ever asks about.
Two things to know before switching a service over in the admin UI:
- This version is not a prerequisite for switching, only for the audience check. A service running an older service-lib does not validate the audience, so it accepts a delegated token as readily as a forwarded one -- meaning the caller's API key stops reaching it either way. What this version adds is the refusal: without it, a token minted for one service would also be accepted by another.
- A caller holding an ancestor capability sees it narrowed, whatever version is deployed.
service:readarrives asservice/<tag>:read, because minting narrows capabilities to this service's own subtree.IServiceAuthServicehandles that; a service that checks for the literal ancestor string itself will stop matching, so checkservice/<tag>/...paths instead. This is the one thing worth verifying in a service's own code before switching it.
Contents
RscCentral.Service.Lib—ServiceOptions,ServiceUtils,ServiceExtensions.AddServiceAuthService,ServiceExtensions.AddServiceAuthenticationRscCentral.Service.Lib.Services—IServiceAuthService/ServiceAuthServiceRscCentral.Service.Lib.Validation—ServiceTagAttribute,ServiceVersionAttributeRscCentral.Service.Lib.OpenApi—AddOpenApiServiceServices,AddServiceOpenApi,MapServiceRoot
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Azure.Monitor.OpenTelemetry.AspNetCore (>= 1.6.0)
- Azure.Monitor.OpenTelemetry.Exporter (>= 1.8.3)
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.10)
- Microsoft.AspNetCore.OpenApi (>= 10.0.10)
- Microsoft.Extensions.Http.Resilience (>= 10.8.0)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.22.0)
- Microsoft.OpenApi (>= 2.7.5)
- NodaTime (>= 3.3.3)
- NodaTime.Serialization.SystemTextJson (>= 1.4.0)
- OpenTelemetry.Extensions.Hosting (>= 1.17.0)
- Scalar.AspNetCore (>= 2.16.17)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|