Rwd.IAM.Client.AspNetCore
2.0.2
dotnet add package Rwd.IAM.Client.AspNetCore --version 2.0.2
NuGet\Install-Package Rwd.IAM.Client.AspNetCore -Version 2.0.2
<PackageReference Include="Rwd.IAM.Client.AspNetCore" Version="2.0.2" />
<PackageVersion Include="Rwd.IAM.Client.AspNetCore" Version="2.0.2" />
<PackageReference Include="Rwd.IAM.Client.AspNetCore" />
paket add Rwd.IAM.Client.AspNetCore --version 2.0.2
#r "nuget: Rwd.IAM.Client.AspNetCore, 2.0.2"
#:package Rwd.IAM.Client.AspNetCore@2.0.2
#addin nuget:?package=Rwd.IAM.Client.AspNetCore&version=2.0.2
#tool nuget:?package=Rwd.IAM.Client.AspNetCore&version=2.0.2
Rwd.IAM.Client.AspNetCore
Optional helpers for ASP.NET Core on top of Rwd.IAM.Client: bearer middleware (validates JWT and sets HttpContext.User), permission filters, and minimal API extensions.
1. Bearer validation middleware (recommended flow)
Registers IAM JWT validation once in the pipeline: reads Authorization: Bearer, calls IIamAccessTokenValidator, assigns HttpContext.User. Endpoints marked [AllowAnonymous] are skipped.
Program.cs example
using Rwd.IAM.Client.AspNetCore;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddRwdIamAccessTokenValidation(o =>
{
o.BaseUrl = new Uri(builder.Configuration["Iam:ApiBaseUrl"]!);
o.IssuerUrl = new Uri(builder.Configuration["Iam:IssuerUrl"]!);
o.RealmName = builder.Configuration["Iam:Realm"]!;
// Central services may trust several realms:
// o.TrustedRealmNames = ["citizens", "main", "master"];
});
builder.Services.AddIamBearerAuthentication(o =>
{
o.Audience = builder.Configuration["Iam:ApiAudience"]; // e.g. "dms-api"; recommended
o.AllowAnonymousWhenMissingBearer = true; // default: no Bearer → anonymous
});
builder.Services.AddControllers();
builder.Services.AddAuthorization();
var app = builder.Build();
app.UseRouting();
// After routing (so [AllowAnonymous] / endpoint metadata is visible)
app.UseIamBearerAuthentication();
app.UseAuthorization();
app.MapControllers();
app.Run();
Controller
[ApiController]
[Route("api/[controller]")]
[Authorize] // user must be authenticated (middleware set HttpContext.User)
public class DistrictsController : ControllerBase
{
[AllowAnonymous]
[HttpGet("public")]
public IActionResult Public() => Ok();
[HttpGet("secure")]
[RequireIamPermission("districts", "view")]
public IActionResult Secure() => Ok();
}
Order matters: UseRouting → UseIamBearerAuthentication → UseAuthorization → Map*.
If you omit AddIamBearerAuthentication(), options still default; call it when you need Audience or AllowAnonymousWhenMissingBearer.
2. MVC — [RequireIamPermission] only (no middleware)
If you already set HttpContext.User elsewhere, use the attribute alone:
[HttpGet]
[RequireIamPermission("districts", "view")]
public IActionResult List() => Ok();
Multiple attributes = AND. Alternative: [RequireIamPermission("districts:view")].
3. Minimal APIs
app.MapGet("/districts", () => Results.Ok())
.RequireIamPermission("districts", "view");
With middleware, add RequireAuthorization() on routes that need a validated user:
app.MapGet("/districts", () => Results.Ok())
.RequireAuthorization()
.RequireIamPermission("districts", "view");
Packages
dotnet add package Rwd.IAM.Client
dotnet add package Rwd.IAM.Client.AspNetCore
Version both together when publishing from this repository.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Rwd.IAM.Client (>= 2.0.2)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.