Rwx.Security
0.3.1
dotnet add package Rwx.Security --version 0.3.1
NuGet\Install-Package Rwx.Security -Version 0.3.1
<PackageReference Include="Rwx.Security" Version="0.3.1" />
<PackageVersion Include="Rwx.Security" Version="0.3.1" />
<PackageReference Include="Rwx.Security" />
paket add Rwx.Security --version 0.3.1
#r "nuget: Rwx.Security, 0.3.1"
#:package Rwx.Security@0.3.1
#addin nuget:?package=Rwx.Security&version=0.3.1
#tool nuget:?package=Rwx.Security&version=0.3.1
Rwx.Security
Current-user abstraction and event-bus metadata enrichment for the Rwx framework.
Install
dotnet add package Rwx.Security --version 0.1.0
Quick start
using Rwx.Security;
builder.Services.AddRwxSecurity();
AddRwxSecurity() registers ABP-style claims-based ICurrentUser services. ICurrentPrincipalAccessor.Change(...) temporarily overrides the principal for the current async flow. In an ASP.NET Core host, call AddRwxAspNetSecurity() from Rwx.AspNet to use HttpContext.User as the default principal.
ICurrentUser exposes claim helpers plus the authenticated user's UserId, Id, UserName, Name, roles, OrgId, and DepartmentId.
For messages published through an already-registered IEventBus, call AddRwxEventBusSecurityEnrichment() to add the current OrgId, UserId, and DepartmentId as message headers automatically.
builder.Services.AddRwxSecurity();
builder.Services.AddRwxMessaging(builder.Configuration, typeof(OrderPlaced).Assembly);
builder.Services.AddRwxEventBusSecurityEnrichment();
On the receiving side, a handler reads those same headers back through Rwx.EventBus.Abstractions's IncomingEventContext — see that package's README. There is deliberately no equivalent AddRwx* call that re-hydrates ICurrentPrincipalAccessor from incoming headers: see Boundaries below.
Boundaries
ICurrentUserAccessor provides request/work metadata, not authorization policy. Domain entities must not access it. Message headers are contextual metadata and must be treated as untrusted at a receiving service; authenticate and authorize at that service's boundary. Never decorate IIntegrationEventHandler<T> to set ICurrentPrincipalAccessor/ICurrentUser from IncomingEventContext — that would let any message on the bus impersonate an org or user with no authentication.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.9)
- Microsoft.Extensions.DependencyInjection (>= 10.0.9)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.9)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.9)
- Microsoft.Extensions.Logging (>= 10.0.9)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.9)
- Rwx.Core (>= 0.3.1)
- Rwx.EventBus.Abstractions (>= 0.3.1)
- Scrutor (>= 7.0.0)
NuGet packages (3)
Showing the top 3 NuGet packages that depend on Rwx.Security:
| Package | Downloads |
|---|---|
|
Rwx.Persistence.EfCore
Package Description |
|
|
Rwx.AspNet
Package Description |
|
|
Rwx.Authorization
Package Description |
GitHub repositories
This package is not used by any popular GitHub repositories.