WebGate.Azure.FunctionsUtils
10.0.0
See the version list below for details.
dotnet add package WebGate.Azure.FunctionsUtils --version 10.0.0
NuGet\Install-Package WebGate.Azure.FunctionsUtils -Version 10.0.0
<PackageReference Include="WebGate.Azure.FunctionsUtils" Version="10.0.0" />
<PackageVersion Include="WebGate.Azure.FunctionsUtils" Version="10.0.0" />
<PackageReference Include="WebGate.Azure.FunctionsUtils" />
paket add WebGate.Azure.FunctionsUtils --version 10.0.0
#r "nuget: WebGate.Azure.FunctionsUtils, 10.0.0"
#:package WebGate.Azure.FunctionsUtils@10.0.0
#addin nuget:?package=WebGate.Azure.FunctionsUtils&version=10.0.0
#tool nuget:?package=WebGate.Azure.FunctionsUtils&version=10.0.0
WebGate.Azure.FunctionsUtils
Helpers for Azure Functions. The library provides FunctionRunContext types that expose user or application identity, UPN, roles, authentication state, request payload parsing, and local development detection.
Package: WebGate.Azure.FunctionsUtils
License: Apache-2.0
dotnet add package WebGate.Azure.FunctionsUtils
Target Framework & Versioning
| Target Framework | net10.0 |
| Package version | 10.x.x |
The NuGet package major version matches the .NET target framework major version.
net10.0→ package version10.x.x- A future uplift to
net11.0would start at package version11.0.0
Within a major line, use minor/patch for library changes that stay on the same TFM.
Environments
AZURE_FUNCTIONS_ENVIRONMENT distinguishes where the functions run:
| Value | Meaning | Auth behavior | IsDev() |
|---|---|---|---|
LocalDevelopment |
Functions on a developer machine | Easy Auth if present, otherwise validated Bearer JWT | true |
Development |
Azure cloud DEV environment | Easy Auth only | false |
Staging / Production / other |
Azure cloud environments | Easy Auth only | false |
Important: Azure’s usual Development value means the cloud DEV slot, not local execution. For local runs set AZURE_FUNCTIONS_ENVIRONMENT=LocalDevelopment in local.settings.json.
Security model
Headers alone are not trusted. Protect cloud Function Apps like this:
Internet → Azure API Management (validate-jwt) → Function App (Easy Auth Required) → UserFunctionRunContext
Easy Auth required (cloud environments)
On the Function App, enable App Service Authentication / Easy Auth and set unauthenticated requests to Return HTTP 401. Easy Auth strips client-suppliedx-ms-client-principal*headers and replaces them after a successful Entra ID login.
Whenever the environment is notLocalDevelopment, this library accepts only Easy Auth (x-ms-client-principal). Bearer fallback is disabled.Do not expose the Function App publicly
Prefer private networking and put Azure API Management in front. Use an APIMvalidate-jwtpolicy against Entra ID (issuer, audience, signing keys) before traffic reaches the Function App.Example APIM fragment:
<validate-jwt header-name="Authorization" failed-validation-httpcode="401"> <openid-config url="https://login.microsoftonline.com/{tenant-id}/v2.0/.well-known/openid-configuration" /> <audiences> <audience>{api-app-id-or-uri}</audience> </audiences> </validate-jwt>Bearer JWT cryptographic validation (
LocalDevelopmentonly)
On a developer machine (AZURE_FUNCTIONS_ENVIRONMENT=LocalDevelopment), if Easy Auth is absent, the library may fall back toAuthorization: Bearer. That token is validated (signature, issuer, audience, lifetime) via Entra OpenID metadata — decode-only is not used.Example
local.settings.json:{ "Values": { "AZURE_FUNCTIONS_ENVIRONMENT": "LocalDevelopment", "FUNCTIONS_UTILS_AAD_TENANT_ID": "{tenant-id}", "FUNCTIONS_UTILS_AAD_AUDIENCE": "{api-app-id-or-uri}" } }Variable Purpose FUNCTIONS_UTILS_AAD_TENANT_IDEntra tenant ID FUNCTIONS_UTILS_AAD_AUDIENCEAPI audience (app ID or Application ID URI) If either variable is missing, Bearer fallback fails closed (
IsAuthenticated() == false).
FunctionRunContext
Public entry points:
| Type | Purpose |
|---|---|
UserFunctionRunContext |
User identity from HTTP request headers |
AppFunctionRunContext |
Application identity from explicit id and roles |
IFunctionRunContext |
Shared API for identity, roles, payload, and environment |
Shared API (IFunctionRunContext):
GetUserId(),GetUPN(),IsAuthenticated(),IsDev()IsInAtLeastOneRole(...),IsInAllRoles(...)GetPayLoad<T>()— reads JSON body from the associatedHttpRequest(user context only)GetEnvironmentVariable(name)
UserFunctionRunContext also exposes GetClaimsPrincipal().
IsDev() follows the Environments table (LocalDevelopment only).
UserFunctionRunContext
Identity is resolved in this order:
- Azure Easy Auth payload from
x-ms-client-principal(all environments) - Validated JWT from
Authorization: Bearer <token>(LocalDevelopmentonly; requires tenant/audience env vars)
Claim mapping:
| Field | Claims (first match wins) |
|---|---|
| User ID | oid, Easy Auth object identifier URI, sub, name identifier URI |
| UPN | upn, Easy Auth UPN URI, preferred_username |
| Roles | roles |
Authenticated is true when a user ID was resolved.
[Function("MyCoolFunction")]
public async Task<IActionResult> MyCoolFunction(
[HttpTrigger(AuthorizationLevel.Anonymous, "get", Route = "users/me")] HttpRequest req)
{
var context = new UserFunctionRunContext(req);
if (!context.IsAuthenticated())
{
return new UnauthorizedResult();
}
var userId = context.GetUserId();
return new OkObjectResult(userId);
}
AppFunctionRunContext
Use for non-user / application callers. Pass application id and roles explicitly; no HTTP headers are parsed.
var context = new AppFunctionRunContext(applicationId, roles: ["reader"]);
var appId = context.GetUserId();
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.IdentityModel.Protocols.OpenIdConnect (>= 8.22.0)
- System.IdentityModel.Tokens.Jwt (>= 8.22.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 10.0.2 | 116 | 8/4/2026 |
| 10.0.1 | 99 | 8/4/2026 |
| 10.0.0 | 110 | 8/3/2026 |
| 0.1.0-alpha-3 | 1,235 | 8/10/2024 |
| 0.1.0-alpha-2 | 188 | 8/9/2024 |
| 0.1.0-alpha-1 | 394 | 6/10/2024 |