YabbaDeck.AppBackend.AspNetCore
1.4.0
dotnet add package YabbaDeck.AppBackend.AspNetCore --version 1.4.0
NuGet\Install-Package YabbaDeck.AppBackend.AspNetCore -Version 1.4.0
<PackageReference Include="YabbaDeck.AppBackend.AspNetCore" Version="1.4.0" />
<PackageVersion Include="YabbaDeck.AppBackend.AspNetCore" Version="1.4.0" />
<PackageReference Include="YabbaDeck.AppBackend.AspNetCore" />
paket add YabbaDeck.AppBackend.AspNetCore --version 1.4.0
#r "nuget: YabbaDeck.AppBackend.AspNetCore, 1.4.0"
#:package YabbaDeck.AppBackend.AspNetCore@1.4.0
#addin nuget:?package=YabbaDeck.AppBackend.AspNetCore&version=1.4.0
#tool nuget:?package=YabbaDeck.AppBackend.AspNetCore&version=1.4.0
YabbaDeck.AppBackend.AspNetCore
The web half of an app backend on the YabbaDeck platform:
the platform's access tokens validated against its JWKS, the inbound client meta-headers resolved
into a request-scoped context, the app_name log scope, and the ping / livez / readyz /
version endpoints every service on the platform serves.
Pair it with YabbaDeck.AppBackend, which it references. That half has no ASP.NET Core
dependency, so a worker can take it alone — which is why these are two packages.
Wiring it up
builder.Services.AddYabbaDeckAppBackend<MyDbContext>(builder.Configuration);
builder.Services.AddYabbaDeckAppBackendWeb(builder.Configuration);
var app = builder.Build();
app.UseYabbaDeckAppBackend(); // the platform's middleware, in the one order that is correct
app.MapYabbaDeckAppBackend(); // /ping /version /livez /readyz
UseYabbaDeckAppBackend() runs the log scope, CORS, then the meta-headers, then authentication
and authorization. That ordering is load-bearing: the CORS middleware answers a preflight itself and
stops, and a preflight carries no credentials by specification — so anything that authenticated one
would answer 401 to a request the browser only sent to ask permission. Getting it wrong fails only
for the web build of a front end, only in a browser, with nothing in the server logs to find.
The four middlewares are public individually if you need to interleave your own. Keep the order.
No secret, ever
The platform signs app-user access tokens with RS256 and publishes the public half at
/.well-known/jwks.json. This package fetches that document and verifies signatures with it, so
nothing in your service can mint a token — which is exactly what makes handing the platform's tokens
to any number of app backends safe. An unknown kid triggers a refresh and one retry, so a key
rotation on the platform is a hiccup rather than an outage.
Validation checks the issuer, the audience (your app's public id — this is what stops a token minted for a neighbouring app being accepted here), RS256 and nothing else, and the lifetime.
[HttpGet("me")]
[Authorize]
public async Task<IActionResult> Me(CancellationToken cancellationToken)
{
if (!User.TryGetUserId(out var userId))
{
return Unauthorized();
}
await users.EnsureExistsAsync(userId, cancellationToken);
return Ok(new CurrentUserDto(userId, User.GetEmail()));
}
The id comes from the validated token and from nowhere else — never a route parameter or a body field, where it would be an invitation to act on a stranger's account.
What it deliberately does not do
- No authorization policy. Endpoints opt in with
[Authorize]. A fallback policy shipped in a package would silently lock every endpoint in every service that took an upgrade. - No health checks of its own.
/readyzevaluates whatever you taggedHealthCheckTags.Ready, because it is your service that has the connection strings. - No CORS origins. It reads them from
Cors:AllowedOrigins, and the default is empty — a deployment with no browser front end permits no browser caller.
MIT licensed. Part of the YabbaDeck platform.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- MassTransit (>= 8.5.10)
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.5)
- Microsoft.EntityFrameworkCore (>= 10.0.10)
- Microsoft.EntityFrameworkCore.Relational (>= 10.0.10)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.16.0)
- YabbaDeck.AppBackend (>= 1.4.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|