YabbaDeck.AppBackend.AspNetCore 1.4.0

The owner has unlisted this package. This could mean that the package is deprecated, has security vulnerabilities or shouldn't be used anymore.
dotnet add package YabbaDeck.AppBackend.AspNetCore --version 1.4.0
                    
NuGet\Install-Package YabbaDeck.AppBackend.AspNetCore -Version 1.4.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="YabbaDeck.AppBackend.AspNetCore" Version="1.4.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="YabbaDeck.AppBackend.AspNetCore" Version="1.4.0" />
                    
Directory.Packages.props
<PackageReference Include="YabbaDeck.AppBackend.AspNetCore" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add YabbaDeck.AppBackend.AspNetCore --version 1.4.0
                    
#r "nuget: YabbaDeck.AppBackend.AspNetCore, 1.4.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package YabbaDeck.AppBackend.AspNetCore@1.4.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=YabbaDeck.AppBackend.AspNetCore&version=1.4.0
                    
Install as a Cake Addin
#tool nuget:?package=YabbaDeck.AppBackend.AspNetCore&version=1.4.0
                    
Install as a Cake Tool

YabbaDeck.AppBackend.AspNetCore

The web half of an app backend on the YabbaDeck platform: the platform's access tokens validated against its JWKS, the inbound client meta-headers resolved into a request-scoped context, the app_name log scope, and the ping / livez / readyz / version endpoints every service on the platform serves.

Pair it with YabbaDeck.AppBackend, which it references. That half has no ASP.NET Core dependency, so a worker can take it alone — which is why these are two packages.

Wiring it up

builder.Services.AddYabbaDeckAppBackend<MyDbContext>(builder.Configuration);
builder.Services.AddYabbaDeckAppBackendWeb(builder.Configuration);

var app = builder.Build();

app.UseYabbaDeckAppBackend();   // the platform's middleware, in the one order that is correct
app.MapYabbaDeckAppBackend();   // /ping /version /livez /readyz

UseYabbaDeckAppBackend() runs the log scope, CORS, then the meta-headers, then authentication and authorization. That ordering is load-bearing: the CORS middleware answers a preflight itself and stops, and a preflight carries no credentials by specification — so anything that authenticated one would answer 401 to a request the browser only sent to ask permission. Getting it wrong fails only for the web build of a front end, only in a browser, with nothing in the server logs to find.

The four middlewares are public individually if you need to interleave your own. Keep the order.

No secret, ever

The platform signs app-user access tokens with RS256 and publishes the public half at /.well-known/jwks.json. This package fetches that document and verifies signatures with it, so nothing in your service can mint a token — which is exactly what makes handing the platform's tokens to any number of app backends safe. An unknown kid triggers a refresh and one retry, so a key rotation on the platform is a hiccup rather than an outage.

Validation checks the issuer, the audience (your app's public id — this is what stops a token minted for a neighbouring app being accepted here), RS256 and nothing else, and the lifetime.

[HttpGet("me")]
[Authorize]
public async Task<IActionResult> Me(CancellationToken cancellationToken)
{
    if (!User.TryGetUserId(out var userId))
    {
        return Unauthorized();
    }

    await users.EnsureExistsAsync(userId, cancellationToken);

    return Ok(new CurrentUserDto(userId, User.GetEmail()));
}

The id comes from the validated token and from nowhere else — never a route parameter or a body field, where it would be an invitation to act on a stranger's account.

What it deliberately does not do

  • No authorization policy. Endpoints opt in with [Authorize]. A fallback policy shipped in a package would silently lock every endpoint in every service that took an upgrade.
  • No health checks of its own. /readyz evaluates whatever you tagged HealthCheckTags.Ready, because it is your service that has the connection strings.
  • No CORS origins. It reads them from Cors:AllowedOrigins, and the default is empty — a deployment with no browser front end permits no browser caller.

MIT licensed. Part of the YabbaDeck platform.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated