Yeditepe.Auth
1.0.1
dotnet add package Yeditepe.Auth --version 1.0.1
NuGet\Install-Package Yeditepe.Auth -Version 1.0.1
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Yeditepe.Auth" Version="1.0.1" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Yeditepe.Auth" Version="1.0.1" />
<PackageReference Include="Yeditepe.Auth" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Yeditepe.Auth --version 1.0.1
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Yeditepe.Auth, 1.0.1"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Yeditepe.Auth@1.0.1
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Yeditepe.Auth&version=1.0.1
#tool nuget:?package=Yeditepe.Auth&version=1.0.1
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Yeditepe.Auth
Yeditepe Pro uygulamaları için paylaşımlı authentication kütüphanesi. Identity Platform ve CorpPanel ile entegre multi-tenant authentication servisleri sağlar.
Kurulum
dotnet add package Yeditepe.Auth
Özellikler
- Multi-tenant Authentication: Kullanıcılar birden fazla tenant'a erişebilir
- JWT Token Yönetimi: Access token üretimi, doğrulama ve decode işlemleri
- Role & Permission Tabanlı Yetkilendirme: CorpPanel'den alınan rol ve izinler
- Identity Platform Entegrasyonu: Login, refresh, logout işlemleri
- CorpPanel Entegrasyonu: Tenant bilgileri ve yetkilendirme
- Tenant Context Middleware: JWT'den tenant bilgilerini otomatik çıkarma
- Önbellekleme Desteği: Yetkilendirme sonuçları için memory cache
Yapılandırma
appsettings.json
{
"YeditepeAuth": {
"ApplicationId": "00000000-0000-0000-0000-000000000000",
"ApplicationCode": "WmsPro",
"Identity": {
"BaseUrl": "https://identity.yeditepe.com",
"TimeoutSeconds": 30,
"RetryCount": 3
},
"CorpPanel": {
"BaseUrl": "https://corppanel.yeditepe.com",
"ApiKey": "your-internal-api-key",
"TimeoutSeconds": 30,
"RetryCount": 3,
"EnableCaching": true,
"CacheExpirationSeconds": 300
},
"Jwt": {
"SigningKey": "your-256-bit-secret-key-here-min-32-chars",
"Issuer": "https://wmspro.yeditepe.com",
"Audience": "wmspro-api",
"AccessTokenMinutes": 60,
"ValidateLifetime": true,
"ClockSkewMinutes": 5
}
}
}
Program.cs
using Yeditepe.Auth.Extensions;
var builder = WebApplication.CreateBuilder(args);
// Yeditepe Auth servislerini ekle
builder.Services.AddYeditepeAuth(builder.Configuration);
var app = builder.Build();
// Authentication middleware
app.UseAuthentication();
app.UseAuthorization();
// Tenant context middleware (opsiyonel)
app.UseTenantContext();
app.MapControllers();
app.Run();
Kullanım
Auth Controller Oluşturma
using Yeditepe.Auth.Controllers;
[ApiController]
[Route("api/v1/auth")]
public class AuthController : YeditepeAuthControllerBase
{
public AuthController(
IIdentityClient identityClient,
ICorpPanelClient corpPanelClient,
ITokenService tokenService,
IOptions<YeditepeAuthOptions> options)
: base(identityClient, corpPanelClient, tokenService, options)
{
}
// Login, Refresh, SwitchTenant, Logout, GetTenants
// endpoint'leri otomatik olarak miras alınır
}
Current User Servisi
public class OrderService
{
private readonly ICurrentUserService _currentUser;
public OrderService(ICurrentUserService currentUser)
{
_currentUser = currentUser;
}
public async Task CreateOrder(CreateOrderRequest request)
{
// Kullanıcı bilgilerine erişim
var userId = _currentUser.UserId;
var tenantId = _currentUser.TenantId;
var email = _currentUser.Email;
// Yetki kontrolü
if (!_currentUser.HasPermission("orders.create"))
{
throw new UnauthorizedAccessException();
}
// Rol kontrolü
if (_currentUser.IsInRole("Admin"))
{
// Admin özel işlemleri
}
}
}
ClaimsPrincipal Extension'ları
[Authorize]
public class ProductsController : ControllerBase
{
[HttpGet]
public IActionResult GetProducts()
{
// User üzerinden extension metodları
var userId = User.GetUserId();
var tenantId = User.GetTenantId();
var tenantCode = User.GetTenantCode();
var roles = User.GetRoles();
var permissions = User.GetPermissions();
// Yetki kontrolü
if (User.HasPermission("products.read"))
{
// ...
}
if (User.HasAnyPermission("products.read", "products.admin"))
{
// ...
}
if (User.HasAllPermissions("products.read", "products.write"))
{
// ...
}
return Ok();
}
}
Token Servisi
public class CustomAuthService
{
private readonly ITokenService _tokenService;
public CustomAuthService(ITokenService tokenService)
{
_tokenService = tokenService;
}
public ClaimsPrincipal? ValidateExternalToken(string token)
{
// Token doğrulama
var principal = _tokenService.ValidateToken(token);
if (principal is null)
{
return null;
}
// Token'dan bilgi çıkarma
var userId = _tokenService.GetUserId(principal);
var tenantId = _tokenService.GetTenantId(principal);
var deviceId = _tokenService.GetDeviceId(principal);
return principal;
}
}
API Endpoints
Base controller aşağıdaki endpoint'leri sağlar:
| Method | Endpoint | Açıklama |
|---|---|---|
| POST | /api/v1/auth/login |
Kullanıcı girişi |
| POST | /api/v1/auth/refresh |
Token yenileme |
| POST | /api/v1/auth/switch-tenant |
Tenant değiştirme |
| POST | /api/v1/auth/logout |
Çıkış |
| GET | /api/v1/auth/tenants |
Kullanıcının tenant'larını listele |
Login Request/Response
// Request
{
"email": "user@example.com",
"password": "password123",
"tenantId": "00000000-0000-0000-0000-000000000000",
"deviceId": "device-unique-id",
"deviceFingerprint": "optional-fingerprint",
"trustDevice": false
}
// Success Response
{
"accessToken": "eyJhbG...",
"refreshToken": "refresh-token",
"expiresAt": "2024-01-01T12:00:00Z",
"user": {
"userId": "00000000-0000-0000-0000-000000000000",
"email": "user@example.com",
"firstName": "John",
"lastName": "Doe",
"fullName": "John Doe",
"roles": ["Admin", "User"],
"permissions": ["orders.read", "orders.write"]
},
"tenant": {
"id": "00000000-0000-0000-0000-000000000000",
"code": "ACME",
"name": "ACME Corporation",
"isDefault": true,
"accessLevel": "Owner"
}
}
// MFA Required Response
{
"sessionToken": "mfa-session-token",
"availableChannels": ["email", "sms", "totp"],
"expiresAt": "2024-01-01T12:05:00Z"
}
JWT Token Claims
Üretilen access token aşağıdaki claim'leri içerir:
| Claim | Açıklama |
|---|---|
sub |
User ID (GUID) |
email |
Kullanıcı e-posta adresi |
tid |
Tenant ID (GUID) |
app |
Application ID (GUID) |
did |
Device ID |
name |
Kullanıcı tam adı |
role |
Roller (multiple) |
permission |
İzinler (multiple) |
Bağımlılıklar
Yeditepe.Auth.Abstractions- Interface tanımlarıMicrosoft.AspNetCore.Authentication.JwtBearer- JWT authenticationMicrosoft.Extensions.Http.Resilience- HTTP resilience/retrySystem.IdentityModel.Tokens.Jwt- JWT işlemleri
Lisans
MIT License - Yeditepe Software © 2024
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.1)
- Microsoft.Extensions.Http.Polly (>= 10.0.1)
- Microsoft.Extensions.Http.Resilience (>= 10.1.0)
- System.IdentityModel.Tokens.Jwt (>= 8.15.0)
- Yeditepe.Auth.Abstractions (>= 1.0.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.