YouBIM.Common.Security.Lib
8.0.24
dotnet add package YouBIM.Common.Security.Lib --version 8.0.24
NuGet\Install-Package YouBIM.Common.Security.Lib -Version 8.0.24
<PackageReference Include="YouBIM.Common.Security.Lib" Version="8.0.24" />
<PackageVersion Include="YouBIM.Common.Security.Lib" Version="8.0.24" />
<PackageReference Include="YouBIM.Common.Security.Lib" />
paket add YouBIM.Common.Security.Lib --version 8.0.24
#r "nuget: YouBIM.Common.Security.Lib, 8.0.24"
#:package YouBIM.Common.Security.Lib@8.0.24
#addin nuget:?package=YouBIM.Common.Security.Lib&version=8.0.24
#tool nuget:?package=YouBIM.Common.Security.Lib&version=8.0.24
YouBIM.Common.Security.Lib
Authentication / Authorization Common Library
Overview
YouBIM.Common.Security.Lib is a common library designed to handle authentication and authorization for microservices in a .NET Core 8 environment. It provides a flexible and robust mechanism for validating JWT tokens and handling client credentials for secure access to APIs.
Features
- JWT Token Validation: Validates tokens, extracting user metadata and roles.
- Client Credentials Validation: Supports authentication using client ID and secret key.
- Custom Authorization Handler: Implements custom authorization logic.
- Configuration Driven: Utilizes
IConfigurationfor managing authentication settings. - Logging Support: Integrated logging for tracking authorization processes and errors.
Installation
Add the library to your project via NuGet:
dotnet add package YouBIM.Common.Security.LibConfigure your
appsettings.jsonto include the necessary authentication settings:{ "AuthenticationConfiguration": { "Authority": "https://your-auth-server.com", "Audience": "your-audience", "Issuer": "your-issuer", "ClientId": "your-client-id", "JwtSecretKey": "your-secret-key" } }
Usage
Registering Services
In your Program.cs, after the environment configuration add the authentication services provided by the library:
string environment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT");
builder.Configuration.AddJsonFile("appsettings.json", true)
.AddJsonFile($"appsettings.{environment}.json", optional: true)
.AddEnvironmentVariables()
.AddCommandLine(args);
//add auth lib inyection
builder.Services.AddAuthentication(builder.Configuration);
Implementing Client Service
Implement the IClientService interface to provide the logic for retrieving user metadata based on client credentials:
public class ClientService : IClientService
{
public async Task<AuthUserMetadata> GetAuthUserByClientIdentifierAsync(string clientId, string secretKey)
{
// Your implementation to fetch user metadata
}
}
Adding Authorization Policies
Add the custom authorization policy to your controllers or endpoints:
[Authorize(Policy = "AuthHandler")]
public class YourController : ControllerBase
{
// Your controller actions
}
Classes and Methods
AuthHandler
Handles the main authorization logic, checking for tokens or client credentials in HTTP headers and validating them.
- HandleRequirementAsync: Core method to process authorization.
- HandleTokenAuthorization: Validates JWT tokens.
- HandleClientCredentialsAuthorizationAsync: Validates client credentials.
- SetAuthUserInHttpContext: Sets user metadata in the HTTP context.
- FailAuthorization: Handles authorization failures and sets appropriate response messages.
AuthRequirement
Defines a requirement for authorization policies.
Util
Provides utility methods for token deserialization and HTTP context extraction.
AuthenticationConfiguration
Holds configuration settings for the authentication process.
AuthUserMetadata
Defines the structure for user metadata including user ID, username, role, buildings, and account ID.
IClientService
Interface to be implemented for client credential validation logic.
DependencyInjection
Extension methods for registering authentication and authorization services.
Important Notes
- Ensure that the JWT secret key is securely stored and accessed, such as using environment variables or a secrets manager.
- Update your NuGet packages regularly, but be aware of breaking changes in newer versions, especially for
Microsoft.AspNetCore.Authentication.JwtBearer.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 8.0.25)
- Microsoft.Extensions.Http (>= 8.0.1)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.