Installation
Install AlmightyShogun.AspNet.Auth.Credentials in the ASP.NET Core API that owns credential users, sessions, and password reset tokens. The application supplies an EF Core context derived from AuthDbContext<TUser>, so credential data lives in the same database and the same migrations as the rest of the domain. The package ships none of its own, so every credential table is created by a migration you generate against that context.
dotnet add package AlmightyShogun.AspNet.Auth.CredentialsDependencies
Framework references
Microsoft.AspNetCore.App— supplies the HTTP abstractions, dependency injection, Identity password hashing, data protection, and WebUtilities APIs the package builds on.
Package references
Microsoft.EntityFrameworkCore10.0.11— supplies the baseDbContext, model building, and query APIs used for users, sessions, tokens, and two-factor enrolments.Microsoft.EntityFrameworkCore.Relational10.0.11— supplies the explicit transactions the credential flows run in, including the serializable ones that make token issuance and lockout counting safe under concurrency. It arrives with any relational provider anyway.Otp.NET1.4.1— generates and verifies the TOTP codes behindIAuthTwoFactorService<TUser>.
Project references
AlmightyShogun.AspNet.Auth— suppliesAuthSettings,IAppHostResolver, the token generator, and the refresh-token cookie helpers.AlmightyShogun.AspNet.Core— suppliesClientContext, User-Agent parsing, and theIExceptionMappercontract this package's exceptions map through.AlmightyShogun.AspNet.Localization— resolves the message on each failure from theauthandpasswordsfiles described in Localization.AlmightyShogun.AspNet.RequestValidation— supplies the[Required],[Email],[Min], and[PasswordSecure]rules carried by the request models.
Startup Registration
AddAuth binds the token settings and the app resolver that credential flows read; AddAuthCredentials maps your context onto the package base context and registers the credential services against your user entity.
WARNING
Register JWT auth first. Credential auth resolves AuthSettings and IAppHostResolver at construction, so a container missing them fails when the first credential service is resolved, not at startup.
using AlmightyShogun.AspNet.Core;
using AlmightyShogun.AspNet.Auth;
using Microsoft.EntityFrameworkCore;
using AlmightyShogun.AspNet.Localization;
using AlmightyShogun.AspNet.Auth.Credentials;
using AlmightyShogun.AspNet.RequestValidation;
builder.Services
.AddMessageLocalization(builder.Configuration)
.AddHttpErrorResponseWriter()
.AddExceptionHandling()
.AddAuth(builder.Configuration)
.AddAspNetValidation()
.AddDbContext<AppDbContext>(options => ...)
.AddAuthCredentials<AppDbContext, AppUser>(builder.Configuration);
WebApplication app = builder.Build();
app.UseHttpErrorResponses();
app.UseAspNetValidation();using Microsoft.EntityFrameworkCore;
using AlmightyShogun.AspNet.Auth.Credentials;
public sealed class AppDbContext(
DbContextOptions<AppDbContext> options
) : AuthDbContext<AppUser>(options);using AlmightyShogun.AspNet.Auth.Credentials;
public sealed class AppUser : AuthUser;Data protection keys
Two-factor secrets are encrypted with ASP.NET Core data protection before they are stored. The default key ring lives on the local machine, so an application running on more than one host, or in a container without a persisted key directory, must configure a shared key store before anyone enrols. Losing the keys makes every stored secret unreadable and forces every enrolled user to set up their authenticator again.