Skip to content

Installation ​

Install AlmightyShogun.AspNet.Auth.Credentials in the ASP.NET Core API that owns credential users, sessions, and password reset tokens. The application supplies an EF Core context derived from AuthDbContext<TUser>, so credential data lives in the same database and the same migrations as the rest of the domain. The package ships none of its own, so every credential table is created by a migration you generate against that context.

sh
dotnet add package AlmightyShogun.AspNet.Auth.Credentials

Dependencies ​

Framework references ​

  • Microsoft.AspNetCore.App — supplies the HTTP abstractions, dependency injection, Identity password hashing, data protection, and WebUtilities APIs the package builds on.

Package references ​

  • Microsoft.EntityFrameworkCore 10.0.11 — supplies the base DbContext, model building, and query APIs used for users, sessions, tokens, and two-factor enrolments.
  • Microsoft.EntityFrameworkCore.Relational 10.0.11 — supplies the explicit transactions the credential flows run in, including the serializable ones that make token issuance and lockout counting safe under concurrency. It arrives with any relational provider anyway.
  • Otp.NET 1.4.1 — generates and verifies the TOTP codes behind IAuthTwoFactorService<TUser>.

Project references ​

  • AlmightyShogun.AspNet.Auth — supplies AuthSettings, IAppHostResolver, the token generator, and the refresh-token cookie helpers.
  • AlmightyShogun.AspNet.Core — supplies ClientContext, User-Agent parsing, and the IExceptionMapper contract this package's exceptions map through.
  • AlmightyShogun.AspNet.Localization — resolves the message on each failure from the auth and passwords files described in Localization.
  • AlmightyShogun.AspNet.RequestValidation — supplies the [Required], [Email], [Min], and [PasswordSecure] rules carried by the request models.

Startup Registration ​

AddAuth binds the token settings and the app resolver that credential flows read; AddAuthCredentials maps your context onto the package base context and registers the credential services against your user entity.

WARNING

Register JWT auth first. Credential auth resolves AuthSettings and IAppHostResolver at construction, so a container missing them fails when the first credential service is resolved, not at startup.

csharp
using AlmightyShogun.AspNet.Core;
using AlmightyShogun.AspNet.Auth;
using Microsoft.EntityFrameworkCore;
using AlmightyShogun.AspNet.Localization;
using AlmightyShogun.AspNet.Auth.Credentials;
using AlmightyShogun.AspNet.RequestValidation;

builder.Services
    .AddMessageLocalization(builder.Configuration)
    .AddHttpErrorResponseWriter()
    .AddExceptionHandling()
    .AddAuth(builder.Configuration)
    .AddAspNetValidation()
    .AddDbContext<AppDbContext>(options => ...)
    .AddAuthCredentials<AppDbContext, AppUser>(builder.Configuration);

WebApplication app = builder.Build();

app.UseHttpErrorResponses();
app.UseAspNetValidation();
csharp
using Microsoft.EntityFrameworkCore;
using AlmightyShogun.AspNet.Auth.Credentials;

public sealed class AppDbContext(
    DbContextOptions<AppDbContext> options
) : AuthDbContext<AppUser>(options);
csharp
using AlmightyShogun.AspNet.Auth.Credentials;

public sealed class AppUser : AuthUser;

Data protection keys ​

Two-factor secrets are encrypted with ASP.NET Core data protection before they are stored. The default key ring lives on the local machine, so an application running on more than one host, or in a container without a persisted key directory, must configure a shared key store before anyone enrols. Losing the keys makes every stored secret unreadable and forces every enrolled user to set up their authenticator again.

All packages are released under the MIT License.