Skip to content

CreateUserRequest ​

Everything an administrator supplies to create an account, including the role and permissions a user must never set for themselves. Public sign-up uses RegisterRequest instead.

WARNING

Never bind this model on a route a normal user can reach. Role and Permissions become claims in the created account's own token, so exposing it publicly lets a caller grant themselves anything.

Fields

Username: string
The account name to claim. Refused with UsernameTakenException when another account already holds it.

Password: string
The initial password, at least 8 characters and subject to the [PasswordSecure] rule. Hashed before the row is written and never stored as given.

Email: string
The address to claim, checked for a valid shape by [Email]. Refused with EmailTakenException when another account already holds it.

Role: string
The role the new account gets, written into its access token as a role claim.
Default: User

Permissions: string[]
The permissions the new account gets, one token claim each. Prefix them per application, as in api:users.read, only when routes are scoped that way.
Default: []

Type signature ​

csharp
public sealed record CreateUserRequest
{
    public required string Username { get; set; }
    public required string Password { get; set; }
    public required string Email { get; set; }
    public string Role { get; set; } = "User";
    public string[] Permissions { get; set; } = [];
}

All packages are released under the MIT License.