CreateUserRequest
Everything an administrator supplies to create an account, including the role and permissions a user must never set for themselves. Public sign-up uses RegisterRequest instead.
WARNING
Never bind this model on a route a normal user can reach. Role and Permissions become claims in the created account's own token, so exposing it publicly lets a caller grant themselves anything.
Fields
Username: string
The account name to claim. Refused with UsernameTakenException when another account already holds it.
Password: string
The initial password, at least 8 characters and subject to the [PasswordSecure] rule. Hashed before the row is written and never stored as given.
Email: string
The address to claim, checked for a valid shape by [Email]. Refused with EmailTakenException when another account already holds it.
Role: string
The role the new account gets, written into its access token as a role claim.
Default: User
Permissions: string[]
The permissions the new account gets, one token claim each. Prefix them per application, as in api:users.read, only when routes are scoped that way.
Default: []
Type signature
public sealed record CreateUserRequest
{
public required string Username { get; set; }
public required string Password { get; set; }
public required string Email { get; set; }
public string Role { get; set; } = "User";
public string[] Permissions { get; set; } = [];
}