AuthUser
The base user entity every credential service works against. Applications inherit from it to add their own profile fields, and the derived type becomes the TUser of the context and the services.
DANGER
AuthUser is a database entity and must not cross the API boundary in either direction. Never return it from an endpoint: it carries the password hash, the surrogate key, and any loaded sessions, so map it to a DTO that exposes only the fields the client needs. Never bind a client payload straight onto it either: Role and Permissions are ordinary settable properties that become claims in the user's own access token, so build it from a RegisterRequest and set those values in application code.
Usage
using AlmightyShogun.AspNet.Auth.Credentials;
public sealed class AppUser : AuthUser
{
public string DisplayName { get; set; } = string.Empty;
public DateTimeOffset CreatedAt { get; set; } = DateTimeOffset.UtcNow;
}Fields
Id: int
The surrogate key, used for foreign keys inside the package. Never put it in a response; Identifier is the value a client is given.
Identifier: Guid
The public identifier, a version 7 GUID so rows sort by creation without leaking a sequence. This is what appears in the access token and what the services accept.
Username: string
The account name, uniquely indexed and accepted by login alongside the email address.
Email: string
The address, uniquely indexed, and what the forgot-password flow matches against. Writing it on a user whose EmailVerifiedAt already carries a value leaves that timestamp describing an address nobody confirmed, so move a verified address through CompleteEmailChangeAsync or clear the timestamp in the same save. Setting it on a user who has never verified one, as creating an account does, needs neither.
EmailVerifiedAt: DateTimeOffset?
When the address was last proved by redeeming a verification token, or null while it never has been. Recorded and never acted on: nothing in the package refuses an unverified account, so gate sign-in on it yourself.
Default: null
Password: string
The password hash produced by ASP.NET Core's hasher. Rehashed in place on sign-in when the hasher reports an outdated format.
Sessions: List<UserSession>
The user's refresh-token sessions. Not loaded unless explicitly included.
Default: []
Role: string
The single role written into the access token as a role claim.
Default: User
Permissions: string[]
The permission values written into the token, one claim each. Store api:users.read style values only when routes are scoped per application; otherwise store plain values such as users.read.
Default: []
IsActive: bool
Whether the account may sign in. A false value is refused after the password is checked, so it never reveals that an account exists.
Default: true
Lockout: UserLockout?
The run of failed sign-ins against the account, or null while there is none. Held in its own table and not loaded unless explicitly included.
Default: null
TwoFactor: UserTwoFactor?
The user's TOTP enrolment, or null when they never began one. Held in its own table and not loaded unless explicitly included.
Default: null