ASP.NET Auth
Adds the authentication pieces commonly needed by ASP.NET Core APIs in this package family. It wires JWT bearer authentication, binds the Auth configuration section, validates token issuer, signing key, lifetime, and configured audiences, and refuses a token issued for an app other than the one the request host resolves to.
Use this package when an API should accept JWT access tokens, store refresh tokens in a consistent cookie, and protect controllers or actions with permission attributes. The package is intentionally focused: token issuing remains application code, while validation, cookie names, cookie helpers, host-to-app resolution, and permission policy registration are handled here.
Categories
- Configuration — the
Authsection the package binds and validates at startup. - Exceptions — what the package throws, and the response each one becomes.
- Localization — the message file those responses are worded from.
- Extensions — startup, request, response, and claims-principal extension methods.
- Attributes — endpoint metadata for permission authorization.
- Services — host resolution and access token generation.
- Records — the minted token and its expiry.
- Constants — the claim types, policy naming, and cookie names the package reads and writes.
Quick Example
csharp
using AlmightyShogun.AspNet.Core;
using AlmightyShogun.AspNet.Auth;
using AlmightyShogun.AspNet.Localization;
builder.Services
.AddMessageLocalization(builder.Configuration)
.AddHttpErrorResponseWriter()
.AddExceptionHandling()
.AddAuth(builder.Configuration);
WebApplication app = builder.Build();
app.UseHttpErrorResponses();