Skip to content

ASP.NET Auth ​

Adds the authentication pieces commonly needed by ASP.NET Core APIs in this package family. It wires JWT bearer authentication, binds the Auth configuration section, validates token issuer, signing key, lifetime, and configured audiences, and refuses a token issued for an app other than the one the request host resolves to.

Use this package when an API should accept JWT access tokens, store refresh tokens in a consistent cookie, and protect controllers or actions with permission attributes. The package is intentionally focused: token issuing remains application code, while validation, cookie names, cookie helpers, host-to-app resolution, and permission policy registration are handled here.

Categories ​

  • Configuration — the Auth section the package binds and validates at startup.
  • Exceptions — what the package throws, and the response each one becomes.
  • Localization — the message file those responses are worded from.
  • Extensions — startup, request, response, and claims-principal extension methods.
  • Attributes — endpoint metadata for permission authorization.
  • Services — host resolution and access token generation.
  • Records — the minted token and its expiry.
  • Constants — the claim types, policy naming, and cookie names the package reads and writes.

Quick Example ​

csharp
using AlmightyShogun.AspNet.Core;
using AlmightyShogun.AspNet.Auth;
using AlmightyShogun.AspNet.Localization;

builder.Services
    .AddMessageLocalization(builder.Configuration)
    .AddHttpErrorResponseWriter()
    .AddExceptionHandling()
    .AddAuth(builder.Configuration);

WebApplication app = builder.Build();

app.UseHttpErrorResponses();

All packages are released under the MIT License.