AddAuth
Registers everything the package needs: the bound AuthSettings, JWT bearer authentication, the host resolver, the token generator, and the permission authorization services. It also registers a mapper covering this package's exceptions, so each becomes a standardized error response.
A token's audience is checked as the token is validated whenever a non-empty Hosts mapping is configured, so a token issued for a different app, or one arriving on a host that maps to none, is refused as unauthenticated with a 401.
Usage
using AlmightyShogun.AspNet.Core;
using AlmightyShogun.AspNet.Auth;
using AlmightyShogun.AspNet.Localization;
builder.Services
.AddMessageLocalization(builder.Configuration)
.AddHttpErrorResponseWriter()
.AddExceptionHandling()
.AddAuth(builder.Configuration);
WebApplication app = builder.Build();
app.UseHttpErrorResponses();Parameters
configuration: IConfiguration
Application configuration containing the Auth section.
registerExceptionHandler: bool
Whether to register the handler that turns this package's exceptions into standardized error responses. Pass false where the application already has an exception handler covering them.
Default: true
Returns
TheIServiceCollection instance with JWT authentication and authorization services configured.Type signature
public IServiceCollection AddAuth(
IConfiguration configuration,
bool registerExceptionHandler = true
);