SAIF.Platform.Authentication.AspNetCore¶
ASP.NET Core authentication middleware layered on top of SAIF.Platform.Authentication's framework-agnostic auth clients. Provides two authentication modes:
- JWT bearer (
JwtBearer/) — for service-to-service calls where the token has already been validated by a fronting service (APIM); this package extracts the bearer token (including from a forwarded-authorization header) and makes it available on the request, but does not re-validate signature, issuer, or lifetime itself. - OpenID Connect (
OpenIdConnect/) — for interactive user sign-in via a cookie session, plus a separate encrypted access-token cookie (SaifApimIdentity) that APIM's inbound policies read directly. This cookie is only registered when configuration provides a 16-character (16 UTF-8 byte)EncryptionKeyfor AES-128; without it, registration is skipped and the cookie is silently omitted, so experience APIs that rely on APIM cookie interop must provision this key.
Both modes share request-scoped tenant-origin resolution (Tenants/, via the x-forward-tenant-origin header) and forwarded-header/APIM path-prefix correction (UseAuthenticationServices()).
Getting started¶
Pick the mode that matches how the service is called. For JWT bearer:
For OpenID Connect:
AddOpenIdConnectServices() also accepts an Action<OpenIdConnectServiceOptions> for callback paths, cookie name, additional scopes, and proactive token-refresh timing. UseOpenIdConnectServices() maps /auth/login, /auth/logout, and /auth/me endpoints (overridable via optional handler delegates) and calls UseAuthenticationServices() internally, so forwarded-header/path-base correction is already applied before UseAuthentication() runs.
Both Add*Services() calls register SAIF.Platform.Authentication's AddAuthenticationServices() (token/tenant services plus Corp and External AuthenticationConfiguration) automatically — services using this package do not need to call that registration themselves.
Coupling with slot routing¶
Both Add*Services() calls also register SAIF.Platform.AspNetCore's AddSlotRouting()/UseSlotRouting() automatically. Services that call AddJwtBearerServices() or AddOpenIdConnectServices() get slot routing for free and should not call AddSlotRouting()/UseSlotRouting() a second time.
Related packages¶
SAIF.Platform.Authentication— the framework-agnostic token-acquisition clients this package wraps.SAIF.Platform.AspNetCore— slot routing, registered automatically by this package (see above).