Skip to content

SAIF.Platform.Authentication.AspNetCore

ASP.NET Core authentication middleware layered on top of SAIF.Platform.Authentication's framework-agnostic auth clients. Provides two authentication modes:

  • JWT bearer (JwtBearer/) — for service-to-service calls where the token has already been validated by a fronting service (APIM); this package extracts the bearer token (including from a forwarded-authorization header) and makes it available on the request, but does not re-validate signature, issuer, or lifetime itself.
  • OpenID Connect (OpenIdConnect/) — for interactive user sign-in via a cookie session, plus a separate encrypted access-token cookie (SaifApimIdentity) that APIM's inbound policies read directly. This cookie is only registered when configuration provides a 16-character (16 UTF-8 byte) EncryptionKey for AES-128; without it, registration is skipped and the cookie is silently omitted, so experience APIs that rely on APIM cookie interop must provision this key.

Both modes share request-scoped tenant-origin resolution (Tenants/, via the x-forward-tenant-origin header) and forwarded-header/APIM path-prefix correction (UseAuthenticationServices()).

Getting started

Pick the mode that matches how the service is called. For JWT bearer:

builder.AddJwtBearerServices();

// ...

app.UseJwtBearerServices();

For OpenID Connect:

builder.AddOpenIdConnectServices();

// ...

app.UseOpenIdConnectServices();

AddOpenIdConnectServices() also accepts an Action<OpenIdConnectServiceOptions> for callback paths, cookie name, additional scopes, and proactive token-refresh timing. UseOpenIdConnectServices() maps /auth/login, /auth/logout, and /auth/me endpoints (overridable via optional handler delegates) and calls UseAuthenticationServices() internally, so forwarded-header/path-base correction is already applied before UseAuthentication() runs.

Both Add*Services() calls register SAIF.Platform.Authentication's AddAuthenticationServices() (token/tenant services plus Corp and External AuthenticationConfiguration) automatically — services using this package do not need to call that registration themselves.

Coupling with slot routing

Both Add*Services() calls also register SAIF.Platform.AspNetCore's AddSlotRouting()/UseSlotRouting() automatically. Services that call AddJwtBearerServices() or AddOpenIdConnectServices() get slot routing for free and should not call AddSlotRouting()/UseSlotRouting() a second time.


View source on GitHub