# SAIF.Platform.Authentication.AspNetCore

ASP.NET Core authentication middleware layered on top of [`SAIF.Platform.Authentication`](../SAIF.Platform.Authentication/index.md)'s framework-agnostic auth clients. Provides two authentication modes:

- **JWT bearer** (`JwtBearer/`) — for service-to-service calls where the token has already been validated by a fronting service (APIM); this package extracts the bearer token (including from a forwarded-authorization header) and makes it available on the request, but does not re-validate signature, issuer, or lifetime itself.
- **OpenID Connect** (`OpenIdConnect/`) — for interactive user sign-in via a cookie session, plus a separate encrypted access-token cookie (`SaifApimIdentity`) that APIM's inbound policies read directly. This cookie is only registered when configuration provides a 16-character (16 UTF-8 byte) `EncryptionKey` for AES-128; without it, registration is skipped and the cookie is silently omitted, so experience APIs that rely on APIM cookie interop must provision this key.

Both modes share request-scoped tenant-origin resolution (`Tenants/`, via the `x-forward-tenant-origin` header) and forwarded-header/APIM path-prefix correction (`UseAuthenticationServices()`).

## Getting started

Pick the mode that matches how the service is called. For JWT bearer:

```csharp
builder.AddJwtBearerServices();

// ...

app.UseJwtBearerServices();
```

For OpenID Connect:

```csharp
builder.AddOpenIdConnectServices();

// ...

app.UseOpenIdConnectServices();
```

`AddOpenIdConnectServices()` also accepts an `Action<OpenIdConnectServiceOptions>` for callback paths, cookie name, additional scopes, and proactive token-refresh timing. `UseOpenIdConnectServices()` maps `/auth/login`, `/auth/logout`, and `/auth/me` endpoints (overridable via optional handler delegates) and calls `UseAuthenticationServices()` internally, so forwarded-header/path-base correction is already applied before `UseAuthentication()` runs.

Both `Add*Services()` calls register [`SAIF.Platform.Authentication`](../SAIF.Platform.Authentication/index.md)'s `AddAuthenticationServices()` (token/tenant services plus Corp and External `AuthenticationConfiguration`) automatically — services using this package do not need to call that registration themselves.

## Coupling with slot routing

Both `Add*Services()` calls also register [`SAIF.Platform.AspNetCore`](../SAIF.Platform.AspNetCore/index.md)'s `AddSlotRouting()`/`UseSlotRouting()` automatically. Services that call `AddJwtBearerServices()` or `AddOpenIdConnectServices()` get slot routing for free and should not call `AddSlotRouting()`/`UseSlotRouting()` a second time.

## Related packages

- [`SAIF.Platform.Authentication`](../SAIF.Platform.Authentication/index.md) — the framework-agnostic token-acquisition clients this package wraps.
- [`SAIF.Platform.AspNetCore`](../SAIF.Platform.AspNetCore/index.md) — slot routing, registered automatically by this package (see above).

---

[View source on GitHub](https://github.com/saif-corp/forge/blob/main/src/dotnet/SAIF.Platform.Authentication.AspNetCore/README.md)
