BSynchro.Authorization 6.4.0

There is a newer version of this package available.
See the version list below for details.
dotnet add package BSynchro.Authorization --version 6.4.0
                    
NuGet\Install-Package BSynchro.Authorization -Version 6.4.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="BSynchro.Authorization" Version="6.4.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="BSynchro.Authorization" Version="6.4.0" />
                    
Directory.Packages.props
<PackageReference Include="BSynchro.Authorization" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add BSynchro.Authorization --version 6.4.0
                    
#r "nuget: BSynchro.Authorization, 6.4.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package BSynchro.Authorization@6.4.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=BSynchro.Authorization&version=6.4.0
                    
Install as a Cake Addin
#tool nuget:?package=BSynchro.Authorization&version=6.4.0
                    
Install as a Cake Tool

Package Description

Product Compatible and additional computed target framework versions.
.NET net6.0 is compatible.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (3)

Showing the top 3 NuGet packages that depend on BSynchro.Authorization:

Package Downloads
BSynchro.Tables.Core

A tool for Querying Trees (database level), generated from excel tables uploaded from ProductSetup ( Tables, Rate Tables, Score Tables).

BSynchro.CQRS

Package Description

BSynchro.Crm.Core.Infrastructure

Package Description

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
8.4.0 104 9/28/2026
8.3.5 187 9/1/2026
8.3.4 385 8/6/2026
8.3.3 493 7/27/2026
8.3.2 136 7/10/2026
8.3.1 239 6/24/2026
8.3.0 202 6/22/2026
8.2.1 278 5/12/2026
8.2.0 253 5/8/2026
8.0.5 121 7/10/2026
8.0.4 715 9/19/2025
8.0.3 554 8/28/2025
6.4.0 83 9/28/2026
6.3.2 160 7/27/2026
6.3.1 133 7/10/2026
6.3.0 138 6/22/2026
6.1.0 153 5/8/2026
6.0.14 140 7/13/2026
6.0.12 375 8/28/2025
Loading failed

Behaviour change: a caller carrying the superadmin profile claim now holds every permission - HasPermissionAsync answers true without consulting policy data, and Evaluate reports the superadmin role plus every permission each policy defines. New permissions and unseeded tenants therefore reach Super Admin without a seed migration. Adds SuperAdmin.IsHeldBy and Role.Matches. Catalog refresh: CoraPermissions and the committed catalog snapshot are brought level with the 8.x line at 8.12.0 - 137 permissions. Fourteen constants are new to this line (scheduler.*, calendar.* and notifications.providers.*). The snapshot had drifted 16 names behind the generated file, so the two drift tests were failing on the branch tip before this release; refreshing both together is the standing obligation this line carries in place of the catalog itself, which lives only on 8.x. Fix: a 403 now names only the permissions that actually failed, taken from the authorization failure rather than from the merged policy. A service composing [RequiresPermission] with another [Authorize(Policy = ...)] previously got "This action requires the 'x' permission" even when a different requirement - a capability scope, say - was what refused the caller. Where the failure names no requirement at all, the denial is left to the framework instead of being attributed by guesswork. This is the net6 counterpart of 8.5.3. Brings the permission enforcement package to the net6 line. Adds [RequiresPermission] plus a policy-provider registration so an endpoint can be gated by a catalog permission, and PermissionDeniedResultHandler so a denial says which permission was missing. Behaviour change: authorization policies are now cached per tenant and loaded on first use rather than at startup; single-host deployments are unaffected, but a deployment serving several tenants from one process previously shared one tenant's policies across all of them. Behaviour change: AuthorizationConfigurationClient now sends an access token - the request token when there is one, and a client-credentials machine token configured via AuthorizationSettings.TokenSettings when there is not, which is the message-bus consume case. It previously sent none. The machine token is cached per tenant, each entry under its own lock, and TokenSettings.TokenEndpointAddress accepts the same {0} placeholder as Address. Behaviour change: policy cache invalidation evicts and re-fetches within the changed tenant's own region, and InvalidationMode.Multiple is honoured. Fix: the claims-augmentation path that runs on message-bus consume resolves the tenant from the ambient bus tenant when there is no HTTP request, instead of falling to the single-tenant cache region. Binary-breaking change: AuthorizationConfigurationClient's public constructor gained IAccessTokenAccessor, IAuthorizationAddressResolver and IMachineTokenProvider parameters, and PolicyCacheMessageEventHandler's gained ICacheDataSource<IPolicy> and ILogger; consumers resolving them through DI are unaffected, but anything constructing them by hand must pass the new arguments. Fix: a caller whose entity claim reaches several companies is now evaluated against all of their copies of a policy, not one. Since each entity holds its own copy of every policy name, the entity-scoped fetch answers with one row per company; the cache keyed by name alone kept result.FirstOrDefault(), so a permission granted to an ordinary role in any other company's copy was silently discarded and the caller was refused with nothing in the log naming the cause. Super Admin never saw it, because that profile short-circuits evaluation. The cache key is now the policy name plus the caller's claimed entity ids, and the copies are combined by PolicyUnion, which qualifies each copy's role names so a role can only satisfy the permissions of the copy it came from - deliberately not a merge by role name, because two companies may define the same role name against different profiles, ProductIds and DataListGroupIds, and merging those would let one company's grants answer for another's. Role names are reported unqualified, so an Evaluate response is unchanged. Any tenant running per-entity policies should take this version: without it, a multi-company caller holds only whatever the arbitrarily-kept copy grants. The policies are fetched through api/policy/searchForEntities on the authorization service, which resolves the claimed ids through the organization hierarchy. Behaviour change: a role granting "all data list groups" reaches the groups of the company whose policy granted it, not every group the caller can see. DataListGroupAccess gains EntityIds - the companies whose every group is covered - and CoversAll is Super Admin alone; a consumer that reads CoversAll and ignores EntityIds will under-grant rather than over-grant, but must be updated to resolve those companies' own groups. Policy gains EntityId, and a derived entity that declared its own must drop it: two members mapped to one element make the Mongo class map throw on every read. Adds product scope: AuthorizationSettings.ProductScopeEnforced, IProductScopeAccessor, IProductScopeGuard and [ProductScopeExempt], so a service whose routes carry a productId can gate a products.* permission on the product the request addresses and constrain its reads to it. Off by default, and unchanged for a service that does not enable it. Fix: policy cache invalidation no longer declines in silence. The handler now logs a warning when a message names no region it can safely evict, and when the changed policy has no cache key registered in that region; both paths previously returned without a trace, which is what let a revoked permission go on being served by a consuming service with nothing anywhere saying so. Every composite key a region holds for a policy name is evicted, through PolicyCacheKeyRegistry, rather than one key. Binary-breaking change: PolicyCacheDataSource's constructor gained ICallerEntityIdAccessor, and PolicyCacheMessageEventHandler's gained PolicyCacheKeyRegistry; IPolicyEvaluator and IAuthorizationRuntimeClient gained product-scoped overloads. Consumers resolving these through DI are unaffected, but anything constructing them by hand, or implementing those interfaces, must be updated. Fix: a caller's policies are now loaded for the user being checked, not for whatever principal the request held when the gate was built. The per-entity load ran as an IConfigureOptions<PolicyOptions> step, which executes when the framework builds the authorization handlers - before it authenticates the endpoint's own scheme. On a host whose default scheme is not its API's (ms.identity-server: the IdentityServer cookie against Bearer controllers) that principal was still anonymous, the fetch named no company, and every caller but Super Admin was refused. Hosts defaulting to Bearer are unaffected. Binary-breaking change: AuthorizationRuntimeClient's constructor takes ICallerPolicySource instead of PolicyOptions, PolicyOptionsService is replaced by CallerPolicySource, ConfiguredPolicySource serves a fixed set, and PolicyOptions is no longer registered by value; consumers resolving the client through DI are unaffected, but anything constructing it by hand or injecting PolicyOptions must be updated. Adds the datalists.rows.read constant (DatalistsRowsRead, "Read Datalist Values"): the runtime read that DataList/QueryDataListRows requires in place of the administration permission datalists.group.view. Additive only. A tenant must run the migration that seeds it (seedDataListRowsRead) before a data-list build using it is deployed, or every caller of that lookup except Super Admin is refused.