Fluens.Web.Auth
0.8.2
dotnet add package Fluens.Web.Auth --version 0.8.2
NuGet\Install-Package Fluens.Web.Auth -Version 0.8.2
<PackageReference Include="Fluens.Web.Auth" Version="0.8.2" />
<PackageVersion Include="Fluens.Web.Auth" Version="0.8.2" />
<PackageReference Include="Fluens.Web.Auth" />
paket add Fluens.Web.Auth --version 0.8.2
#r "nuget: Fluens.Web.Auth, 0.8.2"
#:package Fluens.Web.Auth@0.8.2
#addin nuget:?package=Fluens.Web.Auth&version=0.8.2
#tool nuget:?package=Fluens.Web.Auth&version=0.8.2
Fluens.Web.Auth
JWT Bearer authentication and security headers middleware for Fluens web applications.
Installation
dotnet add package Fluens.Web.Auth
Usage
fluensBuilder.AddAuth();
app.UseSecurityHeaders();
app.UseAuthentication();
app.UseAuthorization();
AddAuth() accepts an optional Action<AuthOptions>? configure callback (after configureJwt); a
callback-only call — with no matching Fluens:Auth configuration section present — is still honoured
and validated.
Configuration section: Fluens:Auth:
{
"Fluens": {
"Auth": {
"Enabled": true,
"Issuer": "https://myapp.example.com",
"Audience": "myapp-api",
"SecretKey": "your-secret-key-at-least-32-characters-long!"
}
}
}
Claim mapping
AddAuth() sets JwtBearerOptions.MapInboundClaims = false before your configureJwt callback
runs, so the token handler preserves the JWT's own claim names ("sub" stays "sub") instead of
rewriting them to legacy WS-Federation claim-type URIs. This is what lets
Fluens.Web.Contexts's ClaimsPrincipal.GetUserId() read the standard "sub" claim directly. If
you need the legacy mapping behavior, opt back in explicitly:
fluensBuilder.AddAuth(configureJwt: jwt => jwt.MapInboundClaims = true);
TokenValidationParameters.NameClaimType and .RoleClaimType are pinned to the short OIDC-style
"name" and "role" claim names, matching MapInboundClaims = false. A token carrying
role: "admin" and name: "Alice" makes ClaimsPrincipal.IsInRole("admin") return true and
Identity.Name return "Alice" without any extra setup:
app.MapGet("/admin", () => "ok").RequireAuthorization(new AuthorizationPolicyBuilder()
.RequireRole("admin")
.Build());
If your issuer emits a legacy WS-Federation claim-type URI for role or name claims instead
(http://schemas.microsoft.com/ws/2008/06/identity/claims/role), override both in configureJwt -
it runs after this library's defaults, so your values win:
fluensBuilder.AddAuth(configureJwt: jwt =>
{
jwt.TokenValidationParameters.RoleClaimType = ClaimTypes.Role;
jwt.TokenValidationParameters.NameClaimType = ClaimTypes.Name;
});
Overriding JwtBearerOptions
AddAuth() accepts an optional configureJwt callback to override JWT Bearer defaults:
fluensBuilder.AddAuth(configureJwt: jwt =>
{
jwt.TokenValidationParameters.ClockSkew = TimeSpan.FromMinutes(1);
});
SecurityHeadersOptions
UseSecurityHeaders() adds all security headers by default. Accepts an optional Action<SecurityHeadersOptions>? configure callback to override individual headers:
app.UseSecurityHeaders(opts =>
{
opts.FrameOptions = false; // disable X-Frame-Options
opts.PermissionsPolicyValue = "camera=(), microphone=()"; // custom policy
});
All headers are enabled via SecurityHeadersOptions (all properties use set — not the usual init —
because the callback above mutates the instance after construction — and default to true):
| Property | Type | Default | Header |
|---|---|---|---|
ContentTypeOptions |
bool |
true |
X-Content-Type-Options: nosniff |
FrameOptions |
bool |
true |
X-Frame-Options: DENY |
ReferrerPolicy |
bool |
true |
Referrer-Policy: strict-origin-when-cross-origin |
PermissionsPolicy |
bool |
true |
Restrictive Permissions-Policy |
PermissionsPolicyValue |
string? |
null |
Custom override for Permissions-Policy value |
License
This project is licensed under the MIT License.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Fluens.Web (>= 0.8.2)
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.12)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.8.2 | 0 | 10/5/2026 |
| 0.8.1 | 120 | 9/15/2026 |
| 0.8.0 | 94 | 9/15/2026 |
| 0.7.11 | 86 | 9/15/2026 |
| 0.7.10 | 92 | 9/13/2026 |
| 0.7.9 | 99 | 9/11/2026 |
| 0.7.8 | 95 | 9/10/2026 |
| 0.7.7 | 97 | 9/10/2026 |
| 0.7.6 | 158 | 7/1/2026 |
| 0.7.5 | 129 | 6/22/2026 |
| 0.7.4 | 149 | 6/18/2026 |
| 0.7.2 | 123 | 6/18/2026 |
| 0.7.1 | 139 | 6/18/2026 |
| 0.6.6 | 287 | 3/11/2026 |
| 0.6.5 | 119 | 3/4/2026 |
| 0.6.4 | 120 | 3/4/2026 |
| 0.6.3 | 125 | 3/3/2026 |
| 0.6.2 | 132 | 3/2/2026 |
| 0.6.1 | 121 | 3/2/2026 |
| 0.6.0 | 126 | 3/1/2026 |