Fluens.Web.Auth 0.8.2

dotnet add package Fluens.Web.Auth --version 0.8.2
                    
NuGet\Install-Package Fluens.Web.Auth -Version 0.8.2
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Fluens.Web.Auth" Version="0.8.2" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Fluens.Web.Auth" Version="0.8.2" />
                    
Directory.Packages.props
<PackageReference Include="Fluens.Web.Auth" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Fluens.Web.Auth --version 0.8.2
                    
#r "nuget: Fluens.Web.Auth, 0.8.2"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Fluens.Web.Auth@0.8.2
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Fluens.Web.Auth&version=0.8.2
                    
Install as a Cake Addin
#tool nuget:?package=Fluens.Web.Auth&version=0.8.2
                    
Install as a Cake Tool

Fluens.Web.Auth

JWT Bearer authentication and security headers middleware for Fluens web applications.

Installation

dotnet add package Fluens.Web.Auth

Usage

fluensBuilder.AddAuth();

app.UseSecurityHeaders();
app.UseAuthentication();
app.UseAuthorization();

AddAuth() accepts an optional Action<AuthOptions>? configure callback (after configureJwt); a callback-only call — with no matching Fluens:Auth configuration section present — is still honoured and validated.

Configuration section: Fluens:Auth:

{
  "Fluens": {
    "Auth": {
      "Enabled": true,
      "Issuer": "https://myapp.example.com",
      "Audience": "myapp-api",
      "SecretKey": "your-secret-key-at-least-32-characters-long!"
    }
  }
}

Claim mapping

AddAuth() sets JwtBearerOptions.MapInboundClaims = false before your configureJwt callback runs, so the token handler preserves the JWT's own claim names ("sub" stays "sub") instead of rewriting them to legacy WS-Federation claim-type URIs. This is what lets Fluens.Web.Contexts's ClaimsPrincipal.GetUserId() read the standard "sub" claim directly. If you need the legacy mapping behavior, opt back in explicitly:

fluensBuilder.AddAuth(configureJwt: jwt => jwt.MapInboundClaims = true);

TokenValidationParameters.NameClaimType and .RoleClaimType are pinned to the short OIDC-style "name" and "role" claim names, matching MapInboundClaims = false. A token carrying role: "admin" and name: "Alice" makes ClaimsPrincipal.IsInRole("admin") return true and Identity.Name return "Alice" without any extra setup:

app.MapGet("/admin", () => "ok").RequireAuthorization(new AuthorizationPolicyBuilder()
    .RequireRole("admin")
    .Build());

If your issuer emits a legacy WS-Federation claim-type URI for role or name claims instead (http://schemas.microsoft.com/ws/2008/06/identity/claims/role), override both in configureJwt - it runs after this library's defaults, so your values win:

fluensBuilder.AddAuth(configureJwt: jwt =>
{
    jwt.TokenValidationParameters.RoleClaimType = ClaimTypes.Role;
    jwt.TokenValidationParameters.NameClaimType = ClaimTypes.Name;
});

Overriding JwtBearerOptions

AddAuth() accepts an optional configureJwt callback to override JWT Bearer defaults:

fluensBuilder.AddAuth(configureJwt: jwt =>
{
    jwt.TokenValidationParameters.ClockSkew = TimeSpan.FromMinutes(1);
});

SecurityHeadersOptions

UseSecurityHeaders() adds all security headers by default. Accepts an optional Action<SecurityHeadersOptions>? configure callback to override individual headers:

app.UseSecurityHeaders(opts =>
{
    opts.FrameOptions = false; // disable X-Frame-Options
    opts.PermissionsPolicyValue = "camera=(), microphone=()"; // custom policy
});

All headers are enabled via SecurityHeadersOptions (all properties use set — not the usual init — because the callback above mutates the instance after construction — and default to true):

Property Type Default Header
ContentTypeOptions bool true X-Content-Type-Options: nosniff
FrameOptions bool true X-Frame-Options: DENY
ReferrerPolicy bool true Referrer-Policy: strict-origin-when-cross-origin
PermissionsPolicy bool true Restrictive Permissions-Policy
PermissionsPolicyValue string? null Custom override for Permissions-Policy value

License

This project is licensed under the MIT License.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.8.2 0 10/5/2026
0.8.1 120 9/15/2026
0.8.0 94 9/15/2026
0.7.11 86 9/15/2026
0.7.10 92 9/13/2026
0.7.9 99 9/11/2026
0.7.8 95 9/10/2026
0.7.7 97 9/10/2026
0.7.6 158 7/1/2026
0.7.5 129 6/22/2026
0.7.4 149 6/18/2026
0.7.2 123 6/18/2026
0.7.1 139 6/18/2026
0.6.6 287 3/11/2026
0.6.5 119 3/4/2026
0.6.4 120 3/4/2026
0.6.3 125 3/3/2026
0.6.2 132 3/2/2026
0.6.1 121 3/2/2026
0.6.0 126 3/1/2026
Loading failed