Galosys.Foundation.AspNetCore.Authorization 26.7.31.1

There is a newer version of this package available.
See the version list below for details.
dotnet add package Galosys.Foundation.AspNetCore.Authorization --version 26.7.31.1
                    
NuGet\Install-Package Galosys.Foundation.AspNetCore.Authorization -Version 26.7.31.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Galosys.Foundation.AspNetCore.Authorization" Version="26.7.31.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Galosys.Foundation.AspNetCore.Authorization" Version="26.7.31.1" />
                    
Directory.Packages.props
<PackageReference Include="Galosys.Foundation.AspNetCore.Authorization" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Galosys.Foundation.AspNetCore.Authorization --version 26.7.31.1
                    
#r "nuget: Galosys.Foundation.AspNetCore.Authorization, 26.7.31.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Galosys.Foundation.AspNetCore.Authorization@26.7.31.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Galosys.Foundation.AspNetCore.Authorization&version=26.7.31.1
                    
Install as a Cake Addin
#tool nuget:?package=Galosys.Foundation.AspNetCore.Authorization&version=26.7.31.1
                    
Install as a Cake Tool

Galosys.Foundation.AspNetCore.Authorization

ABAC(属性授权)框架级模块:统一策略模型、关键字注册表、可插拔评估引擎。零 Web 运行时依赖——Worker/Agent 进程内可直接引用,与 API 场景共享同一策略模型与引擎。

设计文档:docs/designs/abac-design.md;当前为阶段 1(主包 v0.1 完成,M1)

能力清单

能力 状态 说明
策略模型 ✅ v0.1 AbacPolicy / AbacCondition 条件树(and/or/not + 13 运算符 + @ 值引用),System.Text.Json 往返
关键字注册表 ✅ v0.1 IAbacAttributeProvider:user.(Subject 属性包)/ resource.(反射)/ env.*(Environment);HttpContext 属性源可选装配
评估引擎 ✅ v0.1 IAuthorizationEngine + AbacAuthorizationEngine(JSON 树递归解释器,deny-by-default,未知关键字→拒绝+日志)
策略存储/热更新 ✅ v0.1 IAbacPolicyStore(只读三方法)+ ConfigurationAbacPolicyStore(对象/JSON 文件/配置节三源)+ AbacPolicyCache 版本号轮询(默认 30s,原子替换)
官方管线接入 ✅ v0.1 AbacAuthorizationHandler(deny 优先聚合)+ AbacDynamicPolicyProvider(policy 名即策略名)+ 命令式扩展(含显式四要素重载)
Casbin 适配器 ⏳ 阶段 3 独立包 ...Authorization.Casbin
DataPermission 集成 ⏳ 后续 独立包 ...Authorization.DataPermission

使用示例

注册(完整)

services.AddAbacAuthorization(options =>
{
    options.PollingInterval = TimeSpan.FromSeconds(30);   // 热更新轮询
    options.Policies = new[] { /* AbacPolicy 对象 */ };   // 或 PolicyFilePath / PolicySection
});

声明式(接口级授权,API 场景)

[Authorize(Policy = "orders:edit")]   // policy 名即策略名,动态策略提供者无需预注册
public async Task<UnifiedResponse> EditOrder(OrderUpdateCommand command) { ... }

命令式(资源级 ABAC)

var result = await _authorizationService.AuthorizeAsync(User, order, "orders:approve");
if (!result.Succeeded) return UnifiedResponse.Fail("无权限");

显式四要素(Worker/Agent,零 Web 依赖)

var subject = new AbacSubject();
subject.Set("userId", 42L);
subject.Set("roleIds", new long[] { 1, 2 });

var result = await _authorizationService.AuthorizeAsync(
    subject, order, "orders:edit",
    AbacEnvironment.Create(ip: "10.1.2.3"));

替换策略存储(如业务桥)

services.AddAbacAuthorization().WithPolicyStore<BopAbacPolicyStore>();   // 实现 IAbacPolicyStore 只读三方法

HttpContext 属性源(API 场景,可选装配)

services.AddAbacAuthorization().WithHttpContextAttributes();   // env.ip 回退 HttpContext 远端 IP

引擎直用(低层 API)

var engine = sp.GetRequiredService<IAuthorizationEngine>();
var context = AbacContext.Create(subject, order, "orders:edit", AbacEnvironment.Create(ip: "10.1.2.3"));
var allowed = await engine.EvaluateAsync(policy, context);

策略 JSON 示例

{
  "name": "orders:edit",
  "effect": "allow",
  "actions": ["edit"],
  "resources": ["Order"],
  "condition": {
    "op": "and",
    "children": [
      { "op": "eq", "keyword": "resource.ownerId", "value": "@user.userId" },
      { "op": "contains", "keyword": "user.roleIds", "values": [1, 2] }
    ]
  }
}

依赖

  • Galosys.Foundation.Core
  • Microsoft.AspNetCore.Authorization / Microsoft.Extensions.DependencyInjection / Microsoft.Extensions.Logging(10.0.0)
  • Microsoft.AspNetCore.Http.Abstractions(2.3.11,当前实现——仅供 env.ip 属性源;分层抽象改造后移除,见设计文档 9.1 决策记录)

不依赖 Galosys.Foundation.AspNetCore 模块与 Galosys.Foundation.DataPermission(命名含 AspNetCore 但零 Web 运行时)。

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
26.9.23.1 89 9/23/2026
26.9.16.1 88 9/16/2026
26.9.15.1 87 9/15/2026
26.9.14.1 81 9/14/2026
26.9.10.1 97 9/10/2026
26.9.3.1 91 9/3/2026
26.8.29.1 97 8/31/2026
26.8.26.1 107 8/26/2026
26.8.23.1 104 8/23/2026
26.8.21.1 99 8/21/2026
26.8.20.1 98 8/20/2026
26.8.18.1 111 8/18/2026
26.8.17.1 108 8/17/2026
26.8.13.2 106 8/13/2026
26.8.13.1 108 8/13/2026
26.8.12.2 106 8/12/2026
26.8.12.1 106 8/12/2026
26.8.10.1 115 8/10/2026
26.8.5.1 111 8/5/2026
26.7.31.1 118 7/31/2026
Loading failed