Linger.Ldap.Contracts 2.0.0-preview.3

This is a prerelease version of Linger.Ldap.Contracts.
dotnet add package Linger.Ldap.Contracts --version 2.0.0-preview.3
                    
NuGet\Install-Package Linger.Ldap.Contracts -Version 2.0.0-preview.3
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Linger.Ldap.Contracts" Version="2.0.0-preview.3" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Linger.Ldap.Contracts" Version="2.0.0-preview.3" />
                    
Directory.Packages.props
<PackageReference Include="Linger.Ldap.Contracts" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Linger.Ldap.Contracts --version 2.0.0-preview.3
                    
#r "nuget: Linger.Ldap.Contracts, 2.0.0-preview.3"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Linger.Ldap.Contracts@2.0.0-preview.3
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Linger.Ldap.Contracts&version=2.0.0-preview.3&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=Linger.Ldap.Contracts&version=2.0.0-preview.3&prerelease
                    
Install as a Cake Tool

Linger.Ldap.Contracts

Breaking changes and 2.0 migration notes are documented in the Linger migration guide.

Core contracts and shared models for LDAP operations in .NET applications.

Introduction

Linger.Ldap.Contracts exposes separate contracts for the capabilities actually provided by each LDAP implementation. ILdapClient represents native asynchronous LDAP operations, while IActiveDirectoryClient represents the synchronous Windows Active Directory APIs.

Supported Frameworks

  • .NET 10.0
  • .NET 9.0
  • .NET 8.0
  • .NET Standard 2.0

What This Package Contains

  • ILdapClient interface for native asynchronous LDAP operations
  • IActiveDirectoryClient interface for synchronous Windows Active Directory operations
  • LdapConfig and LdapCredentials configuration models
  • LdapUserInfo unified user profile model

ASP.NET Core Integration

Configure Services

Register the contract matching the selected provider. Both may be registered when an application uses both providers.

using Linger.Ldap.Contracts;

public void ConfigureServices(IServiceCollection services)
{
    services.Configure<LdapConfig>(Configuration.GetSection("LdapConfig"));

    services.AddScoped<ILdapClient, Linger.Ldap.Novell.NovellLdapClient>();
    services.AddScoped<IActiveDirectoryClient, Linger.Ldap.ActiveDirectory.AdLdapClient>();
}

appsettings.json Example

{
  "LdapConfig": {
    "Url": "ldap.example.com",
    "Domain": "example",
    "SearchBase": "DC=example,DC=com",
    "SearchFilter": "(&(objectClass=user)(|(sAMAccountName={0})(userPrincipalName={0})(mail={0})))",
    "Security": true,
    "MaxResults": 1000,
    "Credentials": {
      "BindDn": "serviceaccount",
      "BindCredentials": "password"
    },
    "Attributes": [
      "displayName",
      "mail",
      "sAMAccountName",
      "userPrincipalName",
      "telephoneNumber",
      "department"
    ]
  }
}

Usage Examples

Validate User Credentials

public class AuthenticationService
{
    private readonly ILdapClient _ldap;

    public AuthenticationService(ILdapClient ldap)
    {
        _ldap = ldap;
    }

    public async Task<bool> AuthenticateUserAsync(
        string username,
        string password,
        CancellationToken cancellationToken = default)
    {
        var (isValid, userInfo) = await _ldap.ValidateUserAsync(
            username,
            password,
            cancellationToken: cancellationToken);

        if (isValid && userInfo is not null)
        {
            Console.WriteLine($"User {userInfo.DisplayName} authenticated successfully.");
            return true;
        }

        return false;
    }
}

Find and Search Users

public class UserService
{
    private readonly ILdapClient _ldap;

    public UserService(ILdapClient ldap)
    {
        _ldap = ldap;
    }

    public async Task<LdapUserInfo?> GetUserInfoAsync(
        string username,
        CancellationToken cancellationToken = default)
    {
        return await _ldap.FindUserAsync(
            username,
            cancellationToken: cancellationToken);
    }

    public async Task<IReadOnlyList<LdapUserInfo>> SearchUsersAsync(
        string searchTerm,
        CancellationToken cancellationToken = default)
    {
        return await _ldap.GetUsersAsync(
            searchTerm,
            cancellationToken: cancellationToken);
    }

    public async Task<bool> CheckUserExistsAsync(
        string username,
        CancellationToken cancellationToken = default)
    {
        return await _ldap.UserExistsAsync(
            username,
            cancellationToken: cancellationToken);
    }
}

Search in a Specific OU with Custom Bind Credentials

var ldapCredentials = new LdapCredentials
{
    BindDn = "readonly.user",
    BindCredentials = "ReadonlyPassword123!"
};

var users = await _ldap.GetUsersAsync(
    "alice",
    ldapCredentials: ldapCredentials,
    searchBase: "OU=Sales,DC=example,DC=com",
    cancellationToken: cancellationToken);

Advanced Filter Search (Cross-Provider)

var advancedFilter = "(&(objectClass=person)(department=IT)(mail=*))";

var users = await _ldap.SearchUsersByFilterAsync(
    advancedFilter,
    searchBase: "DC=example,DC=com",
    cancellationToken: cancellationToken);

Cancellation Support

All ILdapClient operations accept CancellationToken, and the Novell provider forwards cancellation to its native asynchronous LDAP calls. IActiveDirectoryClient is intentionally synchronous because System.DirectoryServices does not provide asynchronous search operations.

FindUserAsync and GetUsersAsync reject blank usernames, and SearchUsersByFilterAsync rejects blank filters. Use an explicit raw LDAP filter when a broad query is intentional.

public async Task<bool> ValidateUserWithTimeoutAsync(
    ILdapClient ldap,
    string username,
    string password,
    int timeoutSeconds = 5)
{
    using var cts = new CancellationTokenSource(TimeSpan.FromSeconds(timeoutSeconds));

    try
    {
        var (isValid, _) = await ldap.ValidateUserAsync(
            username,
            password,
            cancellationToken: cts.Token);
        return isValid;
    }
    catch (OperationCanceledException)
    {
        Console.WriteLine("LDAP validation timed out.");
        return false;
    }
}

Core Interfaces

public interface ILdapClient
{
    Task<(bool IsValid, LdapUserInfo? LdapUserInfo)> ValidateUserAsync(
        string userName,
        string password,
        string? searchBase = null,
        CancellationToken cancellationToken = default);

    Task<LdapUserInfo?> FindUserAsync(
        string userName,
        LdapCredentials? ldapCredentials = null,
        string? searchBase = null,
        CancellationToken cancellationToken = default);

    Task<IReadOnlyList<LdapUserInfo>> GetUsersAsync(
        string userName,
        LdapCredentials? ldapCredentials = null,
        string? searchBase = null,
        CancellationToken cancellationToken = default);

    Task<IReadOnlyList<LdapUserInfo>> SearchUsersByFilterAsync(
        string filter,
        LdapCredentials? ldapCredentials = null,
        string? searchBase = null,
        CancellationToken cancellationToken = default);

    Task<bool> UserExistsAsync(
        string userName,
        string? searchBase = null,
        CancellationToken cancellationToken = default);
}

Core Models

LdapConfig

public class LdapConfig
{
    public string Url { get; set; } = null!;
    public bool Security { get; set; }
    public string Domain { get; set; } = null!;
    public LdapCredentials? Credentials { get; set; }
    public string SearchBase { get; set; } = null!;
    public string SearchFilter { get; set; } = null!;
    public string[]? Attributes { get; set; }
    public int MaxResults { get; set; } = 1000;
}

IActiveDirectoryClient exposes the corresponding operations as ValidateUser, FindUser, GetUsers, SearchUsersByFilter, and UserExists without Task or CancellationToken.

Providers take an independent snapshot of LdapConfig, including Credentials and Attributes, during client construction. Later changes to the source configuration do not affect an existing client; create a new client to apply new configuration.

LdapUserInfo (Commonly Used Fields)

  • DisplayName
  • SamAccountName
  • Upn
  • Dn
  • Email
  • Department
  • Title
  • MemberOf
  • ProxyAddresses
  • OtherTelephone
  • Status

MemberOf, ProxyAddresses, and OtherTelephone are string arrays because LDAP can return multiple values for these attributes.

Error Behavior

Invalid arguments and configuration are rejected before use. Search-operation connection, TLS, bind, and directory-server failures are surfaced as exceptions; an empty result means that the query completed successfully without matching users. Credential validation returns IsValid = false for invalid credentials. After successful authentication, a provider can return IsValid = true with no profile when the separate profile lookup fails.

Supported Implementations

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed.  net11.0 is compatible. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 was computed. 
.NET Framework net461 was computed.  net462 was computed.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • .NETStandard 2.0

    • No dependencies.
  • net10.0

    • No dependencies.
  • net11.0

    • No dependencies.
  • net8.0

    • No dependencies.
  • net9.0

    • No dependencies.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on Linger.Ldap.Contracts:

Package Downloads
Linger.Ldap.ActiveDirectory

Implementation of LDAP client functionality for Active Directory using System.DirectoryServices. Provides Windows-optimized AD connectivity with features for user authentication, information retrieval, group management, and specialized Active Directory operations.

Linger.Ldap.Novell

Implementation of LDAP client functionality using the Novell.Directory.Ldap provider. Provides cross-platform LDAP connectivity with features such as authentication, user information retrieval, group management, and secure connections.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
2.0.0-preview.3 65 9/13/2026
2.0.0-preview.1 67 8/29/2026
1.6.4 181 8/16/2026
1.6.3 188 8/5/2026
1.6.2 178 8/2/2026
1.6.0 186 7/25/2026
1.5.5 185 7/23/2026
1.5.4-preview 173 7/21/2026
1.5.3-preview 172 7/20/2026
1.5.2-preview 164 7/19/2026
1.5.1-preview 166 7/15/2026
1.5.0-preview 165 7/14/2026
1.4.4-preview 177 6/16/2026
1.4.3-preview 167 6/15/2026
1.4.2 188 5/20/2026
1.4.1-preview 178 5/12/2026
1.4.0 180 5/6/2026
1.3.3-preview 170 5/5/2026
1.3.2-preview 174 4/29/2026
1.3.1-preview 165 4/28/2026
Loading failed