Stratara.EventSourcing.Pipeline.CommandAudit
3.1.0
Prefix Reserved
See the version list below for details.
dotnet add package Stratara.EventSourcing.Pipeline.CommandAudit --version 3.1.0
NuGet\Install-Package Stratara.EventSourcing.Pipeline.CommandAudit -Version 3.1.0
<PackageReference Include="Stratara.EventSourcing.Pipeline.CommandAudit" Version="3.1.0" />
<PackageVersion Include="Stratara.EventSourcing.Pipeline.CommandAudit" Version="3.1.0" />
<PackageReference Include="Stratara.EventSourcing.Pipeline.CommandAudit" />
paket add Stratara.EventSourcing.Pipeline.CommandAudit --version 3.1.0
#r "nuget: Stratara.EventSourcing.Pipeline.CommandAudit, 3.1.0"
#:package Stratara.EventSourcing.Pipeline.CommandAudit@3.1.0
#addin nuget:?package=Stratara.EventSourcing.Pipeline.CommandAudit&version=3.1.0
#tool nuget:?package=Stratara.EventSourcing.Pipeline.CommandAudit&version=3.1.0
Stratara.EventSourcing.Pipeline.CommandAudit
License: FSL-1.1-MIT (Functional Source License — source-available; converts to MIT after 2 years). Not OSI-approved OSS.
Mediator pipeline behavior that records an audit row for every dispatched command in the Stratara event-sourced stack. Both arities are provided so consumers can register a single behavior pair and have it apply to all command shapes.
What's in the box
| Type | Purpose |
|---|---|
CommandAuditBehavior<TRequest> |
Runs the audit-write step before delegating to next() for IRequest (commands without result). |
CommandAuditBehavior<TRequest, TResult> |
Same, for IRequest<TResult> (commands with result + queries). Only records when the request also implements ICommandBase — queries flow through untouched. |
CommandAuditWriter (internal) |
Opens a transaction on IWriteUnitOfWork, writes via ICommandAuditRepository.AddAsync, commits. |
The behavior only audits commands — query requests reach the same generic interface but are filtered by the is ICommandBase check, so registering both behaviors application-wide is safe.
Quick start
// At composition time, alongside the other framework pipeline behaviors:
builder.Services
.AddPipelineBehaviorWithResult(typeof(CommandAuditBehavior<,>))
.AddPipelineBehavior(typeof(CommandAuditBehavior<>));
The behaviors resolve IWriteUnitOfWork from DI (ships with Stratara.EventSourcing.EntityFrameworkCore in the default deployment). No additional registration is needed.
Dependencies
Stratara.Abstractions— forIPipelineBehavior<,>,IRequest/IRequest<T>,ICommandBase,IWriteUnitOfWork,ICommandAuditRepository.JetBrains.Annotations—[UsedImplicitly]on the public behavior classes (DI-instantiated, no static call site).
At runtime an IWriteUnitOfWork implementation must be registered — typically by referencing Stratara.EventSourcing.EntityFrameworkCore and calling AddWriteStore(IConfiguration).
Security note — command payload contents
The audit row stores CommandTypeName and the serialized CommandJson of the dispatched command. Whatever fields your commands carry land in the audit table. Sensitive data (passwords, tokens, API keys, encryption material) MUST NOT live on a command record — or must be marked with [EncryptData] so the registered ISecureJsonSerializer encrypts them before persistence.
The default Stratara registration uses ISecureJsonSerializer (AES-GCM + tenant-scoped AAD) for the audit serialization, so [EncryptData]-annotated properties are protected. Plain-text properties go to disk unencrypted — treat the audit table accordingly when designing command shapes.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- JetBrains.Annotations (>= 2025.2.4)
- Stratara.Abstractions (>= 3.1.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.4.2 | 216 | 10/2/2026 |
| 4.4.1 | 346 | 9/29/2026 |
| 4.4.0 | 122 | 9/27/2026 |
| 4.3.1 | 116 | 9/25/2026 |
| 4.3.0 | 283 | 9/23/2026 |
| 4.2.0 | 125 | 9/18/2026 |
| 4.1.1 | 96 | 9/16/2026 |
| 4.1.0 | 95 | 9/16/2026 |
| 4.0.4 | 820 | 9/14/2026 |
| 4.0.3 | 107 | 9/3/2026 |
| 4.0.2 | 599 | 9/3/2026 |
| 4.0.1 | 315 | 9/2/2026 |
| 4.0.0 | 162 | 8/31/2026 |
| 4.0.0-preview.1 | 75 | 8/31/2026 |
| 3.4.0 | 144 | 8/28/2026 |
| 3.3.0 | 112 | 8/25/2026 |
| 3.2.3 | 108 | 8/22/2026 |
| 3.2.2 | 126 | 8/14/2026 |
| 3.2.1 | 119 | 8/2/2026 |
| 3.1.0 | 129 | 5/30/2026 |
**Breaking release.** The `IKeyStore` and `ISecureBlobEncryptor` contracts changed shape, a new
dependency-light `Stratara.Security` package now owns the production key store and envelope
encryption, and a new vendor-neutral `Stratara.Validation` package adds request validation as a
`Stratara.Mediator` pipeline behavior. Consumers must recompile and adapt call sites; data
encrypted under the previous HKDF-style key model is **not** binary-compatible and needs a
re-encrypt pass on its own schedule.
### Added
- **`Stratara.Validation` — vendor-neutral request validation.** A new package providing a
mediator pipeline behavior that runs `IValidator<T>` implementations before the handler and
throws an aggregated `StrataraValidationException` on failure. Register with
`AddStrataraValidation()` (outermost behavior) and `AddValidatorsFromAssemblyContaining<T>()`.
Only `ValidationSeverity.Error` blocks the request; `Warning`/`Info` failures pass through and
are logged. The package has no FluentValidation dependency — the contract is intentionally
FluentValidation-shape-compatible so an optional adapter can be added later.
- **Validation contracts in `Stratara.Abstractions`** (namespace `Stratara.Abstractions.Validation`):
`IValidator<T>`, `ValidationResult`, `ValidationFailure`, `ValidationSeverity`, and
`StrataraValidationException`. Declaring the exception in `Stratara.Abstractions` lets a
consumer's global exception handler map validation failures to its own error model (e.g.
RFC-7807 ProblemDetails) without referencing the behavior package.
- **`Stratara.Security` — production key store + envelope encryption (dependency-light).** Adds
`EnvelopeFileKeyStore`, a file-backed `IKeyStore` storing **KEK-wrapped, versioned per-scope
data-encryption keys** (rotation, single-version revoke, and whole-scope crypto-shred), plus a
`FileMasterKeyProvider` (`IMasterKeyProvider`, the KEK custody seam), an AES-GCM
`ISecureBlobEncryptor`, and the Development-only `DummyKeyStore`. Register with
`AddStrataraFileKeyStore(configuration)`. The package references only `Stratara.Abstractions` +
BCL crypto + `Microsoft.Extensions.*` abstractions — no EF Core, RabbitMQ, Redis, or cloud SDKs —
so lean consumers can encrypt without pulling in `Stratara.Infrastructure`.
- **New security contracts in `Stratara.Abstractions.Security`:** `KeyScope`, `KeyMaterial`, and
`IMasterKeyProvider`.
### Changed
- **BREAKING — `IKeyStore`.** Replaced `EnsureKeyAsync(level, Guid? tenantId, Guid? userId)` with
`GetOrCreateCurrentKeyAsync(KeyScope)` returning `KeyMaterial` (key id + bytes in one call), and
added `RotateAsync(KeyScope)` and `EraseScopeAsync(KeyScope)`. `RevokeAsync(string keyId)` now
performs a real crypto-shred (the production store no longer treats it as a no-op). Scope
identifiers are `string?` (carrying both slugs and `Guid.ToString()` values) rather than `Guid?`.
- **BREAKING — `ISecureBlobEncryptor`.** `EncryptAsync`/`DecryptAsync` now take a `KeyScope` and a
`purpose` instead of a bare `Guid tenantId`. The encrypted stream gains a leading version byte
(v2) and a `purpose` field; legacy streams without the version byte remain readable (configurable
via `Stratara.Security` options).
- The AES-GCM encryption factory, blob encryptor, and dev key store moved out of
`Stratara.Infrastructure` into `Stratara.Security`; `AddSecurity()` now delegates to it. The
field/JSON `[EncryptData]` path (`ISecureJsonSerializer`) stays in `Stratara.Infrastructure`.
This brings the lockstep family to **22 packable packages**.