Stratara.Identity.AspNetCore
4.0.3
Prefix Reserved
dotnet add package Stratara.Identity.AspNetCore --version 4.0.3
NuGet\Install-Package Stratara.Identity.AspNetCore -Version 4.0.3
<PackageReference Include="Stratara.Identity.AspNetCore" Version="4.0.3" />
<PackageVersion Include="Stratara.Identity.AspNetCore" Version="4.0.3" />
<PackageReference Include="Stratara.Identity.AspNetCore" />
paket add Stratara.Identity.AspNetCore --version 4.0.3
#r "nuget: Stratara.Identity.AspNetCore, 4.0.3"
#:package Stratara.Identity.AspNetCore@4.0.3
#addin nuget:?package=Stratara.Identity.AspNetCore&version=4.0.3
#tool nuget:?package=Stratara.Identity.AspNetCore&version=4.0.3
Stratara.Identity.AspNetCore
Derived. The behaviour described here is specified under
openspec/specs/. Those specifications are the source; this page explains and illustrates them.
License: MIT.
Channel-agnostic ASP.NET Core identity wiring for the Stratara stack. Provides the AddAspNetIdentity / AddAspNetIdentityWithSignInManager extension methods and an IStrataraSignInManager wrapper around the ASP.NET Core SignInManager. Channel-specific glue (Blazor Server's AuthenticationStateProvider, MAUI session-state forwarders, etc.) is the consumer's responsibility — Stratara intentionally stops at the ASP.NET-Core-generic surface to stay application-agnostic.
What's in the box
| Folder | Contents |
|---|---|
DependencyInjection/AspCoreIdentityHostBuilderExtensions |
AddAspNetIdentity<TUser, TIdentityDbContext>() (Stratara password/schema-v3/passkey defaults — no lockout), AddAspNetIdentityWithSignInManager<TUser, TIdentityDbContext>() (same + lockout defaults + AspNetSignInManager + localization), AddDevelopmentNoOpEmailSender<TUser>() (dev-only, throws in Production) |
Lockout only ships with the sign-in manager.
ApplyStrataraLockoutDefaultsruns insideAddAspNetIdentityWithSignInManageronly — the bareAddAspNetIdentityleaves ASP.NET Identity's own lockout defaults in place. If you wire sign-in yourself on top ofAddAspNetIdentity, configureIdentityOptions.Lockoutexplicitly; otherwise password attempts are not throttled the way the rest of this package assumes. |Services/AspNetSignInManager<TUser>| WrapsSignInManager<TUser>+UserManager<TUser>and producesStrataraSignInResultwith already-localized failure messages | |Services/IdentityNoOpEmailSender<TUser>| Development-time email sender that drops every email (Task.CompletedTask); replace in production | |Resources/IdentityResources| Resource-anchor for sign-in failure messages. English default ships inIdentityResources.resx;IdentityResources.de.resxprovides German overrides.AddAspNetIdentityWithSignInManagercallsAddLocalization()soIStringLocalizer<IdentityResources>resolves automatically. | |DependencyInjection/MembershipClaimsServiceCollectionExtensions+Services/MembershipClaims*| Sign-in tenant-claim bridge:AddMembershipTenantClaim<TUser>()(stampstratara:tenant_idat issuance) andAddMembershipTenantClaimsTransformation()(resolve live per request) | |Authorization/*+DependencyInjection/PermissionPolicyServiceCollectionExtensions|AddStrataraPermissionPolicies()— every catalog permission becomes an on-demand[Authorize("...")]policy backed byIPermissionResolver| |Authentication/ApiKey*+DependencyInjection/ApiKeyAuthenticationExtensions|AddStrataraApiKey()(X-Api-Key scheme overIApiKeyStore) andAddStrataraAuthSchemeSelector()(route API-key vs. Bearer vs. cookie by request shape) | |Authentication/Stratara{OpenIdConnect,JwtBearer}Options+DependencyInjection/OpenIdConnectAuthenticationExtensions|AddStrataraOpenIdConnect(configuration)(interactive external login) andAddStrataraJwtBearer(configuration)(API access-token validation, multi-issuer byiss) | |Services/ExternalLoginProvisioningService<TUser>+DependencyInjection/ExternalLoginProvisioningExtensions|AddStrataraExternalLoginProvisioning<TUser>()— hardened JIT create/link of local accounts on first external sign-in (see below) |
Localization
AspNetSignInManager resolves its four user-facing failure messages (Identity.SignIn.Lockout, Identity.SignIn.InvalidCredentials, Identity.SignIn.InvalidTwoFactor, Identity.SignIn.InvalidRecoveryCode) via IStringLocalizer<IdentityResources>. A "not allowed" sign-in deliberately maps onto the InvalidCredentials message rather than getting its own, to avoid confirming that an account exists. Languages out of the box: English (default) and German (de). To add another culture, ship a satellite .resx (e.g. IdentityResources.fr.resx) in your own assembly and register a chained IStringLocalizer<IdentityResources> if needed. Selection follows CultureInfo.CurrentUICulture — wire up app.UseRequestLocalization(...) to map this from the request.
Quick start
// Channel-agnostic ASP.NET Core host (MVC, Razor Pages, Minimal API, ...):
builder.AddAspNetIdentityWithSignInManager<ApplicationUser, IdentityDbContext>();
// Or for a host without sign-in manager (e.g. a worker that only needs identity stores):
builder.AddAspNetIdentity<ApplicationUser, IdentityDbContext>();
For Blazor Server hosts, additionally register your own IStrataraAuthenticationStateProvider implementation (and the AuthenticationStateProvider forwarder). Stratara does not ship a Blazor-specific provider — the previous BlazorAuthenticationStateProvider lived here in 1.x but moved out in v2.0.0 to keep this package application-agnostic.
External login (OpenID Connect) + JIT provisioning
Add external identity providers as ordinary authentication schemes and provision local accounts on first sign-in:
builder.Services
.AddAuthentication(StrataraAuthSchemeSelectorOptions.SchemeName)
.AddCookie(IdentityConstants.ApplicationScheme)
.AddStrataraOpenIdConnect(builder.Configuration) // interactive "log in with <provider>"
.AddStrataraJwtBearer(builder.Configuration) // API access-token validation (iss-routed)
.AddStrataraAuthSchemeSelector(); // route Bearer vs. cookie per request
builder.Services.AddStrataraExternalLoginProvisioning<ApplicationUser>();
AddStrataraOpenIdConnect binds Identity:OpenIdConnect (Authority, ClientId, ClientSecret,
Scopes) and AddStrataraJwtBearer binds Identity:JwtBearer (Authority, Audience, ValidIssuers).
Both key the principal on the issuer sub, never on email — Entra, Keycloak, and generic OIDC differ
only in configuration.
ExternalLoginProvisioningService<TUser> creates or links the local account on a first external
sign-in with the account-takeover defenses on by default: it links on the issuer's (provider, sub);
auto-links to a pre-existing account only when the email is verified by the provider
(email_verified/xms_edov) and already confirmed locally — otherwise it returns
RequiresInteractiveLinking and refuses to merge; honors an optional invitation gate and an
AutoProvision switch; and fails closed. Call it from your sign-in callback (for example the OpenID
Connect OnTicketReceived event). The Stratara.Sample.Identity sample shows the full wiring.
Dependencies
Stratara.Identity.Core— channel-agnostic abstractions (IStrataraSignInManager,IStrataraAuthenticationStateProvider) + shared model records.Stratara.Shared— multitenancy + session-context types.Microsoft.AspNetCore.App— shared framework reference forSignInManager,IEmailSender<TUser>, etc.Microsoft.AspNetCore.Identity.EntityFrameworkCore— ASP.NET Identity stores.Microsoft.AspNetCore.Authentication.OpenIdConnect,Microsoft.AspNetCore.Authentication.JwtBearer— external-login OIDC + API bearer-token schemes.Microsoft.IdentityModel.JsonWebTokens,System.IdentityModel.Tokens.Jwt— JWT helpers for token-based flows.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.11)
- Microsoft.AspNetCore.Authentication.OpenIdConnect (>= 10.0.11)
- Microsoft.AspNetCore.Identity.EntityFrameworkCore (>= 10.0.11)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.22.0)
- Stratara.Identity.Core (>= 4.0.3)
- Stratara.Shared (>= 4.0.3)
- System.IdentityModel.Tokens.Jwt (>= 8.22.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.3 | 51 | 9/3/2026 |
| 4.0.2 | 79 | 9/3/2026 |
| 4.0.1 | 95 | 9/2/2026 |
| 4.0.0 | 242 | 8/31/2026 |
| 4.0.0-preview.1 | 42 | 8/31/2026 |
| 3.4.0 | 120 | 8/28/2026 |
| 3.3.0 | 320 | 8/25/2026 |
| 3.2.3 | 92 | 8/22/2026 |
| 3.2.2 | 710 | 8/14/2026 |
| 3.2.1 | 696 | 8/2/2026 |
| 3.2.0 | 108 | 7/18/2026 |
| 3.1.7 | 123 | 7/1/2026 |
| 3.1.6 | 532 | 6/22/2026 |
| 3.1.5 | 121 | 6/22/2026 |
| 3.1.4 | 126 | 6/15/2026 |
| 3.1.3 | 122 | 6/10/2026 |
| 3.1.2 | 138 | 6/5/2026 |
| 3.1.1 | 212 | 6/1/2026 |
| 3.1.0 | 130 | 5/30/2026 |
| 3.0.23 | 118 | 5/28/2026 |
Three fixes to the same complaint: a host composed exactly as the documentation describes did not
start. Each one was a registration the composites assumed somebody else had made — a tracer, a unit
of work, a Redis connection — and each is now made by the registration that needs it. Nothing that
already worked changes: every fix defers to a registration the host makes itself, in either order,
so the lines a working host added to get past these gaps can simply be deleted. Additive on every
published surface.
### Fixed
- **A host without Redis starts and dispatches.** Every composite that carries a dispatcher
registered the projection-replay state, and its only implementation took a Redis connection that
no composite registers, so a host composed as documented failed at its first dispatch unless it
also ran Redis and called `AddCaching()`. `AddProjectionReplayState()` now chooses at first
resolution: with a registered `IConnectionMultiplexer` the Redis-backed state as before, without
one an in-process state with the same lease semantics — and a warning, once at start-up
(`104_012`), that replay coordination is confined to that process, so a replay requested there
suppresses publication there only. A deployment whose replay must reach several hosts registers
the shared connection, in either order. Redis-backed hosts observe no change.
- **Registering a store context now registers its unit of work.**
`AddNpgsqlWriteDbContextFactory<T>()` registered the context factory, the context and the default
connection resolver but not the `IWriteUnitOfWork` that the event source, the outbox dispatcher and
the command worker take from the container — and nothing else in the published packages did, so a
host composed exactly as documented failed at its first command with a dependency-injection error.
The write registration now try-adds a scoped `IWriteUnitOfWork` over its context, and
`AddNpgsqlReadDbContextFactory<T>()` try-adds `IProjectionsUnitOfWork` and `IReadUnitOfWork`
likewise. A unit of work the host registers itself, before or after, is still the one used; a
hand-written registration can simply be deleted.
- **`AddMediator()` no longer requires the host to register an OpenTelemetry `Tracer`.** The
mediator traces every dispatch and obtained its tracer from the host, but nothing registered one,
so a host that called `AddMediator()` and nothing else failed at the first resolve of `IMediator`.
`AddMediator()` now registers a fallback that emits the dispatch spans from the framework's
`Stratara.Application` activity source — a host that subscribes to framework telemetry sees them,
a host that subscribes to nothing pays for nothing. A `Tracer` the host registers, before or after
`AddMediator()`, is still the one used, so no existing host changes behaviour; the registration
line can simply be deleted. The samples, the README and the package README no longer carry it.