Stratara.Identity.AspNetCore
4.0.4
Prefix Reserved
See the version list below for details.
dotnet add package Stratara.Identity.AspNetCore --version 4.0.4
NuGet\Install-Package Stratara.Identity.AspNetCore -Version 4.0.4
<PackageReference Include="Stratara.Identity.AspNetCore" Version="4.0.4" />
<PackageVersion Include="Stratara.Identity.AspNetCore" Version="4.0.4" />
<PackageReference Include="Stratara.Identity.AspNetCore" />
paket add Stratara.Identity.AspNetCore --version 4.0.4
#r "nuget: Stratara.Identity.AspNetCore, 4.0.4"
#:package Stratara.Identity.AspNetCore@4.0.4
#addin nuget:?package=Stratara.Identity.AspNetCore&version=4.0.4
#tool nuget:?package=Stratara.Identity.AspNetCore&version=4.0.4
Stratara.Identity.AspNetCore
Derived. The behaviour described here is specified under
openspec/specs/. Those specifications are the source; this page explains and illustrates them.
License: MIT.
Channel-agnostic ASP.NET Core identity wiring for the Stratara stack. Provides the AddAspNetIdentity / AddAspNetIdentityWithSignInManager extension methods and an IStrataraSignInManager wrapper around the ASP.NET Core SignInManager. Channel-specific glue (Blazor Server's AuthenticationStateProvider, MAUI session-state forwarders, etc.) is the consumer's responsibility — Stratara intentionally stops at the ASP.NET-Core-generic surface to stay application-agnostic.
What's in the box
| Folder | Contents |
|---|---|
DependencyInjection/AspCoreIdentityHostBuilderExtensions |
AddAspNetIdentity<TUser, TIdentityDbContext>() (Stratara password/schema-v3/passkey defaults — no lockout), AddAspNetIdentityWithSignInManager<TUser, TIdentityDbContext>() (same + lockout defaults + AspNetSignInManager + localization), AddDevelopmentNoOpEmailSender<TUser>() (dev-only, throws in Production) |
Lockout only ships with the sign-in manager.
ApplyStrataraLockoutDefaultsruns insideAddAspNetIdentityWithSignInManageronly — the bareAddAspNetIdentityleaves ASP.NET Identity's own lockout defaults in place. If you wire sign-in yourself on top ofAddAspNetIdentity, configureIdentityOptions.Lockoutexplicitly; otherwise password attempts are not throttled the way the rest of this package assumes. |Services/AspNetSignInManager<TUser>| WrapsSignInManager<TUser>+UserManager<TUser>and producesStrataraSignInResultwith already-localized failure messages | |Services/IdentityNoOpEmailSender<TUser>| Development-time email sender that drops every email (Task.CompletedTask); replace in production | |Resources/IdentityResources| Resource-anchor for sign-in failure messages. English default ships inIdentityResources.resx;IdentityResources.de.resxprovides German overrides.AddAspNetIdentityWithSignInManagercallsAddLocalization()soIStringLocalizer<IdentityResources>resolves automatically. | |DependencyInjection/MembershipClaimsServiceCollectionExtensions+Services/MembershipClaims*| Sign-in tenant-claim bridge:AddMembershipTenantClaim<TUser>()(stampstratara:tenant_idat issuance) andAddMembershipTenantClaimsTransformation()(resolve live per request) | |Authorization/*+DependencyInjection/PermissionPolicyServiceCollectionExtensions|AddStrataraPermissionPolicies()— every catalog permission becomes an on-demand[Authorize("...")]policy backed byIPermissionResolver| |Authentication/ApiKey*+DependencyInjection/ApiKeyAuthenticationExtensions|AddStrataraApiKey()(X-Api-Key scheme overIApiKeyStore) andAddStrataraAuthSchemeSelector()(route API-key vs. Bearer vs. cookie by request shape) | |Authentication/Stratara{OpenIdConnect,JwtBearer}Options+DependencyInjection/OpenIdConnectAuthenticationExtensions|AddStrataraOpenIdConnect(configuration)(interactive external login) andAddStrataraJwtBearer(configuration)(API access-token validation, multi-issuer byiss) | |Services/ExternalLoginProvisioningService<TUser>+DependencyInjection/ExternalLoginProvisioningExtensions|AddStrataraExternalLoginProvisioning<TUser>()— hardened JIT create/link of local accounts on first external sign-in (see below) |
Localization
AspNetSignInManager resolves its four user-facing failure messages (Identity.SignIn.Lockout, Identity.SignIn.InvalidCredentials, Identity.SignIn.InvalidTwoFactor, Identity.SignIn.InvalidRecoveryCode) via IStringLocalizer<IdentityResources>. A "not allowed" sign-in deliberately maps onto the InvalidCredentials message rather than getting its own, to avoid confirming that an account exists. Languages out of the box: English (default) and German (de). To add another culture, ship a satellite .resx (e.g. IdentityResources.fr.resx) in your own assembly and register a chained IStringLocalizer<IdentityResources> if needed. Selection follows CultureInfo.CurrentUICulture — wire up app.UseRequestLocalization(...) to map this from the request.
Quick start
// Channel-agnostic ASP.NET Core host (MVC, Razor Pages, Minimal API, ...):
builder.AddAspNetIdentityWithSignInManager<ApplicationUser, IdentityDbContext>();
// Or for a host without sign-in manager (e.g. a worker that only needs identity stores):
builder.AddAspNetIdentity<ApplicationUser, IdentityDbContext>();
For Blazor Server hosts, additionally register your own IStrataraAuthenticationStateProvider implementation (and the AuthenticationStateProvider forwarder). Stratara does not ship a Blazor-specific provider — the previous BlazorAuthenticationStateProvider lived here in 1.x but moved out in v2.0.0 to keep this package application-agnostic.
External login (OpenID Connect) + JIT provisioning
Add external identity providers as ordinary authentication schemes and provision local accounts on first sign-in:
builder.Services
.AddAuthentication(StrataraAuthSchemeSelectorOptions.SchemeName)
.AddCookie(IdentityConstants.ApplicationScheme)
.AddStrataraOpenIdConnect(builder.Configuration) // interactive "log in with <provider>"
.AddStrataraJwtBearer(builder.Configuration) // API access-token validation (iss-routed)
.AddStrataraAuthSchemeSelector(); // route Bearer vs. cookie per request
builder.Services.AddStrataraExternalLoginProvisioning<ApplicationUser>();
AddStrataraOpenIdConnect binds Identity:OpenIdConnect (Authority, ClientId, ClientSecret,
Scopes) and AddStrataraJwtBearer binds Identity:JwtBearer (Authority, Audience, ValidIssuers).
Both key the principal on the issuer sub, never on email — Entra, Keycloak, and generic OIDC differ
only in configuration.
ExternalLoginProvisioningService<TUser> creates or links the local account on a first external
sign-in with the account-takeover defenses on by default: it links on the issuer's (provider, sub);
auto-links to a pre-existing account only when the email is verified by the provider
(email_verified/xms_edov) and already confirmed locally — otherwise it returns
RequiresInteractiveLinking and refuses to merge; honors an optional invitation gate and an
AutoProvision switch; and fails closed. Call it from your sign-in callback (for example the OpenID
Connect OnTicketReceived event). The Stratara.Sample.Identity sample shows the full wiring.
Dependencies
Stratara.Identity.Core— channel-agnostic abstractions (IStrataraSignInManager,IStrataraAuthenticationStateProvider) + shared model records.Stratara.Shared— multitenancy + session-context types.Microsoft.AspNetCore.App— shared framework reference forSignInManager,IEmailSender<TUser>, etc.Microsoft.AspNetCore.Identity.EntityFrameworkCore— ASP.NET Identity stores.Microsoft.AspNetCore.Authentication.OpenIdConnect,Microsoft.AspNetCore.Authentication.JwtBearer— external-login OIDC + API bearer-token schemes.Microsoft.IdentityModel.JsonWebTokens,System.IdentityModel.Tokens.Jwt— JWT helpers for token-based flows.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.11)
- Microsoft.AspNetCore.Authentication.OpenIdConnect (>= 10.0.11)
- Microsoft.AspNetCore.Identity.EntityFrameworkCore (>= 10.0.11)
- Microsoft.IdentityModel.JsonWebTokens (>= 8.22.0)
- Stratara.Identity.Core (>= 4.0.4)
- Stratara.Shared (>= 4.0.4)
- System.IdentityModel.Tokens.Jwt (>= 8.22.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.3.0 | 0 | 9/23/2026 |
| 4.2.0 | 97 | 9/18/2026 |
| 4.1.1 | 87 | 9/16/2026 |
| 4.1.0 | 87 | 9/16/2026 |
| 4.0.4 | 862 | 9/14/2026 |
| 4.0.3 | 115 | 9/3/2026 |
| 4.0.2 | 593 | 9/3/2026 |
| 4.0.1 | 231 | 9/2/2026 |
| 4.0.0 | 662 | 8/31/2026 |
| 4.0.0-preview.1 | 62 | 8/31/2026 |
| 3.4.0 | 137 | 8/28/2026 |
| 3.3.0 | 333 | 8/25/2026 |
| 3.2.3 | 106 | 8/22/2026 |
| 3.2.2 | 725 | 8/14/2026 |
| 3.2.1 | 708 | 8/2/2026 |
| 3.2.0 | 116 | 7/18/2026 |
| 3.1.7 | 131 | 7/1/2026 |
| 3.1.6 | 536 | 6/22/2026 |
| 3.1.5 | 122 | 6/22/2026 |
| 3.1.4 | 128 | 6/15/2026 |
Three findings from a proof of concept of an alternative execution model, each fixed on the shipped
path. A message a handler cannot take is now redelivered a bounded number of times and then
dead-lettered on both brokers instead of being dropped on one of them; an opt-in closes the window
in which a committed fact could be lost between the commit and its publication; and a version
collision is a concurrency conflict on every supported database provider, not only on PostgreSQL.
Additive on every published surface, with one operator step on RabbitMQ: the worker queues change
name and type, and the old ones are deleted once drained.
### Added
- `Outbox:DurableBundles` (`OutboxOptions.DurableBundles`, default `false`): an event bundle is
written to the outbox table in the transaction that commits its events, published after the
commit, and removed once the bus has accepted it — so a process that ends between the commit and
the publish no longer loses the bundle for every subscription. `IEventBundleOutboxDispatcher`
gains `StoresBundlesWithCommit` and `StoreEventBundleAsync`, and `IOutboxRepository` an
`AddAsync(Guid id, …)` overload, all default-implemented so a consumer's own implementations keep
compiling and keep bus-first. `AddOutboxDispatcher()` now binds the `Outbox` section when the host
carries a configuration. Log event `106_108` records a stored copy the bus accepted but the
framework could not remove. The default path is unchanged; the specification now names its window.
- `IStoreConflictDetector` in `Stratara.Abstractions.EventSourcing`: recognises a database
provider's refusal of a duplicate stream version, so the event source can surface it as a
`ConcurrencyException` on that provider. `AddNpgsqlWriteDbContextFactory<T>()` registers the
PostgreSQL detector and `AddStrataraTestingEventStore<T>()` the SQLite one; detectors accumulate,
so a host on another provider adds its own without displacing the framework's. A host that
registers its write context without `AddNpgsqlWriteDbContextFactory<T>()` gets no detector and
no longer sees a `ConcurrencyException` on a version collision: it switches to that registration,
or registers an `IStoreConflictDetector` of its own that recognises PostgreSQL's SQL state
`23505` in the exception chain (the framework's implementations are not public).
- `MessageRetryOptions` (`Stratara.Abstractions.Messaging`, section `MessageRetry`):
`MaxDeliveryAttempts` (default 3) and `MaxConflictRequeues` (default 100), bound and validated by
`AddMessaging()` and by both `AddAzureServiceBus*` registrations. `MessageRetryPolicy` is the
decision both transports apply. Log event `108_110` and counter `messaging.dead_lettered`
(tags `messaging.topic`, `messaging.subscription`, `reason`) record every dead-lettering; `108_111`
warns when a Service Bus subscription's `MaxDeliveryCount` is below the bounds.
### Changed
- A save now maps and signs its event bundle before the transaction opens, so a save with no
session context — or a signer that fails — fails before anything is committed rather than after
the commit with the events stranded unpublished.
- **RabbitMQ worker subscriptions are quorum queues with a dead-letter queue, under a new name.**
A message whose handler throws is redelivered up to `MaxDeliveryAttempts` times (a concurrency
conflict up to `MaxConflictRequeues` times) and then moved to `<subscription>.dead-letter`; it was
rejected and dropped by the broker before (conflicts were requeued without bound). Because a
classic queue cannot be redeclared as a quorum queue, the worker queue is now
`<subscription>.v2`. **Rollout:** deploy — old and new consumers share the exchange and both
receive every message — then delete the old `<subscription>` queue once it is drained, or it fills
forever. Needs RabbitMQ 3.8+.
- **Azure Service Bus applies the same bounds.** A handler failure is abandoned for redelivery until
`MaxDeliveryAttempts` and then dead-lettered with reason `failure` (it was dead-lettered on the
first failure with the exception type as reason); a conflict is dead-lettered by the framework
past `MaxConflictRequeues` with reason `conflict` (it was left to the broker's `MaxDeliveryCount`).
Set the subscription's `MaxDeliveryCount` at least one above the larger bound.
- `AddAzureServiceBus` and `AddAzureServiceBusWithManagedIdentity` also register a
`ServiceBusAdministrationClient` (try-add) for the advisory limit check.
### Fixed
- The `MediatorCommandWorker` remark said a failing command was dead-lettered; on RabbitMQ it was
dropped. It is now dead-lettered on both brokers, and the remark and the
`BusEnvelopeIntegrityMode.Strict` remark say what happens.
- A duplicate stream version on the SQLite test store (`Stratara.Testing.EntityFrameworkCore`) now
surfaces as `ConcurrencyException`, as it does on PostgreSQL, instead of a bare
`DbUpdateException`. A test that asserted the old exception type needs the new one.