Stratara.Identity.Core
4.0.2
Prefix Reserved
See the version list below for details.
dotnet add package Stratara.Identity.Core --version 4.0.2
NuGet\Install-Package Stratara.Identity.Core -Version 4.0.2
<PackageReference Include="Stratara.Identity.Core" Version="4.0.2" />
<PackageVersion Include="Stratara.Identity.Core" Version="4.0.2" />
<PackageReference Include="Stratara.Identity.Core" />
paket add Stratara.Identity.Core --version 4.0.2
#r "nuget: Stratara.Identity.Core, 4.0.2"
#:package Stratara.Identity.Core@4.0.2
#addin nuget:?package=Stratara.Identity.Core&version=4.0.2
#tool nuget:?package=Stratara.Identity.Core&version=4.0.2
Stratara.Identity.Core
Derived. The behaviour described here is specified under
openspec/specs/. Those specifications are the source; this page explains and illustrates them.
License: MIT.
Channel-agnostic identity primitives for the Stratara stack. Ships the shared model records, interfaces, and the typed HttpClient wrapper consumed by host-specific packages (e.g. Stratara.Identity.AspNetCore for server-side Blazor, with consumer-supplied implementations for non-web hosts such as mobile or desktop).
What's in the box
| Folder | Contents |
|---|---|
Models/ |
AccessTokenInfo (persisted token + expiry), LoginRequest / LoginResponse (HTTP payload shape), ClaimsResponse / ClaimDto (identity-endpoint claims), StrataraSignInResult (standalone, channel-agnostic sign-in outcome with localized failure message, token info, resolved user id, two-factor / lockout flags — no inheritance from Microsoft.AspNetCore.Identity.SignInResult) |
Abstractions/ |
IStrataraSignInManager (per-channel sign-in dispatch), IStrataraAuthenticationStateProvider (auth-state surface), ITokenStorage (secure-storage abstraction), IStrataraRedirectManager (host-native post-auth redirect) |
HttpClientHelper.cs |
IHttpClientHelper + default impl — typed wrapper so identity services can depend on the right configured HttpClient (auth handler + base address) without coupling to specific names |
Quick start
Reference this package from any host or library that needs to consume the Stratara identity surface (model records or the abstractions). Host-specific concrete implementations live in Stratara.Identity.AspNetCore for server-side Blazor; non-web host implementations are supplied by the consumer app.
Dependencies
Stratara.Shared— diagnostics, multitenancy types, session-context helpers used by the host-specific implementations downstream.
No ASP.NET Core / Microsoft.AspNetCore.Identity dependency by design — this package is consumable from MAUI, console, and unit-test contexts without dragging the ASP.NET runtime in transitively.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Stratara.Shared (>= 4.0.2)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Stratara.Identity.Core:
| Package | Downloads |
|---|---|
|
Stratara.Identity.AspNetCore
Channel-agnostic ASP.NET Core identity wiring for the Stratara stack — AddAspNetIdentity and AddAspNetIdentityWithSignInManager extensions, IStrataraSignInManager wrapper, EF stores, i18n'd failure messages, optional passkey support, external-login OpenID Connect + JWT-bearer helpers, and hardened JIT external-login provisioning. Consumers wire their own AuthenticationStateProvider (Blazor Server, MAUI, etc.). |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.3 | 0 | 9/3/2026 |
| 4.0.2 | 0 | 9/3/2026 |
| 4.0.1 | 65 | 9/2/2026 |
| 4.0.0 | 175 | 8/31/2026 |
| 4.0.0-preview.1 | 47 | 8/31/2026 |
| 3.4.0 | 99 | 8/28/2026 |
| 3.3.0 | 322 | 8/25/2026 |
| 3.2.3 | 107 | 8/22/2026 |
| 3.2.2 | 740 | 8/14/2026 |
| 3.2.1 | 704 | 8/2/2026 |
| 3.2.0 | 115 | 7/18/2026 |
| 3.1.7 | 125 | 7/1/2026 |
| 3.1.6 | 548 | 6/22/2026 |
| 3.1.5 | 124 | 6/22/2026 |
| 3.1.4 | 137 | 6/15/2026 |
| 3.1.3 | 126 | 6/10/2026 |
| 3.1.2 | 141 | 6/5/2026 |
| 3.1.1 | 219 | 6/1/2026 |
| 3.1.0 | 136 | 5/30/2026 |
| 3.0.23 | 127 | 5/28/2026 |
Two operational fixes, both found while a consumer rolled out bus-envelope signing and reasoned
about rebuilding its read models: a projection replay now survives a passing failure, and an
integrity failure says whether the signature was absent or wrong. Additive on every published
surface.
### Added
- **A projection replay retries a failing batch before it gives up.** Each batch — the read from
the event store and the application of its entries — now runs under a new named policy,
`ResilienceNames.ProjectionReplayBatch`: five attempts in all, exponential backoff from one second
with jitter between them, any exception except cancellation. A read-store timeout or a
dropped connection mid-rebuild no longer ends the replay; a failure that persists through every
attempt ends it exactly as before, with the same failure record. A retried batch is applied
again from its first entry in a fresh scope, which relies on the guarantee projections already
give under at-least-once delivery: a second application converges (see *Write handlers that
converge rather than accumulate* in the projection guide). Each failed attempt logs a new
warning, `104_011`. `AddResiliencePipelines` registers six policies rather than five. Nothing
about truncation, ordering, progress, the failure record or the lease changes.
### Changed
- **An integrity failure now says whether the signature was absent or wrong, and the existing
warning and error ids fire only for a signature that is present and does not verify.** An
unsigned envelope — what every not-yet-restarted publisher emits during a `Permissive` roll —
was logged as *"signature mismatch"* under the same id as a key mismatch or tampering, so an
operator could not tell a rolling restart from an attack without correlating host start times.
Four new event ids carry the unsigned case: `105_004` (command, permissive), `111_004` (event
bundle, permissive), `105_105` (command, strict) and `111_105` (event bundle, strict). The
existing `105_003`, `111_003`, `105_104` and `111_104` keep their numbers and their level but
now mean a present signature that did not verify; an alert keyed on one of them goes quiet
during a roll instead of firing for every unsigned message. Strict-mode rejections name the
case in their exception message. `BusEnvelopeIntegrityVerifier.Verify` gains an overload with
`out BusEnvelopeIntegrityFailure` (`None`, `Absent`, `Invalid`); the existing overload and the
`BusEnvelopeIntegrityResult` values are unchanged. An absent signature no longer reaches the
signer, which already answered `false` for it.