Stratara.Mediator
3.1.5
Prefix Reserved
See the version list below for details.
dotnet add package Stratara.Mediator --version 3.1.5
NuGet\Install-Package Stratara.Mediator -Version 3.1.5
<PackageReference Include="Stratara.Mediator" Version="3.1.5" />
<PackageVersion Include="Stratara.Mediator" Version="3.1.5" />
<PackageReference Include="Stratara.Mediator" />
paket add Stratara.Mediator --version 3.1.5
#r "nuget: Stratara.Mediator, 3.1.5"
#:package Stratara.Mediator@3.1.5
#addin nuget:?package=Stratara.Mediator&version=3.1.5
#tool nuget:?package=Stratara.Mediator&version=3.1.5
Stratara.Mediator
License: FSL-1.1-MIT (Functional Source License — source-available; converts to MIT after 2 years). Not OSI-approved OSS.
In-process mediator with DI-resolved handlers and pipeline behaviors. Drop-in replacement for MediatR-style routing without the runtime cost of MethodInfo.Invoke — uses a typed wrapper cache and direct DI dispatch.
Quick start
services.AddMediator()
.AddCommandHandlersFromAssemblyContaining<Program>()
.AddQueryHandlersFromAssemblyContaining<Program>()
.AddPipelineBehaviorWithResult(typeof(LoggingBehavior<,>))
.AddPipelineBehavior(typeof(LoggingBehavior<>));
// Optional: wrap in authorization decorator
services.AddAuthorizingMediator<MyAuthorizationProvider>();
What's in the box
IMediator.HandleAsync<TResult>(IRequest<TResult>, CancellationToken)— routes queries and commands-with-result toIQueryHandler<TRequest, TResult>through any registeredIPipelineBehavior<TRequest, TResult>chain.IMediator.HandleAsync<TRequest>(TRequest, CancellationToken)— routes void commands toICommandHandler<TRequest>through any registeredIPipelineBehavior<TRequest>chain.AuthorizingMediatordecorator — checks[RequireRole]attributes on the request type viaIAuthorizationProviderbefore delegating to the inner mediator.BucketLockPool— concurrency primitive that serialisesIAggregateScopedCommanddispatch per bucket id. Used by message-bus consumers (e.g.Stratara.Infrastructure'sMediatorCommandWorker) to keep aggregate writes single-writer.
Pipeline behavior contract
Behaviors run outer-to-inner in DI registration order:
public sealed class LoggingBehavior<TRequest, TResult> : IPipelineBehavior<TRequest, TResult>
where TRequest : IRequest<TResult>
{
public async Task<TResult> HandleAsync(
TRequest request, Func<Task<TResult>> next, CancellationToken cancellationToken)
{
// before
var result = await next();
// after
return result;
}
}
Tenant isolation
AddStrataraTenantIsolation() registers a pipeline behavior that enforces tenant isolation at the
mediator entrance — before the handler runs — for any request that opts in by implementing the
ITenantScopedRequest marker. Requests that do not implement the marker pass through untouched.
public sealed record GetCustomerQuery(Guid CustomerId, Guid TenantId)
: IQuery<CustomerDto>, ITenantScopedRequest;
services
.AddStrataraValidation() // validation stays outermost
.AddStrataraTenantIsolation(); // then tenant isolation
The behavior compares the request's TenantId (the data owner) against the ambient session's
data-owner tenant (SessionContext.TenantId), not the actor tenant (SessionContext.ActorTenantId).
A request whose payload names a different tenant than the established session subject is rejected with
TenantAccessDeniedException (translated to HTTP 403 by AuthorizationExceptionMiddleware on ASP.NET
hosts; surfaced through the message-failure path on workers).
Default vs. strict mode
TenantIsolationMode.Default— enforces only the subject match. A privileged cross-tenant operation (actor tenant ≠ data-owner tenant) passes, because the calling endpoint is expected to have promoted the session's data-owner tenant to the target before dispatch.TenantIsolationMode.Strict— additionally routes every cross-tenant operation through anICrossTenantAuthorizer. Stratara registers a deny-all default (viaTryAdd), so strict mode rejects all cross-tenant access until you register your own authorizer that grants it:
services.AddStrataraTenantIsolation(o => o.Mode = TenantIsolationMode.Strict);
services.AddScoped<ICrossTenantAuthorizer, PlatformAdminCrossTenantAuthorizer>();
internal sealed class PlatformAdminCrossTenantAuthorizer(IHttpContextAccessor http)
: ICrossTenantAuthorizer
{
public ValueTask<bool> IsCrossTenantAllowedAsync(SessionContext session, CancellationToken ct) =>
ValueTask.FromResult(http.HttpContext?.User.IsInRole("PlatformAdmin") ?? false);
}
The behavior runs both in-process (queries via
IMediatorat the endpoint, whereHttpContextis available) and worker-side (commands dispatched through the outbox, where there is noHttpContext). AnICrossTenantAuthorizerthat needs request-role state should be applied on the in-process path; the worker path must base its decision on theSessionContextalone.
Dependencies
Stratara.Abstractions— forIMediator/IRequest/ICommand/IQuery/IPipelineBehaviorcontracts, plusITenantScopedRequest/ICrossTenantAuthorizer/TenantAccessDeniedException.Stratara.Diagnostics— log-event IDs for the tenant-isolation behavior.Microsoft.Extensions.DependencyInjection.Abstractions.Microsoft.Extensions.Logging.Abstractions.OpenTelemetry.Api— emits anActivityper dispatch under theStratara.Applicationsource.
No EF Core, no message bus, no event sourcing. Library-safe.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- JetBrains.Annotations (>= 2025.2.4)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
- OpenTelemetry.Api (>= 1.15.3)
- Stratara.Abstractions (>= 3.1.5)
- Stratara.Diagnostics (>= 3.1.5)
NuGet packages (3)
Showing the top 3 NuGet packages that depend on Stratara.Mediator:
| Package | Downloads |
|---|---|
|
Stratara.Validation
Vendor-neutral request validation for the Stratara framework — a mediator pipeline behavior that runs IValidator<T> implementations before the handler and throws an aggregated StrataraValidationException on failure. No FluentValidation dependency; an optional adapter is shipped separately. |
|
|
Stratara.Outbox.RabbitMQ
Outbox-pattern command and event dispatch for the Stratara event-sourced stack — RabbitMQ IMessageBus implementation, retry worker, mediator command worker, and Redis-coordinated projection-replay state. Azure Service Bus support ships as the sibling Stratara.Outbox.AzureServiceBus package. |
|
|
Stratara.Infrastructure
Infrastructure glue for the Stratara framework — authorization decorators, configuration providers, and DI composition helpers that wire Mediator, Outbox, Identity, and EF Core into a hosted app. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 4.0.3 | 133 | 9/3/2026 |
| 4.0.2 | 455 | 9/3/2026 |
| 4.0.1 | 185 | 9/2/2026 |
| 4.0.0 | 443 | 8/31/2026 |
| 4.0.0-preview.1 | 78 | 8/31/2026 |
| 3.4.0 | 162 | 8/28/2026 |
| 3.3.0 | 368 | 8/25/2026 |
| 3.2.3 | 158 | 8/22/2026 |
| 3.2.2 | 765 | 8/14/2026 |
| 3.2.1 | 406 | 8/2/2026 |
| 3.2.0 | 161 | 7/18/2026 |
| 3.1.7 | 312 | 7/1/2026 |
| 3.1.6 | 587 | 6/22/2026 |
| 3.1.5 | 169 | 6/22/2026 |
| 3.1.4 | 2,031 | 6/15/2026 |
| 3.1.3 | 175 | 6/10/2026 |
| 3.1.2 | 184 | 6/5/2026 |
| 3.1.1 | 897 | 6/1/2026 |
| 3.1.0 | 160 | 5/30/2026 |
| 3.0.23 | 163 | 5/28/2026 |
### Added
- **Configurable snapshot strategy** (`Stratara.Abstractions`, `Stratara.Infrastructure`) — the
snapshot cadence is no longer hard-coded. A new `Stratara.Abstractions.EventSourcing.ISnapshotStrategy`
decides, per stream, whether the event-sourcing runtime should write a snapshot:
`bool ShouldSnapshot(Type aggregateType, long currentVersion, long lastSnapshotVersion)`.
`AddEventSourcing()` registers the default `VersionThresholdSnapshotStrategy` (snapshot every 50
versions — identical to the previous behaviour) via `TryAddSingleton`, so existing consumers see no
change. To take over the policy, register your own singleton `ISnapshotStrategy` (it overrides the
default whether registered before or after `AddEventSourcing()`): vary the threshold per aggregate
type, construct `new VersionThresholdSnapshotStrategy(threshold)` for a different uniform cadence, or
register `NoSnapshotStrategy` to disable snapshotting entirely. This replaces the previously
hard-coded `UseSnapshots`/`SnapshotRange` constants in the default snapshot service, which were not
actually configurable despite the documentation implying they were.
- **`AddDomainEventTypesFromAssemblyContaining<T>()`** (`Stratara.Abstractions`) — registers *only* the
domain event types consumed by an assembly's aggregate `Apply(TEvent)` methods in the trusted-type
resolver, without registering the aggregate types themselves and without pulling any projection / saga
/ command-handler classes into DI. Use it in a host that only needs to deserialize event payloads off
the message bus or event stream — typically a dedicated projection or saga worker — but must not wire
the handler classes (and their runtime dependencies) that `AddProjectionsFromAssemblyContaining<T>`
would register. Complements the existing `AddAggregatesFromAssemblyContaining<T>` (which additionally
registers the aggregate types) and `AddTrustedType<T>` (single type).