UKBatch.AspNetCore.OpenIdConnect
0.2.4-alpha
dotnet add package UKBatch.AspNetCore.OpenIdConnect --version 0.2.4-alpha
NuGet\Install-Package UKBatch.AspNetCore.OpenIdConnect -Version 0.2.4-alpha
<PackageReference Include="UKBatch.AspNetCore.OpenIdConnect" Version="0.2.4-alpha" />
<PackageVersion Include="UKBatch.AspNetCore.OpenIdConnect" Version="0.2.4-alpha" />
<PackageReference Include="UKBatch.AspNetCore.OpenIdConnect" />
paket add UKBatch.AspNetCore.OpenIdConnect --version 0.2.4-alpha
#r "nuget: UKBatch.AspNetCore.OpenIdConnect, 0.2.4-alpha"
#:package UKBatch.AspNetCore.OpenIdConnect@0.2.4-alpha
#addin nuget:?package=UKBatch.AspNetCore.OpenIdConnect&version=0.2.4-alpha&prerelease
#tool nuget:?package=UKBatch.AspNetCore.OpenIdConnect&version=0.2.4-alpha&prerelease
UKBatch.AspNetCore.OpenIdConnect
OpenID Connect login and role-gating for the UKBatch dashboard and REST API. It is a thin, opt-in layer over Microsoft's first-party Microsoft.AspNetCore.Authentication.OpenIdConnect, .JwtBearer, and .Cookies handlers — it works with any standards-compliant OpenID Connect identity provider (Keycloak, Azure AD, Auth0, IdentityServer, …) via the provider's Authority URL. There is no provider-specific code.
What it adds
- Dashboard login — an interactive OpenID Connect code flow with a cookie session and sign-out.
- Viewer / operator role-gating — read endpoints require an authenticated viewer; write endpoints require a configurable operator role. Approval gates keep their own per-gate allowed-roles check.
- Per-user token forwarding — the signed-in user's access token flows from the dashboard to the API, so the API sees the real user and roles and records approvals under the real person.
- Nested-role flattening — identity providers that emit roles nested inside a claim (for example Keycloak's
realm_access.roles/resource_access.*.roles) are flattened to standard role claims automatically.
Usage
builder.Services.AddUKBatchOpenIdConnect(o =>
{
o.Authority = "https://keycloak.example.com/realms/ukbatch";
o.ClientId = "ukbatch-dashboard";
o.ClientSecret = builder.Configuration["Oidc:ClientSecret"];
o.Audience = "ukbatch-api";
o.OperatorRoles = ["batch-operator"];
});
// API: gate reads to viewers, writes to operators.
app.MapGroup("/api").MapUKBatchApi().RequireUKBatchRoleAuthorization();
// Dashboard: require a signed-in session and forward the user's token.
app.MapUKBatchDashboard().RequireAuthorization();
app.MapUKBatchSignOut();
See the repository documentation for the full options and a runnable Keycloak sample.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Cronos (>= 0.10.0)
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 10.0.0)
- Microsoft.AspNetCore.Authentication.OpenIdConnect (>= 10.0.0)
- Polly (>= 8.5.0)
- UKBatch.AspNetCore (>= 0.2.4-alpha)
-
net8.0
- Cronos (>= 0.10.0)
- Microsoft.AspNetCore.Authentication.JwtBearer (>= 8.0.27)
- Microsoft.AspNetCore.Authentication.OpenIdConnect (>= 8.0.27)
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.0)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.0)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.0)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.0)
- Microsoft.Extensions.Options (>= 10.0.0)
- Polly (>= 8.5.0)
- UKBatch.AspNetCore (>= 0.2.4-alpha)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.2.4-alpha | 41 | 7/23/2026 |