Zongsoft.Security.Web 7.7.0

dotnet add package Zongsoft.Security.Web --version 7.7.0
                    
NuGet\Install-Package Zongsoft.Security.Web -Version 7.7.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Zongsoft.Security.Web" Version="7.7.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Zongsoft.Security.Web" Version="7.7.0" />
                    
Directory.Packages.props
<PackageReference Include="Zongsoft.Security.Web" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Zongsoft.Security.Web --version 7.7.0
                    
#r "nuget: Zongsoft.Security.Web, 7.7.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Zongsoft.Security.Web@7.7.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Zongsoft.Security.Web&version=7.7.0
                    
Install as a Cake Addin
#tool nuget:?package=Zongsoft.Security.Web&version=7.7.0
                    
Install as a Cake Tool

Zongsoft.Security.Web Security Plugin Library

License NuGet Version NuGet Downloads GitHub Stars

English | 简体中文


Overview

Zongsoft.Security.Web is a sub-plugin of the security plugin library for the Zongsoft open-source framework. It provides Web plugin support for the security feature set.

It publishes the framework security services as ASP.NET Core controllers: sign-in/sign-out/renewal, secret verification, CAPTCHA issue/verification, users, roles, memberships, passwords, and privileges. The package is an HTTP projection of Zongsoft.Security, not an independent identity store.

Installation and Hosting

dotnet add package Zongsoft.Security.Web

Deploy Zongsoft.Security.Web.plugin with a plugin-aware web host. Its manifest depends on Zongsoft.Security; the core security plugin, data mapping, database schema, credential authentication, and authorization services must already be available.

Endpoint Groups

Controller Responsibility
AuthenticationController sign in by scheme/key, sign out, renew credentials, issue and verify secrets
CaptchaController issue and verify an ICaptcha scheme
UserController user lifecycle, contact verification, password and membership operations
RoleController role lifecycle, members, parents, and inherited relationships
nested privilege controllers direct and filtering privileges for users or roles
AuthorizationController inspect authorization schemes and evaluated privileges

Routes are determined by framework MVC conventions. Use the checked-in HTTP request examples or generated OpenAPI metadata to discover the exact route and payload shape for the deployed version.

Typical Flow

  1. Issue a CAPTCHA or out-of-band secret when the selected policy requires it.
  2. Sign in through an authenticator scheme and capture the returned credential.
  3. Send that credential through the configured authentication handler.
  4. Authorize each operation; renew or sign out according to credential lifetime.

💡 The scheme, scenario, and verification channel are domain values resolved by registered services. Do not invent client-side values without checking the host configuration.

🚨 These controllers mutate identity and privilege state. Require TLS, apply rate limits, restrict administrative operations, prevent cross-tenant identifiers, validate antiforgery needs for browser credentials, and never expose raw password or secret payloads in logs.

Responses and Cancellation

Controllers use standard HTTP status codes, framework pagination, and cancellation tokens. Bulk or reset operations can replace memberships or privileges; clients must distinguish additive operations from reset=true. Cancellation is not proof that a server-side mutation was rolled back—use idempotency and reread state where retries are possible.

Plugin-Based Integration

Compose this feature through the host; a package reference supplies compile-time APIs, while plugin loading also requires deployed manifests and runtime assets. See the complete plugin workflow.

Use a Plugins.Web host and deploy the corresponding main adapter listed below. Service/controller discovery runs during host initialization; do not put business logic into Program.cs. Verify the configured endpoint and authorization before accepting requests.

Runtime artifact Source of truth
Zongsoft.Security.Web Zongsoft.Security.Web.plugin
File copying and dependencies Zongsoft.Security.Web.deploy

Add this fragment to an existing host .deploy (retain Main and the host’s other base manifests; do not replace the whole file):

[plugins zongsoft data]
nuget:Zongsoft.Data

[plugins zongsoft security]
nuget:Zongsoft.Security

[plugins zongsoft security web]
nuget:Zongsoft.Security.Web

Run dotnet deploy against a test deployment as explained in the workflow, with the host's framework, platform, architecture and, where needed, site. Pin compatible versions in real deployments; application dependencies such as databases, caches or commercial runtimes are still separate prerequisites.

Additional artifacts listed by the deployment manifest include Zongsoft.Security.Web.plugin. Retain assemblies, dependencies and satellite resource directories as well. Restart the host after deployment, check plugin loading and service/driver registration, then verify the workflow above; copied files alone do not prove that the feature is active.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
7.7.0 79 9/28/2026
7.6.5 157 4/5/2026
7.6.4 140 3/12/2026
7.6.3 242 11/28/2025
7.6.2 271 11/26/2025
7.6.1 423 9/16/2025
7.6.0 350 8/28/2025
7.5.2 618 7/24/2025
7.5.1 320 6/18/2025
7.5.0 290 4/25/2025
7.4.1 320 4/23/2025
7.4.0 348 4/14/2025
7.3.0 326 4/8/2025
7.2.0 330 4/7/2025
7.1.1 305 3/28/2025
7.1.0 622 3/26/2025
7.0.0 272 2/24/2025
Loading failed