redb.Route.Http.Hosting 4.0.0

Prefix Reserved
There is a newer version of this package available.
See the version list below for details.
dotnet add package redb.Route.Http.Hosting --version 4.0.0
                    
NuGet\Install-Package redb.Route.Http.Hosting -Version 4.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="redb.Route.Http.Hosting" Version="4.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="redb.Route.Http.Hosting" Version="4.0.0" />
                    
Directory.Packages.props
<PackageReference Include="redb.Route.Http.Hosting" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add redb.Route.Http.Hosting --version 4.0.0
                    
#r "nuget: redb.Route.Http.Hosting, 4.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package redb.Route.Http.Hosting@4.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=redb.Route.Http.Hosting&version=4.0.0
                    
Install as a Cake Addin
#tool nuget:?package=redb.Route.Http.Hosting&version=4.0.0
                    
Install as a Cake Tool

redb.Route.Http.Hosting

Shared Kestrel HTTP hosting infrastructure for the redb.Route ESB framework.

Provides SharedHttpServerManager — a multiplexing HTTP server (one Kestrel per host:port, many routes) used by HTTP-based transports (redb.Route.Http, redb.Route.As2, …). Extracting it here lets those connectors share one server manager without depending on each other: register it once with services.AddRedbRouteHttpHosting() (idempotent), and every connector resolves the same singleton — so an HTTP route and an AS2 route in the same worker share one Kestrel and never fight over a port.

Standalone hosting only — depends on the ASP.NET runtime, not on redb.Route core or any connector.

TLS: asking for it selects the socket

A listener registered with ssl: true resolves its server certificate from, in order:

  1. the endpoint — sslCertPath / sslCertPassword on the route URI;
  2. a named connection factory, so the password stays out of the URI;
  3. the host default set here.
services.AddRedbRouteHttpHosting(o => o.Tls.DefaultCertificatePath = "/certs/server.pfx");
// or an already-loaded certificate:
services.AddRedbRouteHttpHosting(o => o.Tls.DefaultCertificate = cert);

This is the shape Camel gives global SSLContextParameters and Spring Boot gives SSL bundles: a certificate on the endpoint is an override, not a requirement. Nothing here turns TLS on — ssl stays an explicit per-endpoint decision; the host only answers "with which certificate".

A listener that asks for TLS and finds no certificate anywhere refuses to bind. It does not fall back to a plaintext socket, which is what nginx, httpd, Jetty, Spring Boot and Kestrel's own UseHttps() all do, and for the same reason: an open port behind an https:// banner is not "TLS off", it is a silent downgrade that operators cannot see.

Trusted proxies

Behind a reverse proxy the socket peer is the proxy, and the client's address and scheme travel in X-Forwarded-For / X-Forwarded-Proto. Which proxies to believe is a property of the process, so it is set once on the host and applies to every listener and every consumer on it:

services.AddRedbRouteHttpHosting(o => o.TrustedProxies.Add("10.0.0.5").Add("10.1.0.0/16"));
// or, constructing the manager by hand:
var hosting = new HttpHostingOptions();
hosting.TrustedProxies.Add("10.0.0.5");
var manager = new SharedHttpServerManager(hosting);

Rules, in the order they apply:

Situation Outcome
No proxy listed Headers ignored, socket peer is the client. The default.
Peer not in the list Headers ignored: nothing in them was written by anyone trusted.
Peer trusted, X-Forwarded-For present Walked from the right past every listed proxy; the first address that is not one is the client. A chain of any length resolves.
An entry does not parse The walk stops and the socket peer is kept. Skipping would reach the client-controlled left part.
Every entry is a trusted proxy Socket peer kept (a proxy calling through itself, a health check).
X-Forwarded-Proto present, peer trusted Request.Scheme rewritten, read in step with the address; ForwardScheme = false turns this off.

The originals are kept in HttpContext.Items under SharedHttpServerManager.OriginalRemoteAddressItem and OriginalSchemeItem. Keep the list to the proxies you operate: a network an attacker can send from lets them choose their own client address. X-Forwarded-Host and the RFC 7239 Forwarded header are not handled.

The walk is ForwardedHeaderResolver, a pure function with no HttpContext in it, so it can be unit-tested on strings and reused by a host that is not Kestrel.

Part of the redb.Route family.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.
  • net8.0

    • No dependencies.
  • net9.0

    • No dependencies.

NuGet packages (6)

Showing the top 5 NuGet packages that depend on redb.Route.Http.Hosting:

Package Downloads
redb.Route.Http

HTTP transport for redb.Route ESB framework. Provides HttpClient producer and Kestrel-based consumer (webhook receiver) with CORS, auth, and streaming support.

redb.Route.Grpc

gRPC transport for redb.Route ESB framework. Serves gRPC methods as path routes on the shared Kestrel host (one port, many methods) and calls them with a GrpcChannel-based producer.

redb.Route.WebSocket

WebSocket transport for redb.Route ESB framework. Provides ClientWebSocket producer and Kestrel-based WebSocket server consumer with text/binary frames, ping/pong, reconnect, and subprotocol support.

redb.Route.SignalR

SignalR transport for redb.Route ESB framework. Provides Kestrel-based SignalR Hub consumer (server) and HubConnection-based producer (client) with dynamic method dispatch, group management, and JSON/MessagePack support.

redb.Route.As2

AS2 (RFC 4130) B2B/EDI transport for the redb.Route ESB framework: signed/encrypted S/MIME over HTTP with MDN receipts.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
4.1.0 65 9/21/2026
4.0.1 179 9/18/2026
4.0.0 332 9/11/2026
3.7.2 298 8/26/2026
3.7.1 313 8/26/2026
3.6.0 226 8/13/2026
3.5.1 233 8/9/2026