Lyo.Api.Authentication
2.0.0
dotnet add package Lyo.Api.Authentication --version 2.0.0
NuGet\Install-Package Lyo.Api.Authentication -Version 2.0.0
<PackageReference Include="Lyo.Api.Authentication" Version="2.0.0" />
<PackageVersion Include="Lyo.Api.Authentication" Version="2.0.0" />
<PackageReference Include="Lyo.Api.Authentication" />
paket add Lyo.Api.Authentication --version 2.0.0
#r "nuget: Lyo.Api.Authentication, 2.0.0"
#:package Lyo.Api.Authentication@2.0.0
#addin nuget:?package=Lyo.Api.Authentication&version=2.0.0
#tool nuget:?package=Lyo.Api.Authentication&version=2.0.0
Lyo.Api.Authentication
Administrative HTTP endpoints for Lyo Authentication. Maps QueryProject surfaces over [user] tables. Hosts supply EndpointAuth (default RequireAuthorization()). Self-service mint/list/revoke stays on /tokens and /auth/me.
Do not map these routes Anonymous() on a public host: they QueryProject every user and token, including SecretHash denial on Token projections.
Examples
Set up the host
services.AddPostgresAuthenticationStoresFromConfiguration(configuration);
services.AddLyoApiAuthentication();
services.AddSingleton<AuthenticationLyoMapper>();
services.AddScoped<ILyoMapper>(sp => new CompositeLyoMapper(
sp.GetRequiredService<AuthenticationLyoMapper>(),
fallbackMapper));
var app = builder.Build();
app.BuildAuthenticationApi(); // RequireAuthorization on every surface
// or AuthenticationApiOptions.WithAuth(EndpointAuth.RequireAuthorization("AuthAdmin"))
Authorization matrix
| Surface | Options property | Endpoints |
|---|---|---|
| User | UserAuth |
Query / Get / Patch / Export. No Create (OIDC provisions). |
| Token | TokenAuth |
Query / Get / Patch / Delete / DeleteBulk. SecretHash is not selectable. Delete hard-removes the row. |
| Claim | ClaimAuth |
Default CRUD. Reserved JWT names (iss, sub, scope, lyo:*, …) are rejected. |
| Scope | ScopeAuth |
Default CRUD. Unique (UserId, Name). Source of truth for JWT scope; provider/link scopes are not copied onto tokens. |
| Linked identity | LinkedIdentityAuth |
Query / Get (read-only) |
| Event | EventAuth |
Query / Get over [user].[event] |
Defaults are EndpointAuth.RequireAuthorization(). Prefer AuthenticationApiOptions.WithAuth(auth) when every surface shares one policy. Revoke is Patch RevokedTimestamp; hard-delete destroys the hash and emits AuthAuditEventKind.TokenDeleted.
Dependencies
Generated from ProjectReference / PackageReference (same model as docs/Lyo.ProjectGraph.html).
Lyo.Api(direct, lyo)Lyo.Api.Export(direct, lyo)Lyo.Authentication(direct, lyo)Lyo.Authentication.Models(direct, lyo)Lyo.Authentication.Postgres(direct, lyo)Lyo.Common.Core(direct, lyo)Lyo.Configuration(direct, lyo)Lyo.Api.Models(transitive, lyo)Lyo.Cache(transitive, lyo)Lyo.Common.Json(transitive, lyo)Lyo.Common.Metadata(transitive, lyo)Lyo.Compression(transitive, lyo)Lyo.DateAndTime(transitive, lyo)Lyo.Diagnostic(transitive, lyo)Lyo.Diagnostic.AspNetCore(transitive, lyo)Lyo.Diff(transitive, lyo)Lyo.Encryption(transitive, lyo)Lyo.EntityReference.Models(transitive, lyo)Lyo.EntityReference.Postgres(transitive, lyo)Lyo.Exceptions(transitive, lyo)Lyo.Formatter(transitive, lyo)Lyo.Hashing(transitive, lyo)Lyo.Health(transitive, lyo)Lyo.KeyStore(transitive, lyo)Lyo.Metrics(transitive, lyo)Lyo.PackageMetadata(transitive, lyo)Lyo.Parameters(transitive, lyo)Lyo.Postgres(transitive, lyo)Lyo.Query(transitive, lyo)Lyo.Query.Evaluation(transitive, lyo)Lyo.Query.Models(transitive, lyo)Lyo.Result(transitive, lyo)Lyo.Streams(transitive, lyo)Lyo.Validation(transitive, lyo)Lyo.Validation.Models(transitive, lyo)BouncyCastle.Cryptography2.6.2(transitive, third-party, netstandard2.0)DynamicExpresso.Core2.19.3(transitive, third-party)EasyCompressor2.1.0(transitive, third-party)Konscious.Security.Cryptography.Argon21.3.1(transitive, third-party)Microsoft.AspNetCore.OpenApi10.0.5(transitive, microsoft)Microsoft.Bcl.AsyncInterfaces10.0.5(transitive, microsoft, netstandard2.0)Microsoft.EntityFrameworkCore10.0.5(transitive, microsoft)Microsoft.EntityFrameworkCore.Analyzers10.0.5(transitive, microsoft)Microsoft.EntityFrameworkCore.Design10.0.5(transitive, microsoft)Microsoft.EntityFrameworkCore.Relational10.0.5(transitive, microsoft)Microsoft.Extensions.Caching.Memory10.0.5(transitive, microsoft)Microsoft.Extensions.Configuration.Binder10.0.5(transitive, microsoft)Microsoft.Extensions.DependencyInjection10.0.5(transitive, microsoft)Microsoft.Extensions.DependencyInjection.Abstractions10.0.5(transitive, microsoft, net10.0, netstandard2.0)Microsoft.Extensions.Hosting.Abstractions10.0.5(transitive, microsoft)Microsoft.Extensions.Logging.Abstractions10.0.5(transitive, microsoft)Microsoft.Extensions.Options10.0.5(transitive, microsoft)Microsoft.Extensions.Options.ConfigurationExtensions10.0.5(transitive, microsoft)Npgsql.EntityFrameworkCore.PostgreSQL10.0.3(transitive, third-party)SmartFormat.NET3.6.1(transitive, third-party)System.Buffers4.6.1(transitive, microsoft, netstandard2.0)System.ComponentModel.Annotations5.0.0(transitive, microsoft)System.IO.Hashing10.0.5(transitive, microsoft, net10.0)System.Memory4.6.3(transitive, microsoft, netstandard2.0)System.Text.Json10.0.5(transitive, microsoft, netstandard2.0)System.Threading.Tasks.Extensions4.6.3(transitive, microsoft, netstandard2.0)
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Lyo.Api (>= 2.0.0)
- Lyo.Api.Export (>= 2.0.0)
- Lyo.Authentication (>= 2.0.0)
- Lyo.Authentication.Models (>= 2.0.0)
- Lyo.Authentication.Postgres (>= 2.0.0)
- Lyo.Common.Core (>= 2.0.0)
- Lyo.Configuration (>= 2.0.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.0.0 | 45 | 9/9/2026 |