Table of Contents

Class HttpGovernanceActorContextOptions

Namespace
AsiBackbone.AspNetCore.Actors
Assembly
AsiBackbone.AspNetCore.dll

Configures how ASP.NET Core claims are mapped into framework-neutral actor contexts.

public sealed class HttpGovernanceActorContextOptions
Inheritance
HttpGovernanceActorContextOptions
Inherited Members

Properties

ActorIdClaimTypes

Gets or sets the claim types used to resolve a stable actor identifier.

public IList<string> ActorIdClaimTypes { get; set; }

Property Value

IList<string>

ActorTypeClaimType

Gets or sets the claim type used to resolve an actor type.

public string ActorTypeClaimType { get; set; }

Property Value

string

Remarks

This must identify a trusted identity-provider-issued or host-generated claim. It must not be populated from user-controlled request, scope, profile, or application data.

AllowedActorTypesFromClaims

Gets or sets the actor types that may be accepted from ActorTypeClaimType.

public IList<GovernanceActorType> AllowedActorTypesFromClaims { get; set; }

Property Value

IList<GovernanceActorType>

Remarks

The conservative default accepts only Human. A host must explicitly add System, Service, or Agent after establishing that the configured claim is protected by a trusted identity boundary. An empty list disables actor-type claim mapping.

DefaultActorIdClaimTypes

Gets the default stable identifier claim types checked for authenticated actors.

public static IReadOnlyList<string> DefaultActorIdClaimTypes { get; }

Property Value

IReadOnlyList<string>

Remarks

Email claims are deliberately absent. Actor identifiers are persisted verbatim and indexed in durable audit rows, and an email address is both personal data and a mutable identifier, so a host that wants one must add it explicitly and accept the retention consequences.

DefaultAllowedActorTypesFromClaims

Gets the default actor types that may be accepted from an HTTP claim.

public static IReadOnlyList<GovernanceActorType> DefaultAllowedActorTypesFromClaims { get; }

Property Value

IReadOnlyList<GovernanceActorType>

Remarks

Privileged software actor types require explicit host opt-in because claim trust is established by the host identity boundary, not by AsiBackbone.

DefaultAuthenticatedActorType

Gets or sets the actor type used when an authenticated principal does not provide a valid or allowed actor type claim.

public GovernanceActorType DefaultAuthenticatedActorType { get; set; }

Property Value

GovernanceActorType

DefaultDisplayNameClaimTypes

Gets the default display-name claim types checked for authenticated actors.

public static IReadOnlyList<string> DefaultDisplayNameClaimTypes { get; }

Property Value

IReadOnlyList<string>

Remarks

Email claims are deliberately absent, for the retention reason described on DefaultActorIdClaimTypes.

DisplayNameClaimTypes

Gets or sets the claim types used to resolve an optional actor display name.

public IList<string> DisplayNameClaimTypes { get; set; }

Property Value

IList<string>

UnauthenticatedDisplayName

Gets or sets the display name used for unauthenticated actors.

public string? UnauthenticatedDisplayName { get; set; }

Property Value

string

Methods

Validate()

Validates the options.

public void Validate()