< Summary

Information
Class: AsiBackbone.AspNetCore.Actors.HttpGovernanceActorContextOptions
Assembly: AsiBackbone.AspNetCore
File(s): /home/runner/work/AsiBackbone/AsiBackbone/src/AsiBackbone.AspNetCore/Actors/HttpGovernanceActorContextOptions.cs
Line coverage
96%
Covered lines: 27
Uncovered lines: 1
Coverable lines: 28
Total lines: 123
Line coverage: 96.4%
Branch coverage
87%
Covered branches: 14
Total branches: 16
Branch coverage: 87.5%
Method coverage

Feature is only available for sponsors

Upgrade to PRO version

Metrics

MethodBranch coverage Crap Score Cyclomatic complexity Line coverage
.cctor()100%11100%
Validate()87.5%161692.31%

File(s)

/home/runner/work/AsiBackbone/AsiBackbone/src/AsiBackbone.AspNetCore/Actors/HttpGovernanceActorContextOptions.cs

#LineLine coverage
 1using System.Security.Claims;
 2using AsiBackbone.Core.Actors;
 3
 4namespace AsiBackbone.AspNetCore.Actors;
 5
 6/// <summary>
 7/// Configures how ASP.NET Core claims are mapped into framework-neutral actor contexts.
 8/// </summary>
 9public sealed class HttpGovernanceActorContextOptions
 10{
 11    /// <summary>
 12    /// Gets the default stable identifier claim types checked for authenticated actors.
 13    /// </summary>
 14    /// <remarks>
 15    /// Email claims are deliberately absent. Actor identifiers are persisted verbatim and indexed in durable audit rows
 16    /// and an email address is both personal data and a mutable identifier, so a host that wants one must add it
 17    /// explicitly and accept the retention consequences.
 18    /// </remarks>
 19    public static IReadOnlyList<string> DefaultActorIdClaimTypes { get; } =
 220    [
 221        ClaimTypes.NameIdentifier,
 222        "sub",
 223        "oid",
 224        "client_id",
 225        "azp",
 226    ];
 27
 28    /// <summary>
 29    /// Gets the default display-name claim types checked for authenticated actors.
 30    /// </summary>
 31    /// <remarks>
 32    /// Email claims are deliberately absent, for the retention reason described on <see cref="DefaultActorIdClaimTypes"
 33    /// </remarks>
 34    public static IReadOnlyList<string> DefaultDisplayNameClaimTypes { get; } =
 235    [
 236        ClaimTypes.Name,
 237        "name",
 238        "preferred_username",
 239    ];
 40
 41    /// <summary>
 42    /// Gets the default actor types that may be accepted from an HTTP claim.
 43    /// </summary>
 44    /// <remarks>
 45    /// Privileged software actor types require explicit host opt-in because claim trust is established by the host iden
 46    /// </remarks>
 47    public static IReadOnlyList<GovernanceActorType> DefaultAllowedActorTypesFromClaims { get; } =
 248    [
 249        GovernanceActorType.Human,
 250    ];
 51
 52    /// <summary>
 53    /// Gets or sets the claim types used to resolve a stable actor identifier.
 54    /// </summary>
 55    public IList<string> ActorIdClaimTypes { get; set; } = [.. DefaultActorIdClaimTypes];
 56
 57    /// <summary>
 58    /// Gets or sets the claim types used to resolve an optional actor display name.
 59    /// </summary>
 60    public IList<string> DisplayNameClaimTypes { get; set; } = [.. DefaultDisplayNameClaimTypes];
 61
 62    /// <summary>
 63    /// Gets or sets the claim type used to resolve an actor type.
 64    /// </summary>
 65    /// <remarks>
 66    /// This must identify a trusted identity-provider-issued or host-generated claim. It must not be populated from use
 67    /// </remarks>
 68    public string ActorTypeClaimType { get; set; } = "actor_type";
 69
 70    /// <summary>
 71    /// Gets or sets the actor types that may be accepted from <see cref="ActorTypeClaimType" />.
 72    /// </summary>
 73    /// <remarks>
 74    /// The conservative default accepts only <see cref="GovernanceActorType.Human" />. A host must explicitly add <see 
 75    /// </remarks>
 76    public IList<GovernanceActorType> AllowedActorTypesFromClaims { get; set; } = [.. DefaultAllowedActorTypesFromClaims
 77
 78    /// <summary>
 79    /// Gets or sets the actor type used when an authenticated principal does not provide a valid or allowed actor type 
 80    /// </summary>
 81    public GovernanceActorType DefaultAuthenticatedActorType { get; set; } = GovernanceActorType.Human;
 82
 83    /// <summary>
 84    /// Gets or sets the display name used for unauthenticated actors.
 85    /// </summary>
 86    public string? UnauthenticatedDisplayName { get; set; }
 87
 88    /// <summary>
 89    /// Validates the options.
 90    /// </summary>
 91    public void Validate()
 92    {
 7793        if (ActorIdClaimTypes is null || ActorIdClaimTypes.Count == 0 || ActorIdClaimTypes.All(string.IsNullOrWhiteSpace
 94        {
 195            throw new InvalidOperationException("At least one actor identifier claim type must be configured.");
 96        }
 97
 7698        if (DisplayNameClaimTypes is null)
 99        {
 0100            throw new InvalidOperationException("DisplayNameClaimTypes must be configured.");
 101        }
 102
 76103        if (string.IsNullOrWhiteSpace(ActorTypeClaimType))
 104        {
 3105            throw new InvalidOperationException("ActorTypeClaimType must be configured.");
 106        }
 107
 73108        if (AllowedActorTypesFromClaims is null)
 109        {
 1110            throw new InvalidOperationException("AllowedActorTypesFromClaims must be configured.");
 111        }
 112
 72113        if (AllowedActorTypesFromClaims.Any(static actorType => !Enum.IsDefined(actorType)))
 114        {
 1115            throw new InvalidOperationException("AllowedActorTypesFromClaims must contain only defined actor types.");
 116        }
 117
 71118        if (!Enum.IsDefined(DefaultAuthenticatedActorType))
 119        {
 1120            throw new InvalidOperationException("DefaultAuthenticatedActorType must be a defined actor type.");
 121        }
 70122    }
 123}

Methods/Properties

.cctor()
Validate()