Table of Contents

Class AuthenticationTestController

Namespace
ProjectTemplate.Web.Tests.TestControllers
Assembly
ProjectTemplate.Web.Tests.dll

Provides test endpoints for verifying application authentication and authorization behavior.

[ApiController]
[Route("test/authentication")]
public sealed class AuthenticationTestController : ControllerBase
Inheritance
AuthenticationTestController
Inherited Members

Methods

Admin()

Returns a test response for users who satisfy the administrator role authorization policy.

[HttpGet("admin")]
[Authorize(Policy = "application.Role.Administrator")]
public IActionResult Admin()

Returns

IActionResult

An IActionResult containing an administrator authorization test result.

Anonymous()

Returns an anonymous response that does not require authentication.

[HttpGet("anonymous")]
[AllowAnonymous]
public IActionResult Anonymous()

Returns

IActionResult

An IActionResult containing an anonymous result.

AntiforgeryToken(IAntiforgery)

Issues a test-only antiforgery request token and stores the paired antiforgery cookie.

[HttpGet("antiforgery-token")]
[AllowAnonymous]
public IActionResult AntiforgeryToken(IAntiforgery antiforgery)

Parameters

antiforgery IAntiforgery

The ASP.NET Core antiforgery service.

Returns

IActionResult

The request token required by the cookie sign-in POST.

CookieSignIn(string)

Establishes a test-only cookie-authenticated principal through the application's configured cookie scheme.

[HttpPost("cookie-sign-in")]
[AllowAnonymous]
[ValidateAntiForgeryToken]
public Task<IActionResult> CookieSignIn(string userName = "cookie-test-user")

Parameters

userName string

The test user name to persist in the authentication cookie.

Returns

Task<IActionResult>

A task that represents the asynchronous sign-in operation.

Fallback()

Returns an unannotated response governed by the fallback authorization policy.

[HttpGet("fallback")]
public IActionResult Fallback()

Returns

IActionResult

An IActionResult containing a fallback-policy result.

Manage()

Returns a test response for users who satisfy the manage application permission authorization policy.

[HttpGet("manage")]
[Authorize(Policy = "application.Permission.ManageApplication")]
public IActionResult Manage()

Returns

IActionResult

An IActionResult containing a manage application permission authorization test result.

Protected()

Returns a protected response that requires an authenticated user.

[HttpGet("protected")]
[Authorize(Policy = "application.AuthenticatedUser")]
public IActionResult Protected()

Returns

IActionResult

An IActionResult containing the protected result and observed identity.

UnannotatedUnsafe()

Accepts an unsafe (PUT) request that carries no antiforgery attribute, so only the global AutoValidateAntiforgeryTokenAttribute filter protects it.

[HttpPut("unannotated-unsafe")]
[AllowAnonymous]
public IActionResult UnannotatedUnsafe()

Returns

IActionResult

An OK response when the request passes antiforgery validation.

Remarks

PUT rather than POST: static analysis (CodeQL cs/web/missing-token-validation) cannot see globally registered MVC filters and would flag an unannotated POST, while the global filter covers every unsafe verb.