| | | 1 | | namespace ProjectTemplate.Web.Authentication.Providers.OpenIdConnect; |
| | | 2 | | |
| | | 3 | | /// <summary> |
| | | 4 | | /// Represents OpenID Connect authentication provider configuration. |
| | | 5 | | /// </summary> |
| | | 6 | | public sealed class OpenIdConnectAuthenticationOptions |
| | | 7 | | { |
| | | 8 | | /// <summary> |
| | | 9 | | /// Gets or sets a value indicating whether OpenID Connect authentication is enabled. |
| | | 10 | | /// </summary> |
| | | 11 | | public bool Enabled { get; set; } |
| | | 12 | | |
| | | 13 | | /// <summary> |
| | | 14 | | /// Gets or sets the OpenID Connect authentication scheme. |
| | | 15 | | /// </summary> |
| | | 16 | | public string Scheme { get; set; } = "OpenIdConnect"; |
| | | 17 | | |
| | | 18 | | /// <summary> |
| | | 19 | | /// Gets or sets the display name shown for the OpenID Connect provider. |
| | | 20 | | /// </summary> |
| | | 21 | | public string DisplayName { get; set; } = "OpenID Connect"; |
| | | 22 | | |
| | | 23 | | /// <summary> |
| | | 24 | | /// Gets or sets the OpenID Connect authority URL. |
| | | 25 | | /// </summary> |
| | | 26 | | public string Authority { get; set; } = string.Empty; |
| | | 27 | | |
| | | 28 | | /// <summary> |
| | | 29 | | /// Gets or sets the OpenID Connect client ID. |
| | | 30 | | /// </summary> |
| | | 31 | | public string ClientId { get; set; } = string.Empty; |
| | | 32 | | |
| | | 33 | | /// <summary> |
| | | 34 | | /// Gets or sets the OpenID Connect client secret. |
| | | 35 | | /// </summary> |
| | | 36 | | public string ClientSecret { get; set; } = string.Empty; |
| | | 37 | | |
| | | 38 | | /// <summary> |
| | | 39 | | /// Gets or sets the callback path used by the OpenID Connect handler. |
| | | 40 | | /// </summary> |
| | | 41 | | public string CallbackPath { get; set; } = "/signin-oidc"; |
| | | 42 | | |
| | | 43 | | /// <summary> |
| | | 44 | | /// Gets or sets the OpenID Connect response type. |
| | | 45 | | /// </summary> |
| | | 46 | | public string ResponseType { get; set; } = "code"; |
| | | 47 | | |
| | | 48 | | /// <summary> |
| | | 49 | | /// Gets or sets a value indicating whether provider tokens are stored in the authentication cookie after sign-in. |
| | | 50 | | /// </summary> |
| | | 51 | | /// <remarks> |
| | | 52 | | /// Defaults to <see langword="false"/>. Saved tokens travel with the authentication cookie on every request, which |
| | | 53 | | /// grows the cookie and keeps access, identity, and refresh tokens on the client. Enable this only when the |
| | | 54 | | /// application calls downstream APIs with the provider's tokens and has a documented protection and lifetime |
| | | 55 | | /// strategy; prefer server-side token storage for anything longer-lived. |
| | | 56 | | /// </remarks> |
| | | 57 | | public bool SaveTokens { get; set; } |
| | | 58 | | |
| | | 59 | | /// <summary> |
| | | 60 | | /// Gets or sets the requested OpenID Connect scopes. |
| | | 61 | | /// </summary> |
| | | 62 | | public string[] Scopes { get; set; } = |
| | 364 | 63 | | [ |
| | 364 | 64 | | "openid", |
| | 364 | 65 | | "profile", |
| | 364 | 66 | | "email" |
| | 364 | 67 | | ]; |
| | | 68 | | } |