Moved/Migrated from KornSW.TokenValidation
Server-Side usage within ASP.NET Core WebAPI Projects:
Configure the Framework during your startup
//(from Nuget Pkg 'SmartStandards.AuthTokenHandling')AccessTokenValidator.ConfigureTokenIntrospection(newLocalJwtIntrospector("myTokeSignKey12345"),IdentityStateManager.InitializeCurrentContext,//[opt] populate MAC-scopes ambient introspectionResultCachingMinutes:2,//[opt] caching if introsp. is expensiveauditingHook:this.CreateAuditingEntry//[opt] auditing for introsp. outcome);Just place the "EvaluateBearerToken"-Attribute over the methods for which the access should be restricted and classify it with an API scope name. In this case were requiring accessors to have the "NiceActionExecutorRole".
classMyMvcController{
...[EvaluateBearerToken("NiceActionExecutorRole")]//<<< use this attribute[HttpPost("DoANiceAction"),Produces("application/json")]publicNiceResponseDtoDoANiceAction([FromBody]NiceRequestDtoargs){
...}}Contains the "API"-Clearance for "NiceActionExecutorRole" within the "scopes"-claim)
{
"iss": "the issuer",
"sub": "832",
"iat": 1684927942,
"exp": 1842607942,
"scope": "API:NiceActionExecutorRole Tenant:1243 DataProtectionLevel:3"
}