Keycloak.AuthServices.Authorization
1.5.2
Prefix Reserved
See the version list below for details.
dotnet add package Keycloak.AuthServices.Authorization --version 1.5.2
NuGet\Install-Package Keycloak.AuthServices.Authorization -Version 1.5.2
<PackageReference Include="Keycloak.AuthServices.Authorization" Version="1.5.2" />
paket add Keycloak.AuthServices.Authorization --version 1.5.2
#r "nuget: Keycloak.AuthServices.Authorization, 1.5.2"
// Install Keycloak.AuthServices.Authorization as a Cake Addin #addin nuget:?package=Keycloak.AuthServices.Authorization&version=1.5.2 // Install Keycloak.AuthServices.Authorization as a Cake Tool #tool nuget:?package=Keycloak.AuthServices.Authorization&version=1.5.2
Keycloak.AuthServices
Easy Authentication and Authorization with Keycloak in .NET and ASP.NET Core.
Getting Started
// Program.cs
var builder = WebApplication.CreateBuilder(args);
var host = builder.Host;
var configuration = builder.Configuration;
var services = builder.Services;
services.AddKeycloakAuthentication(configuration);
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapGet("/", () => "Hello World!");
app.Run();
In this example, configuration is based on appsettings.json
.
//appsettings.json
{
"Keycloak": {
"realm": "Test",
"auth-server-url": "http://localhost:8080/",
"ssl-required": "none",
"resource": "test-client",
"verify-token-audience": false,
"credentials": {
"secret": ""
},
"confidential-port": 0
}
}
It's fetched based on well-known section "Keycloak". AddKeycloakAuthentication
uses KeycloakAuthenticationOptions.Section
under the hood.
You can always fetch the corresponding authentication options like this:
var authenticationOptions = configuration
.GetSection(KeycloakAuthenticationOptions.Section)
.Get<KeycloakAuthenticationOptions>();
services.AddKeycloakAuthentication(authenticationOptions);
AddKeycloakAuthentication
method has several overloads. It allows to override some conventions, for example:
public static AuthenticationBuilder AddKeycloakAuthentication(
this IServiceCollection services,
IConfiguration configuration,
string? keycloakClientSectionName,
Action<JwtBearerOptions>? configureOptions = default)
{
/* implementation */
}
Example. Authentication + Authorization
Here is how to add JWT-based authentication and custom authorization policy.
var builder = WebApplication.CreateBuilder(args);
var host = builder.Host;
var configuration = builder.Configuration;
var services = builder.Services;
host.ConfigureKeycloakConfigurationSource();
// conventional registration from keycloak.json
services.AddKeycloakAuthentication(configuration);
services.AddAuthorization(options =>
{
options.AddPolicy("RequireWorkspaces", builder =>
{
builder.RequireProtectedResource("workspaces", "workspaces:read") // HTTP request to Keycloak to check protected resource
.RequireRealmRoles("User") // Realm role is fetched from token
.RequireResourceRoles("Admin"); // Resource/Client role is fetched from token
});
})
.AddKeycloakAuthorization(configuration);
var app = builder.Build();
app.UseAuthentication();
app.UseAuthorization();
app.MapGet("/workspaces", () => "[]")
.RequireAuthorization("RequireWorkspaces");
app.Run();
Keycloak.AuthServices.Authentication
Add OpenID Connect + JWT Bearer token authentication.
For example, see Getting Started
Adapter File. Optional
Using appsettings.json
is a recommended and it is an idiomatic approach for .NET, but if you want a standalone "adapter" (installation) file - keycloak.json
. You can use ConfigureKeycloakConfigurationSource
. It adds dedicated configuration source.
// add configuration from keycloak file
host.ConfigureKeycloakConfigurationSource("keycloak.json");
// add authentication services, OICD JwtBearerDefaults.AuthenticationScheme
services.AddKeycloakAuthentication(configuration, o =>
{
o.RequireHttpsMetadata = false;
});
Client roles are automatically transformed into user role claims KeycloakRolesClaimsTransformation.
See Keycloak.AuthServices.Authentication - README.md
Keycloak installation file:
// confidential client
{
"realm": "<realm>",
"auth-server-url": "http://localhost:8088/auth/",
"ssl-required": "external", // external | none
"resource": "<clientId>",
"verify-token-audience": true,
"credentials": {
"secret": ""
}
}
// public client
{
"realm": "<realm>",
"auth-server-url": "http://localhost:8088/auth/",
"ssl-required": "external",
"resource": "<clientId>",
"public-client": true,
"confidential-port": 0
}
Keycloak.AuthServices.Authorization
services.AddAuthorization(authOptions =>
{
authOptions.AddPolicy("<policyName>", policyBuilder =>
{
// configure policies here
});
}).AddKeycloakAuthorization(configuration);
See Keycloak.AuthServices.Authorization - README.md
Keycloak.AuthServices.Sdk
Keycloak API clients.
Service | Description |
---|---|
IKeycloakClient | Unified HTTP client - IKeycloakRealmClient, IKeycloakProtectedResourceClient |
IKeycloakRealmClient | Keycloak realm API |
IKeycloakProtectedResourceClient | Protected resource API |
IKeycloakUserClient | Keycloak user API |
IKeycloakProtectionClient | Authorization server API, used by AddKeycloakAuthorization |
// requires confidential client
services.AddKeycloakAdminHttpClient(keycloakOptions);
// based on token forwarding HttpClient middleware and IHttpContextAccessor
services.AddKeycloakProtectionHttpClient(keycloakOptions);
See Keycloak.AuthServices.Sdk - README.md
Build and Development
dotnet cake --target build
dotnet pack -o ./Artefacts
Blog Posts
For more information and real world examples, please see my blog posts related to Keycloak and .NET https://nikiforovall.github.io/tags.html#keycloak-ref
Reference
- https://github.com/thinktecture-labs/webinar-keycloak
- https://github.com/thinktecture-labs/webinar-keycloak-authorization
- https://github.com/elmankross/Jboss.AspNetCore.Authentication.Keycloak/
- https://github.com/mikemir/AspNetCore.KeycloakAuthentication/
- https://github.com/lvermeulen/Keycloak.Net
- https://github.com/keycloak/keycloak-documentation/blob/main/authorization_services/topics/service-authorization-uma-authz-process.adoc
- https://www.keycloak.org/docs/latest/authorization_services/index.html
Product | Versions Compatible and additional computed target framework versions. |
---|---|
.NET | net6.0 is compatible. net6.0-android was computed. net6.0-ios was computed. net6.0-maccatalyst was computed. net6.0-macos was computed. net6.0-tvos was computed. net6.0-windows was computed. net7.0 was computed. net7.0-android was computed. net7.0-ios was computed. net7.0-maccatalyst was computed. net7.0-macos was computed. net7.0-tvos was computed. net7.0-windows was computed. net8.0 was computed. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. |
-
net6.0
NuGet packages (7)
Showing the top 5 NuGet packages that depend on Keycloak.AuthServices.Authorization:
Package | Downloads |
---|---|
Gathrr.Framework.Infrastructure
Package Description |
|
Wcz.Layout
Package Description |
|
Inspire.Framework.Infrastructure
Package Description |
|
Feijuca.Keycloak.MultiTenancy
This project has a quickly purpose: Extend the behavior of keycloak-authorization-services-dotnet but adding a multi-tenancy support. |
|
Feijuca.Auth
Feijuca.Auth simplifies Keycloak integration for user management and multi-tenancy. It features TokenManager for centralized API calls to manage users and auth services for handling multiple tenants using Keycloak realms. Check the documentation for more details! |
GitHub repositories
This package is not used by any popular GitHub repositories.
Version | Downloads | Last updated |
---|---|---|
2.5.3 | 52,732 | 8/19/2024 |
2.5.2 | 62,892 | 6/15/2024 |
2.5.1 | 3,065 | 6/11/2024 |
2.5.0 | 9,574 | 6/2/2024 |
2.4.1 | 11,991 | 5/16/2024 |
2.4.0 | 1,149 | 5/12/2024 |
2.3.0 | 342 | 5/10/2024 |
2.3.0-pre-1 | 79 | 5/9/2024 |
2.2.1 | 765 | 5/9/2024 |
2.2.0 | 168 | 5/8/2024 |
2.1.0 | 2,908 | 5/7/2024 |
2.0.0 | 2,179 | 5/5/2024 |
2.0.0-pre-4 | 121 | 5/4/2024 |
2.0.0-pre-3 | 195 | 4/26/2024 |
2.0.0-pre-2 | 105 | 4/25/2024 |
2.0.0-pre-1 | 239 | 4/24/2024 |
1.6.0 | 236,951 | 10/25/2023 |
1.5.2 | 160,092 | 5/27/2023 |
1.5.1 | 217,846 | 1/17/2023 |
1.5.0 | 630 | 1/17/2023 |
1.4.1 | 2,076 | 1/12/2023 |
1.4.0 | 5,464 | 1/4/2023 |
1.3.0 | 1,458 | 12/28/2022 |
1.2.1 | 34,885 | 9/22/2022 |
1.2.0 | 2,852 | 8/24/2022 |
1.1.0 | 13,107 | 1/30/2022 |
1.0.5 | 142 | 1/29/2022 |
1.0.4 | 141 | 1/28/2022 |
1.0.3 | 134 | 1/28/2022 |
1.0.2 | 139 | 1/23/2022 |
1.0.1 | 608 | 1/19/2022 |
1.0.0 | 4,387 | 1/19/2022 |