string Name { get; }
Source
Gets the stable event name.
Describes a passive AppSurface auth audit event.
This value does not write logs, traces, metrics, or persistent audit records. Host applications own audit transport, retention, redaction, and access control. Metadata should remain non-sensitive and diagnostic.
string Name { get; }
Source
Gets the stable event name.
DateTimeOffset Timestamp { get; }
Source
Gets the timestamp supplied by the host.
AppSurfaceAuthOutcome Outcome { get; }
Source
Gets the high-level auth outcome associated with the event.
AppSurfaceAuthReason Reason { get; }
Source
Gets the concrete auth reason associated with the event.
string? UserId { get; }
Source
Gets the optional user identifier associated with the event.
string? SessionId { get; }
Source
Gets the optional session identifier associated with the event.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
Represents the surface-neutral identity information AppSurface modules can share about a user.
AppSurfaceUser
is not a claims principal, identity-provider user, or authorization policy result. Host adapters should map their security system into this passive value only after authenticating the subject. Metadata is copied with ordinal keys and should be treated as context, not as authority for authorization decisions.
string Id { get; }
Source
Gets the stable host-owned user identifier.
string? DisplayName { get; }
Source
Gets the optional display name for UI or diagnostics.
string? Email { get; }
Source
Gets the optional email address for UI or diagnostics.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
Represents surface-neutral session information associated with an AppSurface auth context.
Session timestamps use DateTimeOffset
so host adapters can preserve their original offset. AppSurface does not convert, refresh, revoke, store, or validate the backing host session.
string Id { get; }
Source
Gets the stable host-owned session identifier.
DateTimeOffset? StartedAt { get; }
Source
Gets the optional timestamp when the host session began.
DateTimeOffset? ExpiresAt { get; }
Source
Gets the optional timestamp when the host session expires.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
Describes a possible host-owned login prompt without executing sign-in or redirects.
The prompt is passive. It never writes cookies, challenges a caller, redirects a response, or invokes an identity provider. Host UI or host adapters decide whether and how to act on it.
string? TargetPath { get; }
Source
Gets the optional app-relative target for host-owned login UI.
string? DisplayText { get; }
Source
Gets optional display text for host-owned login UI.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
Describes a possible host-owned logout prompt without executing sign-out or redirects.
The prompt is passive. It never clears cookies, signs out a caller, redirects a response, or invokes an identity provider. Host UI or host adapters decide whether and how to act on it.
string? TargetPath { get; }
Source
Gets the optional app-relative target for host-owned logout UI.
string? DisplayText { get; }
Source
Gets optional display text for host-owned logout UI.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
Captures the passive user and session context available to AppSurface auth-aware modules.
A context with no User
is a valid anonymous context. The context does not evaluate policies, read the current request, or wrap ASP.NET Core ClaimsPrincipal
; host-specific adapters own those mappings.
AppSurfaceAuthContext Anonymous { get; }
Source
Gets an anonymous auth context with no user, no session, and no metadata.
AppSurfaceUser? User { get; }
Source
Gets the optional authenticated user description.
AppSurfaceSession? Session { get; }
Source
Gets the optional session description.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve host-specific context.
bool IsAuthenticated { get; }
Source
Gets a value indicating whether the context contains a user description.
Defines reserved metadata keys used by AppSurface auth contracts.
Metadata is context for diagnostics, display, and adapter hand-off. It is not an authorization source of truth unless a host-owned adapter validates the value against the host security system. The appsurface.
prefix is reserved for AppSurface-owned keys so future typed properties can migrate existing metadata without key collisions.
Defines stable diagnostic codes for the delegated-agent authorization lifecycle.
Hosts may add a stable subcode to the canonical family for the typed outcome, such as agent-approval.consumption-denied.grant-missing
. Do not use display messages as machine-readable branching values, and do not renumber public outcome enums after release.
Identifies a stable host-local agent or harness identity without exposing credentials.
The value belongs to the host's agent namespace. It is not an application-user id, a user permission, a bearer token, or evidence that the agent may act. ToString
redacts the raw value by default.
string Value { get; }
Source
Gets the stable host-local agent or harness identity.
Identifies the human or host authority that approved an exact action without prescribing an identity provider.
A host can derive this reference from ExternalSubject
, an app-owned identity, or another validated subject namespace. The reference is not an agent grant or a reusable approval credential. ToString
redacts the raw value by default.
string Value { get; }
Source
Gets the stable host-local approver identity.
Describes a host-normalized workflow transition that an approval receipt binds.
The binding profile and digest are opaque host values. Hosts must use the same profile, normalisation rules, and safe digest representation when issuing and consuming a receipt. This type does not prescribe canonicalisation, cryptography, persistence, or a workflow runtime. ToString
intentionally redacts binding values.
bool Matches(AgentActionBinding? other)
Determines whether another binding has the same ordinal action, workflow, state, transition, profile, and digest values.
other
true
when every approval-relevant binding field matches.
string ActionId { get; }
Source
Gets the stable action identifier.
string TaskId { get; }
Source
Gets the host task or harness run identifier.
string WorkflowInstanceId { get; }
Source
Gets the host workflow instance identifier.
string ExpectedState { get; }
Source
Gets the expected current workflow state.
string ExpectedStateVersion { get; }
Source
Gets the expected state version or concurrency stamp.
string Transition { get; }
Source
Gets the requested transition or decision.
string BindingProfile { get; }
Source
Gets the host-defined canonicalisation profile and version in exactly two non-empty, whitespace-free profile/version
segments.
string SafeIntentDigest { get; }
Source
Gets the host-derived safe intent digest.
Declares safe, host-controlled metadata for an action an agent can propose.
This metadata aids host policy and confirmation presentation. It does not classify untrusted agent input, grant authority, or replace a host's policy evaluation.
string ActionId { get; }
Source
Gets the stable action identifier.
string DisplayName { get; }
Source
Gets the host-controlled display name.
AgentActionRisk Risk { get; }
Source
Gets the host-declared risk classification.
AgentConfirmationPosture ConfirmationPosture { get; }
Source
Gets the declared confirmation posture.
AgentActionRedaction Redaction { get; }
Source
Gets display redaction guidance.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
Describes one action an agent proposes to a host.
The request is immutable and contains only host-safe display fields. It does not carry user credentials, bearer tokens, an agent grant, an approval receipt, or permission to execute the action.
AgentActionMetadata Action { get; }
Source
Gets host-controlled action metadata.
AgentActionBinding Binding { get; }
Source
Gets the bound workflow transition.
AgentIdentityReference Agent { get; }
Source
Gets the proposing agent or local harness reference.
string CorrelationId { get; }
Source
Gets the host-generated correlation identifier.
DateTimeOffset RequestedAt { get; }
Source
Gets the host-supplied request timestamp.
string SafeSummary { get; }
Source
Gets the display-safe action summary.
string? Rationale { get; }
Source
Gets the optional display-safe proposal rationale.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
Describes the exact confirmation a host presents to one approver.
This type is passive. Hosts choose how to render a confirmation card, re-evaluate current authority, and issue an opaque receipt after approval. A changed action must be submitted as a new AgentActionRequest
; hosts must not edit an approved request in place.
AgentActionRequest ActionRequest { get; }
Source
Gets the exact action request awaiting confirmation.
AgentApproverReference Approver { get; }
Source
Gets the expected approver reference.
DateTimeOffset ExpiresAt { get; }
Source
Gets the expiration timestamp.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
Describes the host's evaluation of an AgentActionRequest
.
The decision does not evaluate policy, issue a receipt, or execute an action. The diagnostic code must be the canonical family for Kind
or a stable subcode in that family; consumers branch on Kind
rather than on a display message or subcode.
AgentAuthorizationDecision Allowed(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates an allowed decision with the standard AppSurface diagnostic code.
correlationId
message
metadata
An allowed decision.
AgentAuthorizationDecision Denied(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a denied decision with the standard AppSurface diagnostic code.
correlationId
message
metadata
A denied decision.
AgentAuthorizationDecision ConfirmationRequired(AgentConfirmationRequest confirmationRequest, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a confirmation-required decision with the standard AppSurface diagnostic code.
confirmationRequest
message
metadata
A confirmation-required decision.
AgentAuthorizationDecisionKind Kind { get; }
Source
Gets the host evaluation outcome.
string Code { get; }
Source
Gets the stable machine-readable diagnostic code.
string CorrelationId { get; }
Source
Gets the host-generated correlation identifier.
string? Message { get; }
Source
Gets the optional display-safe diagnostic message.
AgentConfirmationRequest? ConfirmationRequest { get; }
Source
Gets the confirmation request when Kind
is AgentAuthorizationDecisionKind.ConfirmationRequired
.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
bool IsAllowed { get; }
Source
Gets a value indicating whether the host allowed the action without confirmation.
bool IsDenied { get; }
Source
Gets a value indicating whether the host denied the action.
bool RequiresConfirmation { get; }
Source
Gets a value indicating whether the host requires a human confirmation.
Describes an opaque host-issued approval proof bound to one action, approver, and expiration.
The receipt is not a bearer-token format, signature, database record, or transport message. Hosts own issuance, storage, revocation, atomic one-use consumption, current-authority checks, and execution. Use FromConfirmedRequest
to issue a new receipt after durable human approval. Direct construction supports host-owned data reconstruction; it neither proves issuance nor authorizes execution. ToString
redacts the opaque receipt reference by default.
AgentApprovalReceipt FromConfirmedRequest(string receiptId, AgentConfirmationRequest confirmationRequest, DateTimeOffset issuedAt, DateTimeOffset expiresAt, IReadOnlyDictionary<string, string>? metadata = null)
Creates an approval receipt from the exact confirmation request that a host durably approved.
receiptId
confirmationRequest
issuedAt
expiresAt
metadata
A receipt bound to the confirmation request's action, agent, approver, and correlation identifier.
This factory validates structural consistency only. The caller must first perform and durably record the human approval, then persist and later atomically consume the resulting receipt.
string ReceiptId { get; }
Source
Gets the opaque host-issued receipt reference.
AgentActionBinding Binding { get; }
Source
Gets the exact action binding.
AgentIdentityReference Agent { get; }
Source
Gets the proposing agent reference.
AgentApproverReference Approver { get; }
Source
Gets the approving authority reference.
string CorrelationId { get; }
Source
Gets the host-generated correlation identifier.
DateTimeOffset IssuedAt { get; }
Source
Gets the host-supplied issuance timestamp.
DateTimeOffset ExpiresAt { get; }
Source
Gets the host-supplied expiration timestamp.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
Describes one terminal host outcome while consuming an approval receipt.
This result does not consume a receipt or retry an action. Hosts return it after their atomic claim and current authority, grant, state, expiry, revocation, and binding checks complete.
AgentApprovalConsumptionResult Consumed(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a consumed result with the standard AppSurface diagnostic code.
correlationId
message
metadata
A consumed result.
AgentApprovalConsumptionResult AlreadyConsumed(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates an already-consumed result with the standard AppSurface diagnostic code.
correlationId
message
metadata
An already-consumed result.
AgentApprovalConsumptionResult Expired(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates an expired result with the standard AppSurface diagnostic code.
correlationId
message
metadata
An expired result.
AgentApprovalConsumptionResult Revoked(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a revoked result with the standard AppSurface diagnostic code.
correlationId
message
metadata
A revoked result.
AgentApprovalConsumptionResult Stale(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a stale result with the standard AppSurface diagnostic code.
correlationId
message
metadata
A stale result.
AgentApprovalConsumptionResult BindingMismatch(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a binding-mismatch result with the standard AppSurface diagnostic code.
correlationId
message
metadata
A binding-mismatch result.
AgentApprovalConsumptionResult Denied(string correlationId, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a denied result with the standard AppSurface diagnostic code.
correlationId
message
metadata
A denied result.
AgentApprovalConsumptionOutcome Outcome { get; }
Source
Gets the terminal host outcome.
string Code { get; }
Source
Gets the stable machine-readable diagnostic code.
string CorrelationId { get; }
Source
Gets the host-generated correlation identifier.
string? Message { get; }
Source
Gets the optional display-safe diagnostic message.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
bool IsConsumed { get; }
Source
Gets a value indicating whether the host consumed the receipt.
Describes a passive audit event for a delegated-agent authorization lifecycle.
Hosts own audit event delivery and should use only display-safe values. This contract must not be treated as proof that an audit sink persisted an event successfully.
AgentAuthorizationAuditEvent FromReceipt(AgentAuthorizationAuditEventKind kind, DateTimeOffset timestamp, string code, AgentApprovalReceipt receipt, string? safeSummary = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates an audit event from a host-issued receipt so the binding, agent, approver, receipt reference, and correlation identifier stay consistent.
kind
timestamp
code
receipt
safeSummary
metadata
An audit event structurally consistent with receipt
.
This factory does not prove that the host persisted the event. It removes caller-side copying for receipt-backed events; hosts reconstructing persisted records may use the constructor after validating their stored references.
AgentAuthorizationAuditEventKind Kind { get; }
Source
Gets the lifecycle event kind.
DateTimeOffset Timestamp { get; }
Source
Gets the host-supplied event timestamp.
string Code { get; }
Source
Gets the stable machine-readable diagnostic code.
string CorrelationId { get; }
Source
Gets the host-generated correlation identifier.
AgentActionBinding Binding { get; }
Source
Gets the bound action representation.
AgentIdentityReference Agent { get; }
Source
Gets the proposing agent reference.
AgentApproverReference? Approver { get; }
Source
Gets the optional approver reference.
string? ReceiptId { get; }
Source
Gets the optional opaque receipt reference.
string? SafeSummary { get; }
Source
Gets the optional display-safe event summary.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied display-safe host metadata.
Represents the result of resolving an external subject to a durable app-owned user id.
This result family is intentionally separate from AppSurfaceAuthResult
. Authentication, policy, and navigation outcomes remain host-auth decisions; identity resolution describes the app-owned mapping step that can happen after the host has authenticated a subject. Messages and metadata should be display-safe and avoid raw subjects, emails, tokens, and provider payloads by default.
AppSurfaceUserIdentityResult Resolved(AppUserId appUserId, ExternalSubject subject, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a successful identity resolution result.
appUserId
subject
message
metadata
A resolved identity result.
AppSurfaceUserIdentityResult MissingSubject(string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result for a missing external subject.
message
metadata
A missing-subject identity result.
AppSurfaceUserIdentityResult MalformedSubject(string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result for a malformed external subject.
message
metadata
A malformed-subject identity result.
AppSurfaceUserIdentityResult DisabledAppUser(ExternalSubject? subject = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result for a disabled app user.
subject
message
metadata
A disabled-app-user identity result.
AppSurfaceUserIdentityResult StaleOrUnknownSession(ExternalSubject? subject = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result for a stale or unknown session.
subject
message
metadata
A stale-or-unknown-session identity result.
AppSurfaceUserIdentityResult DuplicateMapping(ExternalSubject? subject = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result for duplicate mappings.
subject
message
metadata
A duplicate-mapping identity result.
AppSurfaceUserIdentityResult ProvisioningDenied(ExternalSubject? subject = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a failure result when the app declines provisioning or attachment.
subject
message
metadata
A provisioning-denied identity result.
AppSurfaceUserIdentityStatus Status { get; }
Source
Gets the identity resolution status.
AppUserId? AppUserId { get; }
Source
Gets the resolved app-owned user id when Succeeded
is true
.
ExternalSubject? Subject { get; }
Source
Gets the external subject tuple involved in resolution when it was available and valid enough to report safely.
string? Message { get; }
Source
Gets an optional display-safe message supplied by the app resolver.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters or diagnostics preserve app-specific context.
bool Succeeded { get; }
Source
Gets a value indicating whether the external subject resolved to an app-owned user id.
Resolves authenticated external subjects to durable app-owned user ids.
ExternalSubject
tuple, honor cancellation before starting expensive work and while awaiting I/O, and handle concurrent first-time resolution without creating duplicate app users. Prefer enforcing uniqueness at the mapping store with a unique constraint over the external subject tuple (issuer, subject, and partition key), then make competing inserts converge on the same app user id through optimistic concurrency or a transaction retry. Stores that cannot enforce uniqueness should use an equivalent first-provisioning guard, such as a short distributed lock scoped to the external subject tuple.
Avoid a check-then-insert flow that reads a missing mapping and blindly creates a new app user. Concurrent sign-ins can otherwise provision duplicate app users before either caller observes the other mapping.
ValueTask<AppSurfaceUserIdentityResult> ResolveAsync(ExternalSubject subject, AppSurfaceUserIdentityResolutionContext context, CancellationToken cancellationToken = default)
Resolves an external subject to a durable app-owned user id.
subject
context
cancellationToken
An identity resolution result with either an app-owned user id or a typed failure state.
Represents a passive AppSurface auth decision.
AppSurfaceAuthResult
describes an auth decision; it does not challenge, forbid, redirect, evaluate policies, sign users in, or sign users out. Host-specific packages map these outcomes to platform behavior.
AppSurfaceAuthResult Allowed(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result that allows the requested operation.
context
message
metadata
An allowed auth result.
AppSurfaceAuthResult Challenge(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result indicating that the caller should authenticate before retrying.
context
message
metadata
A challenge auth result.
AppSurfaceAuthResult Unauthenticated(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result indicating that the caller is not authenticated.
context
message
metadata
A challenge auth result.
AppSurfaceAuthResult Forbid(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result indicating that the authenticated caller is forbidden.
context
message
metadata
A forbidden auth result.
AppSurfaceAuthResult Forbidden(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result indicating that the authenticated caller is forbidden.
context
message
metadata
A forbidden auth result.
AppSurfaceAuthResult MissingPolicy(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a setup-failure result for a missing host-owned policy.
context
message
metadata
A setup-failure auth result.
AppSurfaceAuthResult MissingServices(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a setup-failure result for missing host-owned auth services.
context
message
metadata
A setup-failure auth result.
AppSurfaceAuthResult MissingSubject(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a setup-failure result for an authenticated caller that could not be mapped to a stable subject.
context
message
metadata
A setup-failure auth result.
AppSurfaceAuthResult UnsafeReturnUrl(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result for an unsafe return or navigation target.
context
message
metadata
An unsafe-navigation auth result.
AppSurfaceAuthResult StaleOrUnknownSession(AppSurfaceAuthContext? context = null, string? message = null, IReadOnlyDictionary<string, string>? metadata = null)
Creates a result for stale, expired, missing, or unresolved session state.
context
message
metadata
A stale-or-unknown-session auth result.
AppSurfaceAuthOutcome Outcome { get; }
Source
Gets the high-level auth outcome.
AppSurfaceAuthReason Reason { get; }
Source
Gets the concrete reason associated with Outcome
.
AppSurfaceAuthContext? Context { get; }
Source
Gets the optional auth context that was evaluated.
string? Message { get; }
Source
Gets an optional message supplied by the host adapter for that adapter's own display contract.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help adapters preserve host-specific context.
bool IsAllowed { get; }
Source
Gets a value indicating whether the outcome allows the requested operation.
bool RequiresAuthentication { get; }
Source
Gets a value indicating whether the caller should authenticate before retrying.
bool IsConfigurationFailure { get; }
Source
Gets a value indicating whether the outcome represents host setup or configuration failure.
Options root for the surface-neutral AppSurface auth composition boundary.
This boundary-preview type is intentionally empty. It exists so future AppSurface auth contracts can add settings through a stable options root after those contracts are proven. It does not configure authentication schemes, authorization policies, user or session access, tenant behavior, identity providers, cookies, bearer tokens, challenges, forbids, middleware, endpoint filters, or UI. Host applications must keep those choices in their host-specific security configuration until a later AppSurface package explicitly owns them.
Carries display-safe context for resolving an external subject to an app-owned user id.
The context is an input to an app-owned resolver. It may carry safe correlation, issuer, tenant, or provisioning policy hints, but those hints are not authority unless the application validates them against its own security and persistence rules. Metadata is copied with ordinal keys.
AppSurfaceUserIdentityResolutionContext Empty { get; }
Source
Gets an empty resolution context.
string? CorrelationId { get; }
Source
Gets the optional display-safe correlation id.
IReadOnlyDictionary<string, string> Metadata { get; }
Source
Gets copied metadata that can help an app resolver preserve display-safe context.
Describes an authenticated external subject before it has been resolved to an app-owned user id.
The uniqueness key is the ordinal tuple of Issuer
, Subject
, and optional PartitionKey
. Use PartitionKey
only for host-validated realm, tenant, client, or environment context that is part of the subject namespace. AppSurface does not treat the partition as tenant authority or authorization truth. The raw values are intentionally omitted from ToString
.
string Issuer { get; }
Source
Gets the stable issuer or identity-provider namespace.
string Subject { get; }
Source
Gets the stable subject id inside the issuer namespace.
string? PartitionKey { get; }
Source
Gets the optional host-validated partition that participates in the uniqueness key.
Registers the surface-neutral AppSurface auth composition boundary.
AppSurfaceAuthModule
is a boundary-preview module. It gives AppSurface packages a stable place to compose future auth contracts without taking a dependency on ASP.NET Core authentication, authorization policies, identity providers, middleware, endpoint filters, cookies, bearer tokens, or UI. Registering this module does not sign users in, inspect requests, challenge callers, forbid callers, or enforce authorization; host applications must continue to configure those behaviors in their host-specific security stack.
void ConfigureServices(StartupContext context, IServiceCollection services)
Registers the AppSurface auth boundary options type.
context
services
This method registers AppSurfaceAuthOptions
with the Microsoft Options pattern so later AppSurface auth contracts have a documented options home. It intentionally adds no runtime auth behavior and performs no request, principal, policy, middleware, or identity-provider configuration.
void RegisterDependentModules(ModuleDependencyBuilder builder)
Registers modules required by the AppSurface auth boundary.
builder
The boundary preview has no dependent modules. Future host-specific auth integrations should declare their own dependencies instead of relying on this module to pull in ASP.NET Core or UI packages.
Identifies a durable app-owned user record after an external authenticated subject has been resolved.
AppUserId
belongs to the consuming application. AppSurface does not allocate ids, prescribe storage, or treat the id as a permission source. The value is intentionally omitted from ToString
so accidental logs and diagnostics do not disclose user identifiers by default.
string Value { get; }
Source
Gets the stable app-owned user id value.
Classifies the host-declared risk of an action an agent proposes.
Risk is descriptive metadata for host policy and user-facing confirmation. It is not permission truth and does not allow an agent to execute an action.
States the confirmation posture declared for an action.
The posture is an input to host policy. A host can require confirmation for any action, and only a host-issued AgentAuthorizationDecision
determines whether the requested action may proceed.
States how a host should treat action arguments in confirmation, audit, and diagnostic displays.
Defines the outcome of host evaluation for an agent action request.
Defines terminal outcomes when a host attempts to consume an approval receipt.
Hosts own receipt storage and atomicity. A host must return exactly one terminal outcome for a consumption attempt and must not retry execution after AlreadyConsumed
. Outcomes such as Stale
are terminal for an attempt, not necessarily for the receipt: a host that detects stale state before its atomic claim leaves the receipt unconsumed and may retry after the original state is restored.
Identifies a passive delegated-agent authorization audit description.
This enum describes lifecycle events only. AppSurface does not write logs, metrics, traces, or persisted audit records; hosts own transport, retention, redaction, access control, and failure handling.
Defines result states for resolving an external subject to an app-owned user id.
Defines the high-level auth outcome AppSurface modules can understand without owning host authentication.
Defines the concrete reason associated with an AppSurface auth outcome.