Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
# 🚀 Pull Request

Thank you for contributing to **UltimateAuth**!
Please complete the following checklist to help us review your PR effectively.
<!-- Thank you for contributing to **UltimateAuth**! -->
<!-- Please complete the following checklist to help us review your PR effectively.-->


## 📘 Summary
Describe what this PR does and why it’s needed.
<!-- Describe what this PR does and why it’s needed. -->


## 🔍 Details
Explain any important implementation details, design decisions, or considerations.
<!-- Explain any important implementation details, design decisions, or considerations. -->


## 🧩 Related Issues
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ UltimateAuth is an open-source auth framework with platform-level capabilities t
| Phase | Version | Scope | Status | Release Date |
| ----------------------- | ------------- | ----------------------------------------- | -------------- | ------------ |
| First Preview | 0.1.0-preview | "Stable" Preview Core | ✅ Completed | 07.04.2026 |
| First Release* | 0.1.0 | Fully Documented & Quality Tested | ✅ Completed | 04.10.2026 |
| First Release* | 0.1.0 | Fully Documented & Quality Tested | ✅ Completed | 08.10.2026 |
| Product Expansion | 0.2.0 | Full Auth Modes | 🟡 In Progress | Q4 2026 |
| Security Expansion | 0.3.0 | MFA, Reauth, Rate Limiting | 🟡 In Progress | Q4 2026 |
| Infrastructure Expansion| 0.4.0 | Redis, Distributed Cache, Password Hasher | 🔜 Planned | Q1 2027 |
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
namespace CodeBeam.UltimateAuth.Sample.UAuthHub.EFCore.Migrations
{
/// <inheritdoc />
public partial class InitUltimateAuth : Migration
public partial class _001_Initial : Migration
{
/// <inheritdoc />
protected override void Up(MigrationBuilder migrationBuilder)
Expand Down Expand Up @@ -432,8 +432,12 @@ protected override void Up(MigrationBuilder migrationBuilder)
migrationBuilder.CreateIndex(
name: "IX_UAuth_SessionRoots_Tenant_UserKey",
table: "UAuth_SessionRoots",
columns: new[] { "Tenant", "UserKey" },
unique: true);
columns: new[] { "Tenant", "UserKey" });

migrationBuilder.CreateIndex(
name: "IX_UAuth_SessionRoots_Tenant_UserKey_RevokedAt",
table: "UAuth_SessionRoots",
columns: new[] { "Tenant", "UserKey", "RevokedAt" });

migrationBuilder.CreateIndex(
name: "IX_UAuth_Sessions_Tenant_ChainId",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ partial class UAuthDbContextModelSnapshot : ModelSnapshot
protected override void BuildModel(ModelBuilder modelBuilder)
{
#pragma warning disable 612, 618
modelBuilder.HasAnnotation("ProductVersion", "10.0.5");
modelBuilder.HasAnnotation("ProductVersion", "10.0.12");

modelBuilder.Entity("CodeBeam.UltimateAuth.Authentication.EntityFrameworkCore.AuthenticationSecurityStateProjection", b =>
{
Expand Down Expand Up @@ -431,8 +431,9 @@ protected override void BuildModel(ModelBuilder modelBuilder)
b.HasIndex("Tenant", "RootId")
.IsUnique();

b.HasIndex("Tenant", "UserKey")
.IsUnique();
b.HasIndex("Tenant", "UserKey");

b.HasIndex("Tenant", "UserKey", "RevokedAt");

b.ToTable("UAuth_SessionRoots", (string)null);
});
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@
//o.Token.RefreshTokenLifetime = TimeSpan.FromSeconds(32);
o.Login.MaxFailedAttempts = 2;
o.Login.LockoutDuration = TimeSpan.FromSeconds(10);
o.Identifiers.AllowMultipleUsernames = true;
o.Identifiers.Behavior.AllowMultipleUsernames = true;
o.UserProfile.EnableMultiProfile = true;
})
.AddUltimateAuthEntityFrameworkCore(db =>
Expand Down
Binary file not shown.
Binary file not shown.
Binary file not shown.
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@
//o.Token.RefreshTokenLifetime = TimeSpan.FromSeconds(32);
o.Login.MaxFailedAttempts = 2;
o.Login.LockoutDuration = TimeSpan.FromSeconds(10);
o.Identifiers.AllowMultipleUsernames = true;
o.Identifiers.Behavior.AllowMultipleUsernames = true;
o.UserProfile.EnableMultiProfile = true;
})
.AddUltimateAuthInMemory()
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
namespace CodeBeam.UltimateAuth.Sample.BlazorServer.EFCore.Migrations
{
/// <inheritdoc />
public partial class InitUltimateAuth : Migration
public partial class _001_Initial : Migration
{
/// <inheritdoc />
protected override void Up(MigrationBuilder migrationBuilder)
Expand Down Expand Up @@ -432,8 +432,12 @@ protected override void Up(MigrationBuilder migrationBuilder)
migrationBuilder.CreateIndex(
name: "IX_UAuth_SessionRoots_Tenant_UserKey",
table: "UAuth_SessionRoots",
columns: new[] { "Tenant", "UserKey" },
unique: true);
columns: new[] { "Tenant", "UserKey" });

migrationBuilder.CreateIndex(
name: "IX_UAuth_SessionRoots_Tenant_UserKey_RevokedAt",
table: "UAuth_SessionRoots",
columns: new[] { "Tenant", "UserKey", "RevokedAt" });

migrationBuilder.CreateIndex(
name: "IX_UAuth_Sessions_Tenant_ChainId",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ partial class UAuthDbContextModelSnapshot : ModelSnapshot
protected override void BuildModel(ModelBuilder modelBuilder)
{
#pragma warning disable 612, 618
modelBuilder.HasAnnotation("ProductVersion", "10.0.5");
modelBuilder.HasAnnotation("ProductVersion", "10.0.12");

modelBuilder.Entity("CodeBeam.UltimateAuth.Authentication.EntityFrameworkCore.AuthenticationSecurityStateProjection", b =>
{
Expand Down Expand Up @@ -431,8 +431,9 @@ protected override void BuildModel(ModelBuilder modelBuilder)
b.HasIndex("Tenant", "RootId")
.IsUnique();

b.HasIndex("Tenant", "UserKey")
.IsUnique();
b.HasIndex("Tenant", "UserKey");

b.HasIndex("Tenant", "UserKey", "RevokedAt");

b.ToTable("UAuth_SessionRoots", (string)null);
});
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@
//o.Token.RefreshTokenLifetime = TimeSpan.FromSeconds(32);
o.Login.MaxFailedAttempts = 2;
o.Login.LockoutDuration = TimeSpan.FromSeconds(10);
o.Identifiers.AllowMultipleUsernames = true;
o.Identifiers.Behavior.AllowMultipleUsernames = true;
})
.AddUltimateAuthEntityFrameworkCore(db =>
{
Expand Down
Binary file not shown.
Binary file not shown.
Binary file not shown.
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@
//o.Token.RefreshTokenLifetime = TimeSpan.FromSeconds(32);
o.Login.MaxFailedAttempts = 2;
o.Login.LockoutDuration = TimeSpan.FromSeconds(10);
o.Identifiers.AllowMultipleUsernames = true;
o.Identifiers.Behavior.AllowMultipleUsernames = true;
})
.AddUltimateAuthInMemory();

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
namespace CodeBeam.UltimateAuth.Core.Abstractions;

public interface IUAuthAtomicExecutor
{
Task ExecuteAsync(Func<CancellationToken, Task> operation, CancellationToken ct = default);

Task<TResult> ExecuteAsync<TResult>(Func<CancellationToken, Task<TResult>> operation, CancellationToken ct = default);
}
1 change: 1 addition & 0 deletions src/CodeBeam.UltimateAuth.Core/AssemblyVisibility.cs
Original file line number Diff line number Diff line change
Expand Up @@ -8,3 +8,4 @@
[assembly: InternalsVisibleTo("CodeBeam.UltimateAuth.Authorization.EntityFrameworkCore")]
[assembly: InternalsVisibleTo("CodeBeam.UltimateAuth.Authentication.EntityFrameworkCore")]
[assembly: InternalsVisibleTo("CodeBeam.UltimateAuth.Tests.Unit")]
[assembly: InternalsVisibleTo("CodeBeam.UltimateAuth.Tests.Integration")]
24 changes: 24 additions & 0 deletions src/CodeBeam.UltimateAuth.Core/Contracts/Common/UniquenessScope.cs
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
namespace CodeBeam.UltimateAuth.Core.Contracts;

// TODO: Add global scope
/// <summary>
/// Defines the scope of uniqueness for an identifier.
/// </summary>
public enum UniquenessScope
{
/// <summary>
/// No uniqueness is enforced.
/// Note that users still can't create duplicate identifiers.
/// </summary>
None = 0,

/// <summary>
/// Uniqueness is enforced within a single user.
/// </summary>
WithinUser = 10,

/// <summary>
/// Uniqueness is enforced within a tenant.
/// </summary>
Tenant = 20
}
1 change: 1 addition & 0 deletions src/CodeBeam.UltimateAuth.Core/Defaults/UAuthActions.cs
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,7 @@ public static class UserIdentifiers
public const string VerifyAdmin = "users.identifiers.verify.admin";
public const string DeleteSelf = "users.identifiers.delete.self";
public const string DeleteAdmin = "users.identifiers.delete.admin";
public const string CheckAvailability = "users.identifiers.check-availability.anonymous";
}

public static class Credentials
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,4 +42,5 @@ public interface IUserEndpointHandler
Task<IResult> UnsetPrimaryUserIdentifierAdminAsync(UserKey userKey, HttpContext ctx);
Task<IResult> VerifyUserIdentifierAdminAsync(UserKey userKey, HttpContext ctx);
Task<IResult> DeleteUserIdentifierAdminAsync(UserKey userKey, HttpContext ctx);
Task<IResult> CheckIdentifierAvailabilityAsync(HttpContext ctx);
}
Original file line number Diff line number Diff line change
Expand Up @@ -311,6 +311,10 @@ public void MapEndpoints(RouteGroupBuilder rootGroup, UAuthServerOptions options
if (Enabled(UAuthActions.UserIdentifiers.DeleteAdmin))
adminUsers.MapPost("/{userKey}/identifiers/delete", async ([FromServices] IUserEndpointHandler h, UserKey userKey, HttpContext ctx)
=> await h.DeleteUserIdentifierAdminAsync(userKey, ctx)).WithMetadata(new AuthFlowMetadata(AuthFlowType.UserIdentifierManagement));

if (Enabled(UAuthActions.UserIdentifiers.CheckAvailability))
self.MapPost("/identifiers/check-availability", async ([FromServices] IUserEndpointHandler h, HttpContext ctx)
=> await h.CheckIdentifierAvailabilityAsync(ctx)).WithMetadata(new AuthFlowMetadata(AuthFlowType.UserIdentifierManagement));
}

if (options.Endpoints.Credentials != false)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -236,7 +236,8 @@ private static IServiceCollection AddUltimateAuthServerInternal(this IServiceCol
services.TryAddScoped<ISessionValidator, UAuthSessionValidator>();
services.TryAddScoped<IRefreshTokenValidator, UAuthRefreshTokenValidator>();
services.TryAddScoped<IPkceAuthorizationValidator, PkceAuthorizationValidator>();
services.TryAddScoped<IIdentifierValidator, IdentifierValidator>();
services.TryAddScoped<IUserIdentifierValidator, UserIdentifierValidator>();
services.TryAddScoped<IUserProfileValidator, UserProfileValidator>();

services.TryAddScoped<ICredentialResponseWriter, CredentialResponseWriter>();
services.TryAddScoped<IRefreshResponseWriter, RefreshResponseWriter>();
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ public sealed class IdentifierNormalizer : IIdentifierNormalizer

public IdentifierNormalizer(IOptions<UAuthServerOptions> options)
{
_options = options.Value.LoginIdentifiers.Normalization;
_options = options.Value.Identifiers.Normalization;
}

public NormalizedIdentifier Normalize(UserIdentifierType type, string value)
Expand Down

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
using CodeBeam.UltimateAuth.Core.Contracts;
using CodeBeam.UltimateAuth.Users.Contracts;

namespace CodeBeam.UltimateAuth.Server.Infrastructure;

public interface IUserIdentifierValidator
{
Task<UserIdentifierValidationResult> ValidateAsync(AccessContext context, UserIdentifierInfo identifier, CancellationToken ct = default);
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
using CodeBeam.UltimateAuth.Core.Contracts;
using CodeBeam.UltimateAuth.Users.Contracts;

namespace CodeBeam.UltimateAuth.Server.Infrastructure;

public interface IUserProfileValidator
{
Task<UserProfileValidationResult> ValidateAsync(AccessContext context, UserProfileInfo profile, CancellationToken ct = default);
}
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,13 @@ namespace CodeBeam.UltimateAuth.Server.Infrastructure;

public sealed class UserCreateValidator : IUserCreateValidator
{
private readonly IIdentifierValidator _identifierValidator;
private readonly IUserIdentifierValidator _identifierValidator;
private readonly IUserProfileValidator _profileValidator;

public UserCreateValidator(IIdentifierValidator identifierValidator)
public UserCreateValidator(IUserIdentifierValidator identifierValidator, IUserProfileValidator profileValidator)
{
_identifierValidator = identifierValidator;
_profileValidator = profileValidator;
}

public async Task<UserCreateValidatorResult> ValidateAsync(AccessContext context, CreateUserRequest request, CancellationToken ct = default)
Expand Down Expand Up @@ -57,6 +59,30 @@ public async Task<UserCreateValidatorResult> ValidateAsync(AccessContext context
errors.AddRange(r.Errors);
}

var effectiveDisplayName =
request.DisplayName
?? request.UserName
?? request.Email
?? request.Phone;

var profileValidation = await _profileValidator.ValidateAsync(context,
new UserProfileInfo
{
ProfileKey = ProfileKey.Default,
FirstName = request.FirstName,
LastName = request.LastName,
DisplayName = effectiveDisplayName,
BirthDate = request.BirthDate,
Gender = request.Gender,
Bio = request.Bio,
Language = request.Language,
TimeZone = request.TimeZone,
Culture = request.Culture
},
ct);

errors.AddRange(profileValidation.Errors);

if (errors.Count == 0)
return UserCreateValidatorResult.Success();

Expand Down
Loading
Loading