Skip to content
Configuration binding

Configuration binding

Both AddHmacManager and AddHmac take an IConfigurationSection instead of a builder delegate:

builder.Services
    .AddAuthentication()
    .AddHmac(builder.Configuration.GetSection("HmacPolicies"));

The schema

The section binds to an array of policies:

{
  "HmacPolicies": [
    {
      "Name": "Some_Policy",
      "Keys": {
        "PublicKey": "37e3e675-370a-4ba9-af74-68f99b539f03",
        "PrivateKey": "zvg29s2cQ4idOqbUJWETOw=="
      },
      "Algorithms": {
        "ContentHashAlgorithm": "SHA256",
        "SigningHashAlgorithm": "HMACSHA256"
      },
      "Nonce": {
        "CacheType": "Memory",
        "MaxAgeInSeconds": 100
      },
      "Schemes": [
        {
          "Name": "Some_Scheme",
          "Headers": [
            {
              "Name": "Some_Header_1",
              "ClaimType": "Header_1_ClaimType"
            }
          ]
        }
      ]
    }
  ]
}

Restricted values:

PropertyValues
PublicKeya GUID string
PrivateKeya base64-encoded string
ContentHashAlgorithmSHA1, SHA256, SHA512
SigningHashAlgorithmHMACSHA1, HMACSHA256, HMACSHA512
CacheTypeMemory, Distributed

Invalid values fail when the policy is built, not on the first request.

See the full schema reference.

PrivateKey is a shared secret. appsettings.json is committed; put the key in user secrets, an environment variable or a real secret store, and let configuration composition supply it. The Kubernetes verifier sources keys from Secrets for exactly this reason.

Reloading

Configuration providers that support reload (the JSON provider does, with reloadOnChange) propagate changes to the live policy set without a restart. The reloader reports the policy set it loaded at startup and on every change at Information (events 1210 and 1211); a reload that fails keeps the previous set and says so at Warning (event 1212). See logging.

With events

The IConfigurationSection overload of AddHmac takes HmacEvents as an optional second argument, since there is no options delegate to set them in:

builder.Services
    .AddAuthentication()
    .AddHmac(configurationSection, new HmacEvents
    {
        OnValidateKeysAsync = (context, keys) => { /* ... */ },
    });

See events.