Deep clean: stop reading password hash, fail-fast config, dependency hygiene - #5
Merged
Merged
Conversation
…icit mapping The reflection-based mapper in Authorization.Common copied every matching property from the database entity into the domain model, which carried the user's password hash into the business and middleware layers even though nothing there needs it. The package only ever mapped two trivial types. - Remove Authorization.Common (Mapper, Converter) and their tests. - Move persistence entities into DataAccess as internal types without a password hash property; Dapper ignores the unmatched column. - Remove PasswordHash from the public User model. - Map entities to models explicitly in SecurityRepository. Refs #3
Microsoft.AspNetCore.Http.Abstractions 2.3.0 is the legacy ASP.NET Core 2.x package; on net8.0 it ships its own copies of types that the host already provides through the shared framework. Reference Microsoft.AspNetCore.App instead, which also covers the Microsoft.Extensions.* packages that were listed explicitly (Configuration.Abstractions was unused). Refs #3
SqlConnectionFactory throws when the connection string is missing, but it is resolved while binding the middleware's scoped dependencies, outside the middleware's graceful-degradation block. A misconfigured host therefore returned 500 on every authenticated request. Validate the options and the connection string presence with ValidateOnStart so the host fails fast. Refs #3
- Add ClaimsEnrichmentMiddleware.UserIdClaimType so consumers and tests stop repeating the "IdUsuario" literal. - Make AddProfileClaimsAsync static; it uses no instance state. - Drop historical wording from option docs and package descriptions. - Update the README for the removed Common package and startup validation. - Share middleware construction in tests and cover the aborted-request path. Refs #3
An empty branches-ignore list is equivalent to an unfiltered push trigger. The CI job only needs to read the repository, so grant contents: read. Refs #3
Deep clean: stop reading password hash, fail-fast config, dependency hygiene
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #3
Brings the cleanup reviewed and merged in #4 into
main.Changes
Usermodel. The reflection mapper packageAuthorization.Commonis replaced with explicit mapping, and the entities are now internal to DataAccess.Microsoft.AspNetCore.Appframework reference instead of the legacyMicrosoft.AspNetCore.Http.Abstractions2.3.0 package and redundantMicrosoft.Extensions.*references.ValidateOnStart) instead of failing every request.UserIdClaimTypeconstant, removed stale comments, updated the README and tests, and restricted CI token permissions.Breaking changes (v2.0.0)
Authorization.Commonpackage was removed.Abstractions.Entitiesis no longer public.User.PasswordHashwas removed.Release note
Merging publishes the 2.0.0 packages to GitHub Packages through
release.yml.