TenantryAspNetCoreTenantBuilderExtensions class
Namespace: Microsoft.Extensions.DependencyInjection · Package: Tenantry.AspNetCore · API reference
Tenantry's ASP.NET Core features on ITenantBuilder<TKey>: how a request is resolved to a tenant, whether endpoints need one, and who may use it. app.UseTenantry() applies them to requests.
public static class TenantryAspNetCoreTenantBuilderExtensionsMethods
ConfigureResolution<TKey>(ITenantBuilder<TKey>, Action<TenantResolutionOptions<TKey>>)
Configures how requests are treated: whether they need a tenant, the status code of each rejection, and the events raised when a request's tenant is made current or a request is rejected.
public static ITenantBuilder<TKey> ConfigureResolution<TKey>(this ITenantBuilder<TKey> builder, Action<TenantResolutionOptions<TKey>> configure) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.configureAction<TenantResolutionOptions<TKey>>: Sets the options.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
RequireTenantByDefault<TKey>(ITenantBuilder<TKey>)
Requires a tenant on every endpoint that does not allow a missing one with AllowMissingTenant().
public static ITenantBuilder<TKey> RequireTenantByDefault<TKey>(this ITenantBuilder<TKey> builder) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ResolveFromClaim<TKey>(ITenantBuilder<TKey>, string)
Resolves the tenant from a claim on the current request principal.
public static ITenantBuilder<TKey> ResolveFromClaim<TKey>(this ITenantBuilder<TKey> builder, string claimType = "tenant_id") where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.claimTypestring: The type of the claim that carries the tenant identifier.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ResolveFromHeader<TKey>(ITenantBuilder<TKey>, string)
Resolves the tenant from the specified HTTP request header.
public static ITenantBuilder<TKey> ResolveFromHeader<TKey>(this ITenantBuilder<TKey> builder, string headerName) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.headerNamestring: The name of the header that carries the tenant identifier, such asX-Tenant-Id.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ResolveFromHost<TKey>(ITenantBuilder<TKey>, Action<HostTenantResolverOptions>?)
Resolves the tenant from the request's host name, such as app.acme.com, for tenants with domains of their own, as HostTenantResolver describes. Your tenant store's ITenantStore<TKey>.FindByIdentifierAsync maps the host name to a tenant.
public static ITenantBuilder<TKey> ResolveFromHost<TKey>(this ITenantBuilder<TKey> builder, Action<HostTenantResolverOptions>? configure = null) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.configureAction<HostTenantResolverOptions>: Sets the domains whose hosts are not tenants (localhostby default), or null for the defaults.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
It resolves every host that is not an IP address or excluded, so resolvers added after it never run for those hosts: add it last. Exclude your own domain, so its hosts do not ask the store for a tenant on every request.
tenant
.ResolveFromSubdomain(o => o.BaseDomains.Add("example.com")) // acme.example.com
.ResolveFromHost(o => o.ExcludedDomains.Add("example.com")); // app.acme.comResolveFromQueryString<TKey>(ITenantBuilder<TKey>, string)
Resolves the tenant from a query string parameter.
public static ITenantBuilder<TKey> ResolveFromQueryString<TKey>(this ITenantBuilder<TKey> builder, string parameterName = "tenantId") where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.parameterNamestring: The name of the query string parameter that carries the tenant identifier.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
For local development and testing only — do not use in production. Query string parameters are routinely logged by servers, proxies, and analytics, and are trivially spoofable, so they are not a safe tenant-resolution mechanism for production traffic.
ResolveFromRouteValue<TKey>(ITenantBuilder<TKey>, string)
Resolves the tenant from a route value.
public static ITenantBuilder<TKey> ResolveFromRouteValue<TKey>(this ITenantBuilder<TKey> builder, string routeValueKey = "tenant") where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.routeValueKeystring: The name of the route value that carries the tenant identifier, as in/api/{tenant}/orders.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ResolveFromSubdomain<TKey>(ITenantBuilder<TKey>, Action<SubdomainTenantResolverOptions>?)
Resolves the tenant from the subdomain of the request host, as SubdomainTenantResolver describes.
public static ITenantBuilder<TKey> ResolveFromSubdomain<TKey>(this ITenantBuilder<TKey> builder, Action<SubdomainTenantResolverOptions>? configure = null) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.configureAction<SubdomainTenantResolverOptions>: Sets the base domains and the subdomains that are not tenants (wwwby default), or null for the defaults.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
UseResolver<TResolver>(ITenantBuilder)
Registers a custom ITenantResolver implementation, created through dependency injection in each request's scope, so it can depend on scoped services such as a DbContext.
public static ITenantBuilder UseResolver<TResolver>(this ITenantBuilder builder) where TResolver : class, ITenantResolverType parameters:
TResolver: The resolver type.
Parameters:
builderITenantBuilder: The tenant builder.
Returns: ITenantBuilder: The same builder, without its key type: call methods that need it first.
UseResolver<TKey>(ITenantBuilder<TKey>, Func<IServiceProvider, ITenantResolver>)
Registers a custom ITenantResolver created by a factory, as a singleton.
public static ITenantBuilder<TKey> UseResolver<TKey>(this ITenantBuilder<TKey> builder, Func<IServiceProvider, ITenantResolver> factory) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.factoryFunc<IServiceProvider, ITenantResolver>: Creates the resolver from the application's services.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
UseResolver<TKey>(ITenantBuilder<TKey>, ITenantResolver)
Registers a custom ITenantResolver instance.
public static ITenantBuilder<TKey> UseResolver<TKey>(this ITenantBuilder<TKey> builder, ITenantResolver resolver) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.resolverITenantResolver: The resolver to use for every request.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ValidateTenantAccessByClaim<TKey>(ITenantBuilder<TKey>, string)
Validates tenant access by matching the resolved tenant against claims on the current request principal. Supports repeated claims with single tenant ids and JSON array claim values.
public static ITenantBuilder<TKey> ValidateTenantAccessByClaim<TKey>(this ITenantBuilder<TKey> builder, string claimType) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.claimTypestring: The type of the claims that list the tenant identifiers the principal may use. A request for any other tenant is refused.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ValidateTenantAccess<TValidator>(ITenantBuilder)
Adds an access validator of type TValidator, created in each request's scope, so it can depend on scoped services such as a DbContext. Every validator must allow a request before its tenant is made current.
public static ITenantBuilder ValidateTenantAccess<TValidator>(this ITenantBuilder builder) where TValidator : classType parameters:
TValidator: The validator type, which implementsITenantAccessValidator<TKey>for the application's tenant key type.
Parameters:
builderITenantBuilder: The tenant builder.
Returns: ITenantBuilder: The same builder, without its key type: call methods that need it first.
Exceptions:
InvalidOperationException:TValidatordoes not implementITenantAccessValidator<TKey>for the builder's key type.
ValidateTenantAccess<TKey>(ITenantBuilder<TKey>, Func<HttpContext, ITenantDescriptor<TKey>, bool>)
Adds a synchronous tenant access validator. Every validator must allow a request before its tenant is made current.
public static ITenantBuilder<TKey> ValidateTenantAccess<TKey>(this ITenantBuilder<TKey> builder, Func<HttpContext, ITenantDescriptor<TKey>, bool> validator) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.validatorFunc<HttpContext, ITenantDescriptor<TKey>, bool>: Returns true when the request may use the resolved tenant; otherwise an endpoint that needs a tenant refuses the request withTenantResolutionOptions<TKey>.AccessDeniedStatusCode, and any other runs without one.
Returns: ITenantBuilder<TKey>: The same builder for chaining.
ValidateTenantAccess<TKey>(ITenantBuilder<TKey>, Func<HttpContext, ITenantDescriptor<TKey>, CancellationToken, ValueTask<bool>>)
Adds an asynchronous tenant access validator. Every validator must allow a request before its tenant is made current.
public static ITenantBuilder<TKey> ValidateTenantAccess<TKey>(this ITenantBuilder<TKey> builder, Func<HttpContext, ITenantDescriptor<TKey>, CancellationToken, ValueTask<bool>> validator) where TKey : IEquatable<TKey>, IParsable<TKey>Type parameters:
TKey: The tenant identifier type.
Parameters:
builderITenantBuilder<TKey>: The tenant builder.validatorFunc<HttpContext, ITenantDescriptor<TKey>, CancellationToken, ValueTask<bool>>: Returns true when the request may use the resolved tenant; otherwise an endpoint that needs a tenant refuses the request withTenantResolutionOptions<TKey>.AccessDeniedStatusCode, and any other runs without one. It receives the request's cancellation token.
Returns: ITenantBuilder<TKey>: The same builder for chaining.