Docs
Tenantry CoreAPI reference

ITenantAccessValidator<TKey> interface

Namespace: Tenantry.AspNetCore · Package: Tenantry.AspNetCore · API reference

Decides whether a request may use the tenant it names. Register one with tenant.ValidateTenantAccess<TValidator>(): it is created in each request's scope, so it can depend on scoped services such as a DbContext.

Every validator must allow a request before its tenant is made current. A request refused by one gets TenantResolutionOptions<TKey>.AccessDeniedStatusCode on an endpoint that needs a tenant, and continues without a tenant on any other.

public sealed class MembershipValidator(AppDbContext db) : ITenantAccessValidator<Guid>
{
    public async ValueTask<bool> ValidateAsync(HttpContext context, ITenantDescriptor<Guid> tenant, CancellationToken ct) =>
        await db.Memberships.AnyAsync(m => m.UserId == context.User.FindFirstValue("sub") && m.TenantId == tenant.TenantId, ct);
}
public interface ITenantAccessValidator<TKey> where TKey : IEquatable<TKey>, IParsable<TKey>

Type parameters

  • TKey: The tenant identifier type.

Methods

ValidateAsync(HttpContext, ITenantDescriptor<TKey>, CancellationToken)

Returns true when the request may use tenant.

ValueTask<bool> ValidateAsync(HttpContext context, ITenantDescriptor<TKey> tenant, CancellationToken cancellationToken)

Parameters:

  • context HttpContext: The request.
  • tenant ITenantDescriptor<TKey>: The tenant the request names, found in the tenant store.
  • cancellationToken CancellationToken: The request's cancellation token.

Returns: ValueTask<bool>

On this page