mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
Both hosts now apply the same Identity password rule: at least 6 characters with one uppercase letter, one number and one special character. Change password requires an authenticated caller, verifies the current password before evaluating the new one, and reports a policy rejection separately from a wrong current password.
24 lines
924 B
C#
24 lines
924 B
C#
using Data.SeaHavenIndustries;
|
|
using Microsoft.AspNetCore.Identity;
|
|
|
|
namespace Api.SeaHavenIndustries.Infrastructure
|
|
{
|
|
public static class IdentityRegistration
|
|
{
|
|
/// <summary>
|
|
/// Registers ASP.NET Identity for the API with the shared password policy.
|
|
/// Program.cs and the behavior tests both compose Identity through this
|
|
/// method so the rule under test is the rule that runs.
|
|
/// </summary>
|
|
public static IdentityBuilder AddSeaHavenIdentity(this IServiceCollection services)
|
|
{
|
|
return services.AddIdentity<ApplicationUser, IdentityRole>(options =>
|
|
{
|
|
options.User.RequireUniqueEmail = false;
|
|
IdentityPasswordPolicy.Apply(options.Password);
|
|
})
|
|
.AddEntityFrameworkStores<ApplicationDbContext>()
|
|
.AddDefaultTokenProviders();
|
|
}
|
|
}
|
|
}
|