Search Results for

      Show / Hide Table of Contents

      Intent.AspNetCore.Identity.AccountController

      Generate ASP.NET Core WebAPI controller for account management and JWT authentication.

      What This Module Does

      This module generates a complete account management controller that exposes HTTP endpoints for user registration and authentication. It includes:

      • Register Endpoint - User account registration with email/password
      • Login Endpoint - User login returning JWT bearer token
      • Password Reset - Forgot-password and reset-password endpoints
      • Account Management - Read and update the current user's email and password
      • Email Confirmation - Email sending service (customizable)
      • JWT Token Generation - Secure token creation with configurable expiration
      • Token Service - Reusable token creation abstraction

      The controller integrates with ASP.NET Core Identity for user management and JWT for token-based authentication.

      Generated Artifacts

      AccountController

      HTTP controller with endpoints:

      Endpoint Purpose
      POST /api/Account/Register Create a new user account
      POST /api/Account/Login Log in and receive a JWT bearer token
      POST /api/Account/Refresh Exchange a refresh token for a new access token
      POST /api/Account/ConfirmEmail Confirm an email address from a registration link
      POST /api/Account/Logout Log the current user out
      POST /api/Account/forgotPassword Send a password reset link
      POST /api/Account/resetPassword Complete a password reset
      GET /api/Account/manage/info Retrieve the current user's info
      POST /api/Account/manage/info Update the current user's email and/or password

      Route prefix

      The api segment above is not hardcoded — it comes from the Default API Route Prefix setting under API Settings, the same setting ordinary controllers use, so the auth endpoints sit alongside the rest of your API wherever you put it. Set it to auth/ and the endpoints become auth/Account/Login and so on. Clearing it generates routes with no prefix at all (Account/Login).

      That setting belongs to Intent.AspNetCore.Controllers, which this module deliberately does not depend on — installing the auth endpoints should not force controllers onto an application that models no Services. When that module is absent the setting group is too, and the prefix falls back to api.

      ⚠️ The shipped proxy metadata does not follow the setting. The Account service metadata in Intent.AspNetCore.Identity.AccountController.Metadata is static and shared by every consuming application, so typed clients generated by Service Proxies or Web Client keep calling api/.... The Software Factory logs a warning whenever the resolved prefix is not api. The same applies to Intent.Blazor.JwtAuth, which hardcodes api/Account/... in a separate application that cannot read this one's settings.

      TokenService Interface and Implementation

      • ITokenService - Interface for JWT token generation
      • TokenService - Implementation creating JWT bearer tokens with:
        • User ID and email claims
        • Expiration configuration
        • Signature validation

      AccountEmailSender Interface and Implementation

      • IAccountEmailSender - Interface for email notification
      • AccountEmailSender - Implementation for sending confirmation/reset emails
      • Customizable via dependency injection

      Models and DTOs

      • Register request model with email/password validation
      • Authenticate request model
      • Token response model with token and expiration
      • User identity models

      Key Design Patterns

      Identity and Authentication Flow

      1. User registers with email and password
      2. ASP.NET Core Identity hashes and stores password
      3. User authenticates with credentials
      4. TokenService generates JWT bearer token
      5. Client includes token in Authorization header for subsequent requests

      JWT Token Structure

      Generated tokens include:

      • Issued Claims:
        • sub (subject) - User ID
        • email - User email address
        • iat (issued at) - Token creation time
        • exp (expiration) - Token expiration time
      • Validation: HMAC signature verification

      Email Confirmation (Optional)

      • Account registration triggers email confirmation email
      • Custom IAccountEmailSender implementation sends email
      • Confirmation link includes verification token
      • Email confirmed before account fully activated

      Role-Based Authorization

      • Token includes roles/claims from ASP.NET Core Identity
      • Controllers use [Authorize] and [Authorize(Roles="Admin")]
      • Custom authorization policies can be defined

      Customization Points

      Token Configuration

      Customize via TokenService configuration:

      • Expiration Duration - JWT token lifetime (default: 15 minutes)
      • Refresh Token Lifetime - Refresh token validity period
      • Secret Key - HMAC signature secret (from configuration)
      • Issuer/Audience - JWT claims validation

      Email Sender Implementation

      Override IAccountEmailSender implementation:

      • SendConfirmationEmail - Custom email template
      • SendPasswordResetEmail - Password reset email
      • Use SendGrid, SMTP, or other providers

      User Identity Entity

      Configure via ASP.NET Core Identity options:

      • PasswordPolicy - Complexity requirements (length, uppercase, digits, symbols)
      • LockoutPolicy - Account lockout after failed attempts
      • SignInPolicy - Require email confirmation before signin
      • TokenProvider - Token generation for email confirmation

      Class Name and Namespace Overrides

      • ClassName - AccountController class name formula
      • Namespace - Controller namespace formula

      When To Use

      Use this module when:

      • Building APIs with user authentication and JWT tokens
      • You need account registration and login endpoints
      • Integrating with ASP.NET Core Identity for user management
      • Implementing Role-Based Access Control (RBAC)
      • Supporting email-based account confirmation

      Don't use when:

      • Building applications with Windows/NTLM authentication
      • Integrating with external OAuth/OIDC providers (consider MSAL module instead)
      • API authentication is handled by API Gateway
      • Client applications handle identity entirely

      Module Settings

      This module contributes no settings of its own. It reads one setting owned by another module:

      Default API Route Prefix (API Settings)

      Owned by Intent.AspNetCore.Controllers. Drives the route prefix for every generated endpoint — see Route prefix above for the fallback and proxy-metadata caveats.

      Identity User Type Configuration

      • IdentityUser Entity - Entity representing authenticated users
      • Primary Key Type - GUID (default) or Int

      Database Configuration

      • EF Core migrations create AspNetUsers table
      • Password hashing via Identity's password hasher
      • Claims and roles stored in Identity tables

      Related Modules

      • Intent.AspNetCore.Identity - ASP.NET Core Identity configuration
      • Intent.Security.JWT - JWT token generation and validation utilities
      • Intent.Application.Identity - Current user service and authorization
      • Intent.Security.MSAL - OAuth/OIDC authentication via Azure AD
      • Edit this page
      ☀
      ☾
      In this article
      Back to top Copyright © 2017-, Intent Architect Holdings Ltd