Skip to content

Report every sign-in and route JWT sign-in through CustomSignInManager - #4

Merged
gismofx merged 2 commits into
mainfrom
feature/portguardian-signin-events
Sep 26, 2026
Merged

gismofx merged 2 commits into
mainfrom
feature/portguardian-signin-events

Conversation

@gismofx

@gismofx gismofx commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator
  • CustomSignInManager reports each sign-in (ISignInReporter): cookie sign-ins via a PasswordSignInAsync override, token sign-ins via the new CheckPasswordByEmailAsync
  • Default reporter: an ILogger line on every OS (category CPE.DapperIdentity.SignIn) and, on Windows, an Application-log event under PortGuardian.SignIn (1000 failed, 1001 succeeded); never throws
  • Fix: JWT Authenticate checked only the password hash, so a disabled user still got a token; Refresh now refuses a disabled user too
  • The vanilla-UI set-up registers CustomSignInManager, so IsEnabled applies there as well
  • Tests for the event format, each sign-in outcome, and both JWT endpoints over SQLite

- CustomSignInManager reports each sign-in (ISignInReporter): cookie
  sign-ins via a PasswordSignInAsync override, token sign-ins via the
  new CheckPasswordByEmailAsync
- Default reporter: an ILogger line on every OS (category
  CPE.DapperIdentity.SignIn) and, on Windows, an Application-log event
  under PortGuardian.SignIn (1000 failed, 1001 succeeded); never throws
- Fix: JWT Authenticate checked only the password hash, so a disabled
  user still got a token; Refresh now refuses a disabled user too
- The vanilla-UI set-up registers CustomSignInManager, so IsEnabled
  applies there as well
- Tests for the event format, each sign-in outcome, and both JWT
  endpoints over SQLite
Comment thread DapperIdentity.Stores/SignIn/SignInReporting.cs Fixed
Comment thread DapperIdentity.Stores/SignIn/SignInReporting.cs Fixed
- SignInReportingOptions (DapperIdentity:SignInReporting:UserNames):
  Hashed (default), Plain or None; successes never carry a name
- Usernames cleaned of line breaks and control characters and capped
  at 256 characters before logging (CodeQL log forging)
new EventId(attempt.Succeeded ? SignInEventFormat.SucceededId : SignInEventFormat.FailedId,
attempt.Succeeded ? "SignInSucceeded" : "SignInFailed"),
"Sign-in {Outcome} for {UserName} from {ClientIp} on {App} via {Path} ({Reason})",
attempt.Succeeded ? "succeeded" : "failed", SignInEventFormat.UserNameFor(attempt, _userNames), attempt.ClientIp, _appName, attempt.Path,
@gismofx
gismofx merged commit cd299da into main Sep 26, 2026
3 checks passed
@gismofx
gismofx deleted the feature/portguardian-signin-events branch September 26, 2026 23:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants