Table of Contents

Interface IUserDirectoryService

Namespace
Tharga.Team
Assembly
Tharga.Team.dll

Pluggable connection to an external user directory (e.g. Microsoft Entra ID). Optional — registered via AddUserDirectoryService<T>() on the platform options; when not registered, directory features (verify, directory-only listing, directory delete) are unavailable and their UI is hidden.

public interface IUserDirectoryService

Properties

IsConfigured

Whether this directory has everything it needs to answer. A registration that is missing configuration reports false, and callers treat it exactly as they treat no registration at all — directory features stay hidden rather than being offered and then failing.

bool IsConfigured { get; }

Property Value

bool

Remarks

Defaults to true, so an implementation with nothing to configure — or one written before this member existed — needs no change.

The alternative was to let the first call fail, which is what the Entra provider used to do: it threw InvalidOperationException on the first Graph request, long after registration appeared to succeed and from a place that named neither the registration nor the missing setting. An unmet prerequisite should be reported where it can be acted on, not where it happens to be noticed.

Methods

DeleteUserAsync(string, CancellationToken)

Delete a user from the directory. For Entra this is a soft delete: the user is restorable by an administrator for 30 days, but is immediately signed-out-of and removed org-wide.

Task DeleteUserAsync(string directoryId, CancellationToken cancellationToken = default)

Parameters

directoryId string
cancellationToken CancellationToken

Returns

Task

GetUsersAsync(CancellationToken)

Enumerate all users in the directory, streamed page by page.

IAsyncEnumerable<DirectoryUser> GetUsersAsync(CancellationToken cancellationToken = default)

Parameters

cancellationToken CancellationToken

Returns

IAsyncEnumerable<DirectoryUser>

SetUserNameAsync(string, string, CancellationToken)

Write a display name back to the directory.

Task SetUserNameAsync(string directoryId, string name, CancellationToken cancellationToken = default)

Parameters

directoryId string
name string
cancellationToken CancellationToken

Returns

Task

Remarks

The only write here that is not destructive, and the reason it exists: an application that collects no attributes at sign-up holds the real name while the directory holds a placeholder, so the good name exists and cannot reach the people administering the tenant.

Never called automatically. Which side owns display names is a per-host decision — a host federating from a corporate directory wants the directory authoritative and would be alarmed to find the application overwriting it. Gated on o.Blazor.WriteNameToDirectory, default off.

Throws by default, so a directory implementation that cannot write says so rather than silently accepting and discarding — the failure mode this codebase keeps having to fix.

VerifyUserAsync(IUser, CancellationToken)

Verify that a local user still exists (and is enabled) in the directory. Resolves by the user's stored DirectoryId when set, otherwise falls back to matching by email.

Task<DirectoryVerificationResult> VerifyUserAsync(IUser user, CancellationToken cancellationToken = default)

Parameters

user IUser
cancellationToken CancellationToken

Returns

Task<DirectoryVerificationResult>