Class AuditingApiKeyServiceDecorator
Decorator that wraps IApiKeyAdministrationService and logs audit entries for all mutation operations via CompositeAuditLogger. Read operations are passed through without logging.
public class AuditingApiKeyServiceDecorator : IApiKeyAdministrationService
- Inheritance
-
AuditingApiKeyServiceDecorator
- Implements
- Inherited Members
Constructors
AuditingApiKeyServiceDecorator(IApiKeyAdministrationService, CompositeAuditLogger, IHttpContextAccessor)
public AuditingApiKeyServiceDecorator(IApiKeyAdministrationService inner, CompositeAuditLogger auditLogger, IHttpContextAccessor httpContextAccessor)
Parameters
innerIApiKeyAdministrationServiceauditLoggerCompositeAuditLoggerhttpContextAccessorIHttpContextAccessor
Methods
CreateKeyAsync(string, string, AccessLevel, string[], string[], DateTime?, IReadOnlyList<Tag>, string, string)
Creates a new API key with the specified settings (advanced mode). tags are system-set key-value tags, settable only here (not from the UI) and immutable thereafter. createdBy records who created the key; null for keys created without a user context (e.g. auto-generated), surfaced as "System" in the UI. ownerMemberKey makes the key owner-scoped ("private") — bound to that team member and hidden from / immutable by other members; null = a normal team-wide key.
public Task<IApiKey> CreateKeyAsync(string teamKey, string name, AccessLevel accessLevel, string[] roles = null, string[] scopeOverrides = null, DateTime? expiryDate = null, IReadOnlyList<Tag> tags = null, string createdBy = null, string ownerMemberKey = null)
Parameters
teamKeystringnamestringaccessLevelAccessLevelrolesstring[]scopeOverridesstring[]expiryDateDateTime?tagsIReadOnlyList<Tag>createdBystringownerMemberKeystring
Returns
CreateSystemKeyAsync(string, string[], DateTime?, string)
Creates a new system-level API key with the specified explicit scope set.
public Task<IApiKey> CreateSystemKeyAsync(string name, string[] scopes, DateTime? expiryDate = null, string createdBy = null)
Parameters
namestringHuman-readable name for the key.
scopesstring[]Explicit scopes granted to this key. Not resolved through AccessLevel/roles.
expiryDateDateTime?Optional expiry date.
createdBystringIdentity of the user creating the key (for audit).
Returns
DeleteKeyAsync(string, string)
Deletes an API key. Verifies team ownership.
public Task DeleteKeyAsync(string teamKey, string key)
Parameters
Returns
DeleteSystemKeyAsync(string)
Deletes a system API key.
public Task DeleteSystemKeyAsync(string key)
Parameters
keystring
Returns
GetByApiKeyAsync(string)
Looks up an API key by its raw value. Returns null if no match is found.
public Task<IApiKey> GetByApiKeyAsync(string apiKey)
Parameters
apiKeystring
Returns
GetKeysAsync(string)
Returns all API keys for the specified team, creating default keys if fewer than AutoKeyCount exist.
public IAsyncEnumerable<IApiKey> GetKeysAsync(string teamKey)
Parameters
teamKeystring
Returns
GetSystemKeysAsync()
Returns all system-level API keys (not bound to a team).
public IAsyncEnumerable<IApiKey> GetSystemKeysAsync()
Returns
LockKeyAsync(string, string)
Discards the stored secret so the raw key value can never be retrieved again. Verifies team ownership.
public Task LockKeyAsync(string teamKey, string key)
Parameters
Returns
Remarks
This does not disable the key. A locked key still authenticates — locking only makes the
value unrecoverable, which is why ApiKeyOptions.AutoLockKeys can lock every key at creation
without breaking anything.
To stop a key working, use SetKeyDisabledAsync(string, string, bool, string), which is reversible and keeps the key's name, scopes, roles, tags and history. Delete only when the key should cease to exist.
LockSystemKeyAsync(string)
Discards the stored secret of a system API key so its raw value can never be retrieved again.
public Task LockSystemKeyAsync(string key)
Parameters
keystring
Returns
Remarks
This does not disable the key — see LockKeyAsync(string, string).
RefreshKeyAsync(string, string)
Generates a new API key value for an existing key entry. Returns the entity with the raw key visible once.
public Task<IApiKey> RefreshKeyAsync(string teamKey, string key)
Parameters
Returns
RefreshSystemKeyAsync(string)
Regenerates a system key's raw value. Returns the entity with the raw key visible once.
public Task<IApiKey> RefreshSystemKeyAsync(string key)
Parameters
keystring
Returns
SetKeyDisabledAsync(string, string, bool, string)
public Task SetKeyDisabledAsync(string teamKey, string key, bool disabled, string actor = null)
Parameters
Returns
Remarks
Both directions are audited, and under distinct actions: disable is a containment and
enable is a decision to trust the key again. Rolling them into one entry keyed on a boolean
would make "who re-enabled this, and when" a query rather than a reading.
SetRolesAsync(string, string, string[])
Sets the Roles (tenant roles) array on an existing team API key. Verifies team ownership.
Pass null or an empty array to clear all roles.
public Task SetRolesAsync(string teamKey, string key, string[] roles)
Parameters
Returns
SetScopeOverridesAsync(string, string, string[])
Sets the ScopeOverrides array on an existing team API key. Verifies team ownership.
Pass null or an empty array to clear all overrides.
public Task SetScopeOverridesAsync(string teamKey, string key, string[] scopes)
Parameters
Returns
SetSystemKeyDisabledAsync(string, bool, string)
public Task SetSystemKeyDisabledAsync(string key, bool disabled, string actor = null)
Parameters
Returns
Remarks
Both directions are audited, and under distinct actions: disable is a containment and
enable is a decision to trust the key again. Rolling them into one entry keyed on a boolean
would make "who re-enabled this, and when" a query rather than a reading.