Skip to content

[BUG] ABAC needs a populated ISecurityContextAccessor, but AddEncinaABAC does not register it and nothing populates SecurityContext from HttpContext.User #1705

Description

@dlrivada

Description

ABAC requires a populated ISecurityContextAccessor, but AddEncinaABAC neither registers it with the DI container nor does Encina provide a mechanism to populate SecurityContext from HttpContext.User. Applications following the quick-start receive abac.missing_context on every request after PR #1701 merges.

Steps to Reproduce

  1. Configure ABAC using only AddEncinaABAC (per docs/features/abac/quick-start.md:21-41)
  2. Create an endpoint decorated with [RequirePolicy] or [RequireCondition]
  3. Make an authenticated request to that endpoint
  4. See abac.missing_context error

Expected Behavior

The ABAC PEP evaluates against a security context the framework provides, opt-in and fail-closed:

  1. AddEncinaABAC registers everything it resolves, or fails at startup with a message naming the missing registration (AddEncinaSecurity); a DI test builds ABAC alone with ValidateOnBuild and ValidateScopes (AGENTS.md section 3).
  2. An opt-in ASP.NET Core integration in Encina.AspNetCore populates SecurityContext from HttpContext.User per request (user id from the configured claim, roles, IsAuthenticated), registered by an explicit extension method; tests with an authenticated and an anonymous request.
  3. A documented service-identity pattern for background jobs and message handlers (an explicit scope that sets a service principal).
  4. The ABAC quick-start and README show the complete registration.

Actual Behavior

After PR #1701 merges, every request decorated with [RequirePolicy] or [RequireCondition] fails with abac.missing_context. Before #1701, the behavior was fail-open: the request was evaluated as user "" (#1676).

Environment

Code Sample

// docs/features/abac/quick-start.md:21-41 registers only ABAC:
services.AddEncinaABAC(options => { /* ... */ });
// No AddEncinaSecurity() and nothing sets ISecurityContextAccessor.SecurityContext,
// so [RequirePolicy] requests are denied with abac.missing_context.

Stack Trace

Not applicable: the request returns Left(abac.missing_context); no exception is thrown.

Additional Context

Root Cause

  1. AddEncinaABAC resolves ISecurityContextAccessor in pipeline behavior but never registers it with the DI container. Unit tests manually add a substitute; no test validates ABAC registration alone with ValidateOnBuild/ValidateScopes.
  2. Nothing in src/ sets ISecurityContextAccessor.SecurityContext. The only reference is a hand-copied snippet in src/Encina.Security/README.md:58-65. Encina.AspNetCore does not provide an integration to populate the context from HttpContext.User.
  3. No documented pattern exists for populating the security context in non-HTTP flows (background jobs, message handlers).

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-authorizationAuthorization and access control patternsbugSomething isn't workingp0-mandatoryBacklog priority P0: mandatory for 1.0 (SPEC-000, ENCINA-1.0-RECONCILIATION section 4)

    Projects

    • Status
      Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions