IdentityServer4.Contrib.RedisStore 1.0.1

.NET Standard 1.5
There is a newer version of this package available.
See the version list below for details.
dotnet add package IdentityServer4.Contrib.RedisStore --version 1.0.1
NuGet\Install-Package IdentityServer4.Contrib.RedisStore -Version 1.0.1
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="IdentityServer4.Contrib.RedisStore" Version="1.0.1" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
paket add IdentityServer4.Contrib.RedisStore --version 1.0.1
#r "nuget: IdentityServer4.Contrib.RedisStore, 1.0.1"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
// Install IdentityServer4.Contrib.RedisStore as a Cake Addin
#addin nuget:?package=IdentityServer4.Contrib.RedisStore&version=1.0.1

// Install IdentityServer4.Contrib.RedisStore as a Cake Tool
#tool nuget:?package=IdentityServer4.Contrib.RedisStore&version=1.0.1

IdentityServer4.Contrib.RedisStore

IdentityServer4.Contrib.RedisStore is a persistance layer using Redis DB for operational data of Identity Server 4. Specifically, this store provides implementation for IPersistedGrantStore.

How to use

You need to install the nuget package

then you can inject the stores in the Identity Server 4 Configuration at startup:

public void ConfigureServices(IServiceCollection services)
        {
            const string connectionString = @"---redis store connection string---";
            
            services.AddMvc();

            services.AddIdentityServer()
                .AddTemporarySigningCredential()
                .AddOperationalStore(connectionString);
        }

Or by passing ConfigurationOptions instance, which contains the configuration of Redis store:

public void ConfigureServices(IServiceCollection services)
        {
            var options = new ConfigurationOptions {  /* ... */ };
            
            services.AddMvc();

            services.AddIdentityServer()
                .AddTemporarySigningCredential()
                .AddOperationalStore(options);
        }

the solution approach

the solution was approached based on how the SQL Store storing the operational data, but the concept of Redis as a NoSQL db is totally different than relational db concepts, all the operational data stores implement the following IPersistedGrantStore interface:

    public interface IPersistedGrantStore
    {
        Task StoreAsync(PersistedGrant grant);

        Task<PersistedGrant> GetAsync(string key);

        Task<IEnumerable<PersistedGrant>> GetAllAsync(string subjectId);

        Task RemoveAsync(string key);

        Task RemoveAllAsync(string subjectId, string clientId);

        Task RemoveAllAsync(string subjectId, string clientId, string type);
    }

with the IPersistedGrantStore contract, we notice that the GetAllAsync(subjectId), RemoveAllAsync(subjectId,clientId) and RemoveAllAsync(subjectId,clientId,type) defines a contract to read based on subject id and remove all the grants in the store based on subject, client ids and type of the grant.

this brings trouble to Redis store since redis as a reliable dictionary is not designed for relational queries, so the trick is to store multiple key entries for the same grant, and the keys can be reached using key, subject, client ids and type.

so the StoreAsync operation stores the following entries in Redis:

  1. Key → RedisStruct: stored as key string value pairs, used to retrieve the grant based on the key, if the grant exists or not expired.

  2. Key(SubjectId) → Key* : stored in a redis Set, used on the GetAllAsync, to retrieve all the grant related to a given subject id.

  3. Key(SubjectId:ClientId) → Key* : stored in a redis set, used to retrieve all the keys that are related to a subject and client ids, to remove them while calling RemoveAllAsync.

  4. Key(SubjectId:ClientId:type) → Key* : stored in a redis set, used to retrieve all the keys that are related to a subject, client ids and type of the grant, to remove them while calling RemoveAllAsync.

for more information on data structures used to store the grant please refer to Redis data types documentation

since Redis has a key Expiration feature based on a defined date time or time span, and to not implement a logic similar to SQL store implementation for cleaning up the store periodically from dangling grants, the store uses the key expiration of redis while storing based on the following criteria:

  1. for Key of the grant, the expiration is straight forward, it's set on the StringSet Redis operation as defined by identity server on the grant object.

  2. for Key(SubjectId), Key(SubjectId:ClientId) and Key(SubjectId:clientId:type) the expiration is not set, since the same and only store type is persisting the grants regardless of their type, not like the identity server 3, where it has multiple store for each grant type.

Feedback

feedbacks are always welcomed, please open an issue for any problem or bug found, and the suggestions are also welcomed.

Product Versions
.NET net5.0 net5.0-windows net6.0 net6.0-android net6.0-ios net6.0-maccatalyst net6.0-macos net6.0-tvos net6.0-windows net7.0 net7.0-android net7.0-ios net7.0-maccatalyst net7.0-macos net7.0-tvos net7.0-windows
.NET Core netcoreapp1.0 netcoreapp1.1 netcoreapp2.0 netcoreapp2.1 netcoreapp2.2 netcoreapp3.0 netcoreapp3.1
.NET Standard netstandard1.5 netstandard1.6 netstandard2.0 netstandard2.1
.NET Framework net461 net462 net463 net47 net471 net472 net48 net481
MonoAndroid monoandroid
MonoMac monomac
MonoTouch monotouch
Tizen tizen30 tizen40 tizen60
Xamarin.iOS xamarinios
Xamarin.Mac xamarinmac
Xamarin.TVOS xamarintvos
Xamarin.WatchOS xamarinwatchos
Compatible target framework(s)
Additional computed target framework(s)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (4)

Showing the top 4 NuGet packages that depend on IdentityServer4.Contrib.RedisStore:

Package Downloads
LDFCore.Authorized

Package Description

LDFCore.Net5.Authorized

Package Description

BizzPo.IdentityServer

Package Description

MySoft.ServiceCenter.Core.IdentityServer

用于微服务器框架的核心库

GitHub repositories (1)

Showing the top 1 popular GitHub repositories that depend on IdentityServer4.Contrib.RedisStore:

Repository Stars
geffzhang/NanoFabric
基于Consul + .NET Core + Polly + Ocelot + Exceptionless + IdentityServer等开源项目的微服务开发框架
Version Downloads Last updated
4.0.0 255,010 7/3/2020
4.0.0-RC 577 6/25/2020
3.1.2 45,097 6/25/2020
3.1.1 39,478 2/20/2020
3.1.0 1,480 2/12/2020
3.0.2 29,232 10/12/2019
3.0.0 16,114 9/24/2019
3.0.0-preview2 344 9/9/2019
3.0.0-preview1 260 8/24/2019
2.1.2 33,991 10/12/2019
2.1.0 25,140 6/6/2019
2.0.0 45,689 11/22/2018
2.0.0-preview1 556 10/30/2018
1.4.5 15,506 10/2/2018
1.4.4.1 1,426 9/10/2018
1.4.4 959 9/8/2018
1.4.3 818 9/8/2018
1.4.2 7,107 6/18/2018
1.4.1 1,523 6/2/2018
1.4.1-rc1 722 6/1/2018
1.3.0 3,662 4/12/2018
1.2.0 2,192 2/28/2018
1.2.0-beta5 2,136 2/12/2018
1.2.0-beta2 768 2/8/2018
1.2.0-beta 667 2/7/2018
1.0.1 2,986 12/21/2017
1.0.0 1,329 9/5/2017
0.9.8-preview 788 8/29/2017
0.9.7-preview 829 8/28/2017
0.9.6-preview 795 8/24/2017

fix a problem related to StackExchange.Redis package, blocking the usage of library in Asp.Net core 2.