Load for Blazor/MudBlazor UI changes involving forms, dialogs, focus, keyboard navigation, landmarks, ARIA, color contrast, RTL-safe styling, or WCAG 2.2 AA tests; not for backend-only changes.
日本語の概要は準備中です。原文の説明を表示しています。
Load for authentication or authorization changes involving BFF cookies/tokens, JWT validation, claims/user ID extraction, policies, handler access checks, impersonation, or 401/403 bugs; not for UI affordance gating alone.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Bearer token to the API.sub then nameidentifier then sid, and a missing user identifier yields 401 Unauthorized.aud and azp with a five-minute clock skew, and authorized audiences include islamu-event-api and islamu-event-blazor.GET with [AllowAnonymous], writes with [Authorize], while resource/action checks route through AuthorizationBehavior to RuntimeAuthorizationProvider (which delegates to Cerbos gRPC PDP or FallbackAuthorizationService).AuthorityProfile pre-resolution in local mode and making _links the only client-side source of truth for action gating.localStorage or sessionStorage bypasses the BFF boundary and weakens browser-side security._links drifts from the server authorization contract.Tenant query filter during runtime request handling creates cross-tenant authorization and data-isolation bugs.aud or only azp allows unauthorized clients to present otherwise valid tokens.IUserContext from HttpContext.RequestServices inside a controller hides an ambient dependency and is rejected from compiled controller calls by ApiCompiledBoundaryTests.// Identity derivation is a pure function of the principal and already has one authority.
// Do not write another extraction helper — see resources/user-id-extraction.md.
using Explore.Application.Authentication;
Guid? userId = principal.GetPlatformUserId(); // sub -> nameidentifier -> sid -> internal_user_id
Guid required = principal.GetRequiredPlatformUserId(); // throws UnauthorizedAccessException
// In a controller, ExploreControllerBase already exposes CurrentUserId / RequiredUserId.
// For provider-linked accounts, inject IQueryHandler<ResolveCurrentUserIdByIdentityRequest, Guid?> identityQuery.
// Provider binding wins over GUID/internal-user claims; an unlinked account has no email fallback.
Guid? resolved = await identityQuery.ResolveCurrentUserIdAsync(User, cancellationToken);
public sealed record UpdateEventCommand(Guid EventId, string Title)
: IAuthorizedRequest<BaseCommandResponse<Guid>>;
public sealed class UpdateEventHandler(IEventRepository repository)
{
public async Task<BaseCommandResponse<Guid>> Handle(
UpdateEventCommand request,
CancellationToken cancellationToken)
{
Event entity = await repository.GetRequiredAsync(request.EventId, cancellationToken);
entity.Rename(request.Title);
await repository.UpdateAsync(entity, cancellationToken);
return new BaseCommandResponse<Guid>(entity.Id, true, "Updated");
}
}
dotnet test --project tests/Event.Architecture.Tests/Event.Architecture.Tests.csproj --configuration Release --verbosity quiet -- --treenode-filter "/*/*/AuthorizationParityTests/*" --minimum-expected-tests 1 --no-progress --maximum-parallel-tests 1dotnet test --project tests/Event.API.IntegrationTests/Event.API.IntegrationTests.csproj --configuration Release --verbosity quietdotnet build --configuration Release --verbosity quietまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Load for Blazor/MudBlazor UI changes involving forms, dialogs, focus, keyboard navigation, landmarks, ARIA, color contrast, RTL-safe styling, or WCAG 2.2 AA tests; not for backend-only changes.
日本語の概要は準備中です。原文の説明を表示しています。
Load when a task asks to research, verify, compare, or look up framework/package behavior, release notes, standards, RFCs, CVEs, or unfamiliar APIs; use repository evidence first, then official docs, and not for codebase navigation alone.
日本語の概要は準備中です。原文の説明を表示しています。
Load for Aspire AppHost work: start/stop/wait resources, inspect dashboard/logs/traces, add integrations/resources, rebuild a service, run isolated worktrees, or diagnose Aspire orchestration; not for plain dotnet apps, container-only deployments, or cloud deployment.
日本語の概要は準備中です。原文の説明を表示しています。
Load for Blazor BFF server work involving YARP proxy routes, cookie sessions, access-token forwarding/refresh, downstream API calls, BFF handlers, or browser-to-API auth failures; not for client component rendering or API JWT validation alone.
日本語の概要は準備中です。原文の説明を表示しています。
Load when editing Blazor `.razor.css`, scoped selectors, `::deep`, BEM class names, RTL/logical CSS properties, or styling nested MudBlazor components; not for global design tokens or non-Blazor CSS.
日本語の概要は準備中です。原文の説明を表示しています。
Load for Blazor/MudBlazor component or page changes involving render modes, dialogs, parameters/events, HAL-gated actions, generated API clients or generated record consumption, theming, or component tests; add accessibility or CSS-isolation only when touched.
日本語の概要は準備中です。原文の説明を表示しています。